24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 20351-20400 of 24021 CVEs Page 408 of 481
CVE-2025-27771
Analyzed
7.4
uptrain-ai uptrain

UpTrain is an open-source platform to evaluate and improve generative AI applications

2026-08-18
CVE-2025-27770
Analyzed
7.4
uptrain-ai uptrain

UpTrain is an open-source platform to evaluate and improve generative AI applications

2026-08-18
CVE-2025-2776
KEV Analyzed
9.5
SysAid SysAid On-Prem

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.

2025-07-23
CVE-2025-2775
KEV Analyzed
9.5
SysAid SysAid On-Prem

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.

2025-07-23
CVE-2025-27724
Analyzed
9.3
MedDream MedDream PACS Premium

A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file...

2025-07-28
CVE-2025-27721
Analyzed
7.5
INFINITT Healthcare INFINITT PACS System Manager

Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthorized access to system resources

2025-08-21
CVE-2025-27713
Analyzed
7.8
Intel Intel(R) QAT Windows software

Out-of-bounds write for some Intel(R) QAT Windows software before version 2

2025-11-13
CVE-2025-27621
Analyzed
7.7
uptrain-ai uptrain

UpTrain is an open-source platform to evaluate and improve generative AI applications

2026-08-18
CVE-2025-27614
Analyzed
8.6
j6t gitk

Gitk is a Tcl/Tk based Git history browser

2025-07-11
CVE-2025-27582
Analyzed
7.6
One Identity Password Manager

The Secure Password extension in One Identity Password Manager before 5

2025-07-14
CVE-2025-27577
Analyzed
8.4
OpenHarmony OpenHarmony

in OpenHarmony v5

2025-08-11
CVE-2025-2749
KEV Analyzed
9.5
Kentico Xperience

Kentico Xperience Path Traversal Vulnerability - Active in CISA KEV catalog.

2026-04-21
CVE-2025-2747
KEV Analyzed
9.5
Kentico Xperience

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.

2025-10-20
CVE-2025-27466
Analyzed
9.8
Xen Xen

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple i...

2025-09-12
CVE-2025-27464
Analyzed
9.4
Xen Windows PV drivers

The Xen Windows PV drivers fail to implement security descriptors on various facilities, allowing unprivileged users to access sensitive interfaces.

2026-07-10
CVE-2025-27463
Analyzed
9.4
Xen Windows PV drivers

The Xen Windows PV drivers for the XenIface facility lack proper security descriptors, allowing unprivileged users to access the interface and potenti...

2026-07-10
CVE-2025-27462
Analyzed
9.4
Xen Windows PV drivers

The Xen Windows PV drivers for the XenCons facility lack proper security descriptors, allowing unprivileged users to access the interface and potentia...

2026-07-10
CVE-2025-27461
Analyzed
7.6
Endress+Hauser Endress+Hauser MEAC300-FNADE4

During startup, the device automatically logs in the EPC2 Windows user without requesting a password

2025-07-06
CVE-2025-27460
7.6
Endress+Hauser Endress+Hauser MEAC300-FNADE4

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker

2025-07-06
CVE-2025-2746
KEV Analyzed
9.5
Kentico Xperience

Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.

2025-10-20
CVE-2025-27456
7.5
Endress+Hauser Endress+Hauser MEAC300-FNADE4

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame,...

2025-07-06
CVE-2025-27449
7.5
Endress+Hauser Endress+Hauser MEAC300-FNADE4

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susc...

2025-07-06
CVE-2025-27447
7.4
Endress+Hauser Endress+Hauser MEAC300-FNADE4

The web application is susceptible to cross-site-scripting attacks

2025-07-06
CVE-2025-27380
Analyzed
7.6
Altium AES

HTML injection in Project Release in Altium Enterprise Server (AES) 7

2026-01-22
CVE-2025-27378
Analyzed
8.6
Altium AES

AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied

2026-01-22
CVE-2025-27225
Analyzed
7.5
Enterprise

TRUfusion Enterprise through 7

2025-10-27
CVE-2025-27224
Analyzed
9.8
TRUfusion Enterprise through

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitiz...

2025-10-28
CVE-2025-27223
Analyzed
7.5
Enterprise

TRUfusion Enterprise through 7

2025-10-28
CVE-2025-27222
Analyzed
8.6
Enterprise

TRUfusion Enterprise through 7

2025-10-27
CVE-2025-27217
Analyzed
9.1
Ubiquiti UISP Application

A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP App...

2025-08-21
CVE-2025-27216
Analyzed
8.8
Ubiquiti UISP Application

Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate pr...

2025-08-21
CVE-2025-27215
Analyzed
8.1
Ubiquiti UniFi Connect Display Cast

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported ch...

2025-08-21
CVE-2025-27214
Analyzed
9.8
Ubiquiti UniFi Connect EV Station Pro

A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent...

2025-08-21
CVE-2025-27212
Analyzed
9.8
Ubiquiti UniFi Access Reader Pro

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access manageme...

2025-08-05
CVE-2025-27211
Analyzed
7.5
Ubiquiti EdgeMAX EdgeSwitch

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1

2025-08-05
CVE-2025-27203
Analyzed
9.6
Adobe Adobe Connect

Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution...

2025-07-08
CVE-2025-27129
Analyzed
9.8
Tenda AC6 V5.0

An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP reque...

2025-08-20
CVE-2025-27128
Analyzed
8.4
OpenHarmony OpenHarmony

in OpenHarmony v5

2025-08-11
CVE-2025-27077
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while processing message in guest VM

2025-09-24
CVE-2025-27076
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while processing simultaneous requests via escape path

2025-08-07
CVE-2025-27075
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host

2025-08-07
CVE-2025-27074
Analyzed
8.8
Qualcomm Snapdragon

Memory corruption while processing a GP command response

2025-11-04
CVE-2025-27073
Analyzed
7.5
Qualcomm Snapdragon

Transient DOS while creating NDP instance

2025-08-07
CVE-2025-27071
Analyzed
7.3
Qualcomm Snapdragon

Memory corruption while processing specific files in Powerline Communication Firmware

2025-08-07
CVE-2025-27070
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while performing encryption and decryption commands

2025-11-04
CVE-2025-27069
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while processing DDI command calls

2025-08-07
CVE-2025-27068
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while processing an IOCTL command with an arbitrary address

2025-08-07
CVE-2025-27067
Analyzed
7.8
Qualcomm Snapdragon

Memory corruption while processing DDI call with invalid buffer

2025-08-07
CVE-2025-27066
Analyzed
7.5
Qualcomm Snapdragon

Transient DOS while processing an ANQP message

2025-08-07
CVE-2025-27065
Analyzed
7.5
Qualcomm Snapdragon

Transient DOS while processing a frame with malformed shared-key descriptor

2025-08-07