24458 Total CVEs
24363 AI Analyzed
343 CISA KEV
5636 Critical
All Vendors
Showing 20201-20250 of 24458 CVEs Page 405 of 490
CVE-2025-41714
Analyzed
8.8
Welotec SmartEMS Web Application

The upload endpoint insufficiently validates the 'Upload-Key' request header

2025-09-10
CVE-2025-41709
Analyzed
9.8
Janitza UMG 96RM-E 24V(5222063)

A critical vulnerability exists in a specific component of various products, allowing an attacker to cause a major impact via an unspecified vector. T...

2026-03-11
CVE-2025-41708
Analyzed
7.4
Bender CC612

Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface

2025-09-08
CVE-2025-41702
Analyzed
9.8
Welotec EG400Mk2-D11001-000101

The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid H...

2025-08-26
CVE-2025-41701
Analyzed
7.8
Beckhoff TE1000 | TwinCAT 3 Enineering

An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affect...

2025-09-09
CVE-2025-41700
Analyzed
7.8
CODESYS CODESYS Development System

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a COD...

2025-12-02
CVE-2025-41699
Analyzed
8.8
Phoenix Contact CHARX SEC-3150

An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as r...

2025-10-14
CVE-2025-41698
Analyzed
7.8
Draeger Draeger ICMHelper

A low privileged local attacker can interact with the affected service although user-interaction should not be allowed

2025-08-05
CVE-2025-41691
Analyzed
7.5
CODESYS Control RTE (SL)

An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted...

2025-08-05
CVE-2025-41690
Analyzed
7.4
Endress+Hauser Promag 10 with HART

A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s event...

2025-09-02
CVE-2025-41688
Analyzed
7.2
MB connect line mbNET HW1

A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox

2025-07-31
CVE-2025-41687
Analyzed
9.8
Weidmueller IE-SR-2TX-WL

An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices.

2025-07-23
CVE-2025-41686
Analyzed
7.8

A low-privileged local attacker can exploit improper permissions on nssm

2025-08-12
CVE-2025-41684
Analyzed
8.8
Weidmueller IE-SR-2TX-WL

An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user in...

2025-07-23
CVE-2025-41683
Analyzed
8.8
Weidmueller IE-SR-2TX-WL

An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user in...

2025-07-23
CVE-2025-41682
Analyzed
8.8
Bender CC612

An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password

2025-09-08
CVE-2025-41672
Analyzed
10
WAGO Wago Device Sphere

A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.

2025-07-07
CVE-2025-41669
Analyzed
8.8
Phoenix Contact AXC F 1152

The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store witho...

2026-05-27
CVE-2025-41668
Analyzed
8.8
Phoenix Contact AXC F 1152

A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and ex...

2025-07-08
CVE-2025-41667
Analyzed
8.8
Phoenix Contact AXC F 1152

A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to...

2025-07-08
CVE-2025-41666
Analyzed
8.8
Phoenix Contact AXC F 1152

A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file o...

2025-07-08
CVE-2025-41664
Analyzed
7.5
WAGO Coupler 0750-0362

A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission h...

2025-09-08
CVE-2025-41660
Analyzed
8.8
CODESYS CODESYS Control RTE (SL)

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code executi...

2026-03-24
CVE-2025-41659
Analyzed
8.3
CODESYS Control RTE (SL)

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys

2025-08-05
CVE-2025-41656
Analyzed
10
Pilz IndustrialPI 4 with Firmware Bullseye

An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED...

2025-07-06
CVE-2025-41648
Analyzed
9.8
Pilz IndustrialPI 4 with IndustrialPI webstatus

An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all ava...

2025-07-06
CVE-2025-41459
Analyzed
7.8
Two App Studio Journey

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5

2025-07-22
CVE-2025-41430
Analyzed
7.5
F5 BIG-IP

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate

2025-10-16
CVE-2025-41425
Analyzed
8.1
DuraComm SPM-500 DP-10iN-100-MU

DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack

2025-07-23
CVE-2025-41420
Analyzed
9.6
WWBN AVideo

A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954f...

2025-07-25
CVE-2025-41392
Analyzed
7.8
Ashlar-Vellum Cobalt

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12

2025-08-19
CVE-2025-41390
Analyzed
7.8
Truffle Security TruffleHog

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co

2025-10-20
CVE-2025-41368
Analyzed
8.1
Smallsrv Small HTTP

Problem in the Small HTTP Server v3

2026-03-28
CVE-2025-41359
Analyzed
7.8
Smallsrv Small HTTP

Vulnerability related to an unquoted service path in Small HTTP Server 3

2026-03-28
CVE-2025-41258
Analyzed
8
danny-avila LibreChat

LibreChat version 0

2026-03-19
CVE-2025-41253
Analyzed
7.5
VMware Spring Cloud Gateway Server Webflux

The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties t...

2025-10-16
CVE-2025-41252
Analyzed
7.5
VMware NSX

Description: VMware NSX contains a username enumeration vulnerability

2025-09-29
CVE-2025-41251
Analyzed
8.1
VMware NSX

VMware NSX contains a weak password recovery mechanism vulnerability

2025-09-29
CVE-2025-41250
Analyzed
8.5
VMware vCenter

VMware vCenter contains an SMTP header injection vulnerability

2025-09-29
CVE-2025-41249
Analyzed
7.5
VMware Spring Framework

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized supe...

2025-09-16
CVE-2025-41248
Analyzed
7.5
VMware Spring Security

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super...

2025-09-16
CVE-2025-41246
Analyzed
7.6
VMware Tools

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls

2025-09-29
CVE-2025-41244
KEV Analyzed
7.8
VMware VCF operations

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability

2025-09-29
CVE-2025-41243
Analyzed
10
Spring Cloud Gateway

Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable whe...

2025-09-16
CVE-2025-41240
Analyzed
10
VMware bitnamicharts/appsmith

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document ro...

2025-07-25
CVE-2025-41239
Analyzed
7.1
VMware ESXi

VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSo...

2025-07-15
CVE-2025-41238
Analyzed
9.3
VMware ESXi

VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bou...

2025-07-15
CVE-2025-41237
Analyzed
9.3
VMware Cloud Foundation

VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds wri...

2025-07-15
CVE-2025-41236
Analyzed
9.3
VMware ESXi

VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local ad...

2025-07-15
CVE-2025-41224
Analyzed
8.8
Siemens RUGGEDCOM RMC8388 V5.X

A vulnerability has been identified in RUGGEDCOM RMC8388 V5

2025-07-10