24581 Total CVEs
24486 AI Analyzed
343 CISA KEV
5700 Critical
All Vendors
Showing 19701-19750 of 24581 CVEs Page 395 of 492
CVE-2025-49145
Analyzed
8.7
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-49113
KEV Analyzed
9.5
Roundcube Webmail

RoundCube Webmail Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.

2026-02-21
CVE-2025-49090
Analyzed
7.1
Matrix Matrix specification

The Matrix specification before 1

2025-10-02
CVE-2025-49070
Analyzed
7.5
NasaTheme Elessi

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi allows PHP L...

2025-07-06
CVE-2025-49060
Analyzed
10
CMSSuperHeroes Wastia

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue aff...

2025-10-23
CVE-2025-49059
Analyzed
9.3
CleverReach® CleverReach® WP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP allows SQL Injectio...

2025-08-14
CVE-2025-49036
Analyzed
8.1
octagonwebstudio Premium Addons for KingComposer

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addo...

2025-08-14
CVE-2025-49034
Analyzed
7.6
Aman Funnel Builder by FunnelKit

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows SQL...

2025-07-16
CVE-2025-49033
Analyzed
8.5
Metagauss ProfileGrid

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows Blind SQL Injectio...

2025-08-14
CVE-2025-49031
Analyzed
7.1
Stefan M SMu Manual DoFollow

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefan M

2025-07-16
CVE-2025-49029
9.1
bitto.kazi Custom Login And Signup Widget

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.Kazi Custom Login And Signup Widget allows Code Injection.This issue...

2025-07-06
CVE-2025-49028
Analyzed
7.1
Zoho Mail Zoho ZeptoMail

Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail allows Stored XSS

2026-01-01
CVE-2025-48989
Analyzed
7.5
Apache Apache Tomcat

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack

2025-08-14
CVE-2025-48986
Analyzed
8.8
Revive Revive Adserver

Authorization bypass in Revive Adserver 5

2025-11-20
CVE-2025-48984
Analyzed
8.8
Veeam Backup and Replication

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

2025-10-31
CVE-2025-48983
Analyzed
9.9
Veeam Backup and Replication

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by...

2025-10-31
CVE-2025-48982
Analyzed
7.3
Veeam Agent for Microsoft Windows

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a ma...

2025-10-31
CVE-2025-48981
Analyzed
8.6
CompuGroup Medical CGM MEDICO

An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate dat...

2025-10-08
CVE-2025-48978
Analyzed
7.5
Ubiquiti EdgeMAX EdgeSwitch

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1

2025-08-21
CVE-2025-48963
Analyzed
7.3
Acronis Acronis Cyber Protect Cloud Agent

Local privilege escalation due to improper soft link handling

2025-08-28
CVE-2025-48956
Analyzed
7.5

vLLM is an inference and serving engine for large language models (LLMs)

2025-08-21
CVE-2025-48952
9.4
jokob-sk NetAlertX

NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to by...

2025-07-06
CVE-2025-48928
KEV Analyzed
9.5
TeleMessage service

TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability - Recently added to CISA KEV.

2025-07-05
CVE-2025-48927
KEV Analyzed
9.5
TeleMessage service

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability - Recently added to CISA KEV.

2025-07-05
CVE-2025-48913
Analyzed
9.8
Apache Apache CXF

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capa...

2025-08-08
CVE-2025-48891
Analyzed
7.6
Advantech iView

A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils

2025-07-11
CVE-2025-48869
Analyzed
7.5
horilla-opensource horilla

Horilla is a free and open source Human Resource Management System (HRMS)

2025-09-24
CVE-2025-48868
Analyzed
7.2
horilla-opensource horilla

Horilla is a free and open source Human Resource Management System (HRMS)

2025-09-24
CVE-2025-48860
Analyzed
8
Bosch Rexroth ctrlX OS - Setup

A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to...

2025-08-14
CVE-2025-48826
Analyzed
8.8
Planet WGR-500

A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1

2025-10-07
CVE-2025-48824
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-48822
Analyzed
8.6
Microsoft Windows 10 Version 1607

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally

2025-07-08
CVE-2025-48817
Analyzed
8.8
Microsoft Remote Desktop client for Windows Desktop

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-48733
Analyzed
7.5
DuraComm SPM-500 DP-10iN-100-MU

DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication

2025-07-23
CVE-2025-48732
Analyzed
7.3
WWBN AVideo

An incomplete blacklist exists in the

2025-07-25
CVE-2025-48725
Analyzed
8.1
QNAP Systems QuTS hero

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions

2026-02-12
CVE-2025-48724
Analyzed
8.1
QNAP Systems Qsync Central

A buffer overflow vulnerability has been reported to affect Qsync Central

2026-02-12
CVE-2025-48723
Analyzed
8.1
QNAP Systems Qsync Central

A buffer overflow vulnerability has been reported to affect Qsync Central

2026-02-12
CVE-2025-48707
Analyzed
7.5
Unknown

An issue was discovered in Stormshield Network Security (SNS) before 5

2025-09-26
CVE-2025-48704
Analyzed
7.5
Pexip Infinity

Pexip Infinity 35

2025-12-26
CVE-2025-48703
KEV Analyzed
9
centos-webpanel CentOS Web Panel

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total...

2025-09-19
CVE-2025-48700
KEV Analyzed
9.5
Synacor Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability - Active in CISA KEV catalog.

2026-04-21
CVE-2025-48654
Analyzed
7.8
Google Android

In onStart of CompanionDeviceManagerService

2026-03-04
CVE-2025-48653
Analyzed
7.8
Google Android

In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code

2026-03-04
CVE-2025-48650
Analyzed
8.4
Google Android

In multiple locations, there is a possible information disclosure due to SQL injection

2026-03-03
CVE-2025-48647
Analyzed
7.8
Google Google Devices

In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc

2026-01-17
CVE-2025-48646
Analyzed
7.8
Google Android

In executeRequest of ActivityStarter

2026-03-03
CVE-2025-48645
Analyzed
7.8
Google Android

In loadDescription of DeviceAdminInfo

2026-03-04
CVE-2025-48639
Analyzed
7.3
Google Android

In DefaultTransitionHandler

2025-12-09
CVE-2025-48638
Analyzed
7.8
Google Android

In __pkvm_load_tracing of trace

2025-12-09