24458 Total CVEs
24363 AI Analyzed
343 CISA KEV
5636 Critical
All Vendors
Showing 19601-19650 of 24458 CVEs Page 393 of 490
CVE-2025-48927
KEV Analyzed
9.5
TeleMessage service

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability - Recently added to CISA KEV.

2025-07-05
CVE-2025-48913
Analyzed
9.8
Apache Apache CXF

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capa...

2025-08-08
CVE-2025-48891
Analyzed
7.6
Advantech iView

A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils

2025-07-11
CVE-2025-48869
Analyzed
7.5
horilla-opensource horilla

Horilla is a free and open source Human Resource Management System (HRMS)

2025-09-24
CVE-2025-48868
Analyzed
7.2
horilla-opensource horilla

Horilla is a free and open source Human Resource Management System (HRMS)

2025-09-24
CVE-2025-48860
Analyzed
8
Bosch Rexroth ctrlX OS - Setup

A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to...

2025-08-14
CVE-2025-48826
Analyzed
8.8
Planet WGR-500

A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1

2025-10-07
CVE-2025-48824
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-48822
Analyzed
8.6
Microsoft Windows 10 Version 1607

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally

2025-07-08
CVE-2025-48817
Analyzed
8.8
Microsoft Remote Desktop client for Windows Desktop

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-48733
Analyzed
7.5
DuraComm SPM-500 DP-10iN-100-MU

DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication

2025-07-23
CVE-2025-48732
Analyzed
7.3
WWBN AVideo

An incomplete blacklist exists in the

2025-07-25
CVE-2025-48725
Analyzed
8.1
QNAP Systems QuTS hero

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions

2026-02-12
CVE-2025-48724
Analyzed
8.1
QNAP Systems Qsync Central

A buffer overflow vulnerability has been reported to affect Qsync Central

2026-02-12
CVE-2025-48723
Analyzed
8.1
QNAP Systems Qsync Central

A buffer overflow vulnerability has been reported to affect Qsync Central

2026-02-12
CVE-2025-48707
Analyzed
7.5
Unknown

An issue was discovered in Stormshield Network Security (SNS) before 5

2025-09-26
CVE-2025-48704
Analyzed
7.5
Pexip Infinity

Pexip Infinity 35

2025-12-26
CVE-2025-48703
KEV Analyzed
9
centos-webpanel CentOS Web Panel

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total...

2025-09-19
CVE-2025-48700
KEV Analyzed
9.5
Synacor Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability - Active in CISA KEV catalog.

2026-04-21
CVE-2025-48654
Analyzed
7.8
Google Android

In onStart of CompanionDeviceManagerService

2026-03-04
CVE-2025-48653
Analyzed
7.8
Google Android

In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code

2026-03-04
CVE-2025-48650
Analyzed
8.4
Google Android

In multiple locations, there is a possible information disclosure due to SQL injection

2026-03-03
CVE-2025-48647
Analyzed
7.8
Google Google Devices

In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc

2026-01-17
CVE-2025-48646
Analyzed
7.8
Google Android

In executeRequest of ActivityStarter

2026-03-03
CVE-2025-48645
Analyzed
7.8
Google Android

In loadDescription of DeviceAdminInfo

2026-03-04
CVE-2025-48639
Analyzed
7.3
Google Android

In DefaultTransitionHandler

2025-12-09
CVE-2025-48638
Analyzed
7.8
Google Android

In __pkvm_load_tracing of trace

2025-12-09
CVE-2025-48637
Analyzed
7.8
Google Android

In multiple functions of mem_protect

2025-12-09
CVE-2025-48636
Analyzed
8.4
Google Android

In openFile of BugreportContentProvider

2026-03-03
CVE-2025-48635
Analyzed
7.7
Google Android

In multiple functions of TaskFragmentOrganizerController

2026-03-04
CVE-2025-48634
Analyzed
7.3
Google Android

In relayoutWindow of WindowManagerService

2026-03-04
CVE-2025-48633
KEV Analyzed
9.5
Google Android

Android Framework Information Disclosure Vulnerability - Active in CISA KEV catalog.

2025-12-03
CVE-2025-48632
Analyzed
7.8
Google Android

In setDisplayName of AssociationRequest

2025-12-09
CVE-2025-48631
Analyzed
7.5
Google Android

In onHeaderDecoded of LocalImageResolver

2025-12-09
CVE-2025-48630
Analyzed
7.4
Google Android

In drawLayersInternal of SkiaRenderEngine

2026-03-04
CVE-2025-48629
Analyzed
7.8
Google Android

In findAvailRecognizer of VoiceInteractionManagerService

2025-12-09
CVE-2025-48628
Analyzed
7.8
Google Android

In validateIconUserBoundary of PrintManagerService

2025-12-09
CVE-2025-48627
Analyzed
7.8
Google Android

In startNextMatchingActivity of ActivityTaskManagerService

2025-12-09
CVE-2025-48626
Analyzed
9.8
Google Android

In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to re...

2025-12-09
CVE-2025-48625
Analyzed
7
Google Android

In multiple locations of UsbDataAdvancedProtectionHook

2025-12-09
CVE-2025-48624
Analyzed
7.8
Google Android

In multiple functions of arm-smmu-v3

2025-12-09
CVE-2025-48623
Analyzed
7.8
Google Android

In init_pkvm_hyp_vcpu of pkvm

2025-12-09
CVE-2025-48621
Analyzed
7.3
Google Android

In DefaultTransitionHandler

2025-12-09
CVE-2025-48620
Analyzed
7.8
Google Android

In onSomePackagesChanged of VoiceInteractionManagerService

2025-12-09
CVE-2025-48619
Analyzed
8.4
Google Android

In multiple functions of ContentProvider

2026-03-04
CVE-2025-48615
Analyzed
7.8
Google Android

In getComponentName of MediaButtonReceiverHolder

2025-12-09
CVE-2025-48613
Analyzed
7.8
Google Android

In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the same key

2026-03-04
CVE-2025-48612
Analyzed
7.8
Google Android

In multiple locations, there is a possible way for an application on a work profile to set the main user's default NFC payment setting due to improper...

2025-12-09
CVE-2025-48611
Analyzed
10
Google Android

A desync in persistence within DeviceId.java, caused by a missing bounds check, allows for local escalation of privilege without requiring user intera...

2026-03-11
CVE-2025-48606
Analyzed
7.8
Google Android

In preparePackage of InstallPackageHelper

2025-12-09