23871 Total CVEs
23776 AI Analyzed
336 CISA KEV
5459 Critical
All Vendors
Showing 19751-19800 of 23871 CVEs Page 396 of 478
CVE-2025-40554
Analyzed
9.8
SolarWinds Web Help Desk

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke s...

2026-01-28
CVE-2025-40553
Analyzed
9.8
SolarWinds Web Help Desk

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic...

2026-01-28
CVE-2025-40552
Analyzed
9.8
SolarWinds Web Help Desk

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to exe...

2026-01-28
CVE-2025-40551
KEV Analyzed
9.8
SolarWinds Web Help Desk

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whic...

2026-01-28
CVE-2025-40549
Analyzed
9.1
SolarWinds Serv-U

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to...

2025-11-19
CVE-2025-40548
Analyzed
9.1
SolarWinds Serv-U

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code....

2025-11-19
CVE-2025-40547
Analyzed
9.1
SolarWinds Serv-U

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute cod...

2025-11-19
CVE-2025-40541
Analyzed
9.1
SolarWinds Serv-U

An Insecure Direct Object Reference (IDOR) vulnerability in Serv-U allows authenticated administrators to execute native code as a privileged account...

2026-02-24
CVE-2025-40540
Analyzed
9.1
SolarWinds Serv-U

A critical type confusion vulnerability in Serv-U allows an authenticated administrative user to execute arbitrary native code, potentially compromisi...

2026-02-24
CVE-2025-40539
Analyzed
9.1
SolarWinds Serv-U

A type confusion vulnerability in Serv-U enables authenticated administrative users to execute arbitrary native code with the privileges of the servic...

2026-02-24
CVE-2025-40538
Analyzed
9.1
SolarWinds Serv-U

A broken access control vulnerability in Serv-U allows domain or group administrators to escalate privileges, create system admin users, and execute a...

2026-02-24
CVE-2025-40537
Analyzed
7.5
SolarWinds Web Help Desk

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to ad...

2026-01-28
CVE-2025-40536
KEV Analyzed
8.1
SolarWinds Web Help Desk

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated atta...

2026-01-28
CVE-2025-4046
Analyzed
8.5
Lexmark Lexmark Cloud Services

A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization

2025-08-19
CVE-2025-4044
Analyzed
8.2
Lexmark Universal Print Driver

Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information...

2025-08-19
CVE-2025-4008
KEV Analyzed
9.5
Smartbedded MeteoBridge

Smartbedded Meteobridge Command Injection Vulnerability - Active in CISA KEV catalog.

2025-10-02
CVE-2025-39510
Analyzed
8.5
ValvePress Pinterest Automatic Pin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin allows SQL In...

2025-08-14
CVE-2025-39496
Analyzed
9.3
WBW WooBeWoo Product Filter Pro

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Injec...

2025-08-28
CVE-2025-39484
Analyzed
9.3
Waituk Entrada

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue a...

2026-01-06
CVE-2025-39477
Analyzed
9.8
Sfwebservice InWave Jobs

Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff...

2026-01-07
CVE-2025-3947
Analyzed
8.2
Honeywell C300 PCNT02

The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Controlย Data Access (CDA)

2025-07-11
CVE-2025-3946
Analyzed
8.2
Honeywell C300 PCNT02

The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Controlย Data Access (CDA...

2025-07-11
CVE-2025-39247
Analyzed
8.6
Hikvision HikCentral Professional

There is an Access Control Vulnerability in some HikCentral Professional versions

2025-08-29
CVE-2025-38747
Analyzed
7.8
Dell SupportAssist OS Recovery

Dell SupportAssist OS Recovery, versions prior to 5

2025-08-07
CVE-2025-38743
Analyzed
7.8
Dell iDRAC Service Module (iSM)

Dell iDRAC Service Module (iSM), versions prior to 6

2025-08-21
CVE-2025-38741
Analyzed
7.5
Dell Enterprise SONiC OS

Dell Enterprise SONiC OS, version 4

2025-08-05
CVE-2025-38739
Analyzed
7.2
Dell Dell Digital Delivery

Dell Digital Delivery, versions prior to 5

2025-08-05
CVE-2025-3848
Analyzed
8.8

The Download Manager and Payment Form WordPress Plugin โ€“ WP SmartPay plugin for WordPress is vulnerable to privilege escalation via account takeover i...

2025-07-05
CVE-2025-3839
Analyzed
8
Unknown

A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction

2026-01-23
CVE-2025-38352
KEV Analyzed
9.5
Linux Linux kernel

Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability - Active in CISA KEV catalog.

2025-09-04
CVE-2025-3831
Analyzed
8.1
checkpoint Check Point Harmony SASE

Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties

2025-08-12
CVE-2025-38250
Analyzed
7.8
Linux Linux kernel

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix use-after-free in vhci_flush() syzbot reported use-afte...

2026-06-21
CVE-2025-38129
Analyzed
7.8
Linux Linux kernel

In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix use-after-free in page_pool_recycle_in_ring syzbot reported a uaf...

2026-06-21
CVE-2025-37736
Analyzed
8.8
Elastic Elastic Cloud Enterprise (ECE)

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be...

2025-11-08
CVE-2025-37735
Analyzed
7
Elastic Kibana

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service...

2025-11-06
CVE-2025-37729
Analyzed
9.1
Elastic Elastic Cloud Enterprise (ECE)

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin acces...

2025-10-13
CVE-2025-3770
Analyzed
7
TianoCore EDK2

EDK2 contains a vulnerability in BIOS where an attacker may cause โ€œProtection Mechanism Failureโ€ by local access

2025-08-07
CVE-2025-3753
Analyzed
7.8
Open Source Robotics Foundation Robot Operating System (ROS)

A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and...

2025-07-17
CVE-2025-3719
Analyzed
8.1
Nozomi Networks Guardian

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users wit...

2025-10-07
CVE-2025-3718
Analyzed
7.9
Nozomi Networks Guardian

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter

2025-10-07
CVE-2025-37168
Analyzed
8.2
HPE ArubaOS (AOS)

Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system

2026-01-14
CVE-2025-37164
KEV Analyzed
10
HPE HPE OneView

A remote code execution issue exists in HPE OneView.

2025-12-17
CVE-2025-37163
Analyzed
7.2
HPE HPE Aruba Networking Management Software (Airwave)

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform

2025-11-19
CVE-2025-37161
Analyzed
7.5
HPE

A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service

2025-11-19
CVE-2025-37155
Analyzed
7.8
HPE HPE Aruba Networking AOS-CX

A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only us...

2025-11-19
CVE-2025-37127
Analyzed
7.2
HPE HPE Aruba Networking EdgeConnect SD-WAN Gateway

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to ga...

2025-09-16
CVE-2025-37126
Analyzed
7.2
HPE HPE Aruba Networking EdgeConnect SD-WAN Gateway

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run ar...

2025-09-16
CVE-2025-37125
Analyzed
7.5
HPE HPE Aruba Networking EdgeConnect SD-WAN Gateway

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS)

2025-09-16
CVE-2025-37124
Analyzed
8.6
HPE HPE Aruba Networking EdgeConnect SD-WAN Gateway

A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections

2025-09-16
CVE-2025-37123
Analyzed
8.8
HPE HPE Aruba Networking EdgeConnect SD-WAN Gateway

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to esca...

2025-09-16