24458 Total CVEs
24363 AI Analyzed
343 CISA KEV
5636 Critical
All Vendors
Showing 19501-19550 of 24458 CVEs Page 391 of 490
CVE-2025-49691
Analyzed
8
Microsoft Windows 10 Version 1507

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network

2025-07-10
CVE-2025-49688
Analyzed
8.8
Microsoft Windows Server 2012 R2

Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49687
Analyzed
8.8
Microsoft Windows 10 Version 1507

Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally

2025-07-08
CVE-2025-49676
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49674
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49673
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49672
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49670
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49669
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49668
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49663
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49657
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49655
Analyzed
9.8
Keras Keras

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a mali...

2025-10-17
CVE-2025-4962
Analyzed
7.7
lunary-ai lunary-ai/lunary

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up...

2025-08-19
CVE-2025-4960
Analyzed
7.8
EPSON EPSON Printer Controller Installer

The com

2026-02-20
CVE-2025-4957
Analyzed
7.1
Metagauss ProfileGrid

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid allows Reflected XSS

2025-09-26
CVE-2025-49569
Analyzed
7.8
Adobe Substance3D - Viewer

Substance3D - Viewer versions 0

2025-08-13
CVE-2025-49564
Analyzed
7.8
Adobe Illustrator

Illustrator versions 28

2025-08-12
CVE-2025-49563
Analyzed
7.8
Adobe Illustrator

Illustrator versions 28

2025-08-12
CVE-2025-49560
Analyzed
7.8
Adobe Substance3D - Viewer

Substance3D - Viewer versions 0

2025-08-13
CVE-2025-49557
Analyzed
8.7
Adobe Adobe Commerce

Adobe Commerce versions 2

2025-08-12
CVE-2025-49555
Analyzed
8.1
Adobe Adobe Commerce

Adobe Commerce versions 2

2025-08-12
CVE-2025-49553
Analyzed
9.3
Adobe Adobe Connect

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to...

2025-10-14
CVE-2025-49551
Analyzed
8.8
Adobe ColdFusion

ColdFusion versions 2025

2025-07-10
CVE-2025-49537
Analyzed
7.9
Adobe ColdFusion

ColdFusion versions 2025

2025-07-10
CVE-2025-49533
Analyzed
9.8
Adobe Adobe Experience Manager (MS)

Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbit...

2025-07-08
CVE-2025-4953
Analyzed
7.4
Red Hat Red Hat Enterprise Linux 8

A flaw was found in Podman

2025-09-16
CVE-2025-49521
8.8

A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 tem...

2025-07-06
CVE-2025-49520
8.8

A flaw was found in Ansible Automation Platformโ€™s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command

2025-07-06
CVE-2025-49506
Analyzed
7.5
Apache Apache Portable Runtime Utility

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentia...

2026-08-27
CVE-2025-49495
Analyzed
8.4
Processor

An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580

2026-01-06
CVE-2025-49492
7.4
ASR Falcon Linuxใ€Kestrelใ€Lapwing Linux

Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun

2025-07-06
CVE-2025-49480
7.4
ASR Falcon Linuxใ€Kestrelใ€Lapwing Linux

Out-of-bounds access in ASR180x ใ€ASR190x in lte-telephony, This vulnerability is associated with program files apps/lzma/src/LzmaEnc

2025-07-06
CVE-2025-4946
Analyzed
8.1
Odin Design Vikinger

The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the vikinger_delete_activity_med...

2025-07-05
CVE-2025-49459
Analyzed
7.8
Zoom Communications Zoom Workplace for Windows on ARM

Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6

2025-09-09
CVE-2025-49457
Analyzed
9.6
Zoom Communications Zoom Clients for Windows

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

2025-08-12
CVE-2025-49438
Analyzed
7.2
Max Chirkov Simple Login Log

Deserialization of Untrusted Data vulnerability in Max Chirkov Simple Login Log allows Object Injection

2025-08-20
CVE-2025-49417
Analyzed
9.8
BestWpDeveloper WooCommerce Product Multi-Action

Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action allows Object Injection. This issue affects WooCom...

2025-07-06
CVE-2025-49414
Analyzed
10
Fastw3b FW Gallery

Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery allows Using Malicious Files. This issue affects FW Gallery: f...

2025-07-06
CVE-2025-49407
Analyzed
7.1
favethemes Houzez

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS

2025-08-28
CVE-2025-49405
Analyzed
8.1
favethemes Houzez

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP...

2025-08-28
CVE-2025-49404
Analyzed
8.5
purethemes Listeo Core

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in purethemes Listeo-Core allows SQL Injection

2025-08-28
CVE-2025-49401
Analyzed
9.8
axiomthemes smart SEO

Deserialization of Untrusted Data vulnerability in ExpressTech Systems Quiz And Survey Master allows Object Injection. This issue affects Quiz And Sur...

2025-09-05
CVE-2025-49399
Analyzed
8.8
Basix NEX-Forms

Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms allows Cross Site Request Forgery

2025-08-20
CVE-2025-49388
Analyzed
9.8
kamleshyadav Miraculous Core Plugin

Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin allows Privilege Escalation. This issue affects Miraculous Core Pl...

2025-08-28
CVE-2025-49387
Analyzed
10
add-ons.org

Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms allows Upload a Web Shell t...

2025-08-28
CVE-2025-49383
Analyzed
8.1
CocoBasic Neresa

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Neresa allows PHP L...

2025-08-28
CVE-2025-49382
Analyzed
8.8
DexignZone JobZilla - Job Board WordPress Theme

Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme allows Privilege Escalation

2025-08-20
CVE-2025-49381
Analyzed
9.6
ads.txt Guru ads.txt Guru Connect

Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect allows Cross Site Request Forgery. This issue affects ads.txt Gur...

2025-08-20
CVE-2025-49378
Analyzed
8.5
Themefic Hydra Booking

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL...

2025-10-23