8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 2001-2050 of 8341 CVEs Page 41 of 167
CVE-2025-6514
9.6
Unknown Multiple Products

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the authorization_endpoint response U...

2025-07-10
CVE-2025-65118
8.8
Unknown Multiple Products

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbit...

2026-01-16
CVE-2025-65112
Analyzed
9.4
Unknown Multiple Products

PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated user...

2025-11-30
CVE-2025-65110
8.1
Vega Multiple Products

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs

2026-01-06
CVE-2025-65108
Analyzed
10
Google Multiple Products

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block...

2025-11-22
CVE-2025-65103
8.8
OpenSTAManager Multiple Products

OpenSTAManager is an open source management software for technical assistance and invoicing

2025-11-20
CVE-2025-65098
7.4
Typebot Multiple Products

Typebot is an open-source chatbot builder

2026-01-24
CVE-2025-65091
Analyzed
10
Unknown Multiple Products

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONServic...

2026-01-10
CVE-2025-65073
7.5
Keystone Multiple Products

OpenStack Keystone before 26

2025-11-18
CVE-2025-6507
Analyzed
9.8
Unknown Multiple Products

A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code exe...

2025-09-02
CVE-2025-6505
8.1
Unauthorized Multiple Products

Unauthorized access and impersonation can occur in versions 4

2025-07-29
CVE-2025-65041
Analyzed
10
Microsoft Multiple Products

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

2025-12-19
CVE-2025-6504
8.4
HDP Multiple Products

In HDP Server versions below 4

2025-07-29
CVE-2025-65037
Analyzed
10
Microsoft Multiple Products

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

2025-12-19
CVE-2025-65036
8.3
Unknown Multiple Products

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence

2025-12-06
CVE-2025-65034
8.1
Rallly Multiple Products

Rallly is an open-source scheduling and collaboration tool

2025-11-20
CVE-2025-65033
8.1
Rallly Multiple Products

Rallly is an open-source scheduling and collaboration tool

2025-11-20
CVE-2025-65030
7.1
Rallly Multiple Products

Rallly is an open-source scheduling and collaboration tool

2025-11-20
CVE-2025-65029
8.1
Rallly Multiple Products

Rallly is an open-source scheduling and collaboration tool

2025-11-20
CVE-2025-65027
7.6
ROM Multiple Products

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface

2025-12-03
CVE-2025-65025
8.2
Unknown Multiple Products

esm

2025-11-20
CVE-2025-65024
7.2
Unknown Multiple Products

i-Educar is free, fully online school management software

2025-11-20
CVE-2025-65023
7.2
Unknown Multiple Products

i-Educar is free, fully online school management software

2025-11-20
CVE-2025-65022
7.2
Unknown Multiple Products

i-Educar is free, fully online school management software

2025-11-20
CVE-2025-65021
Analyzed
9.1
Unknown Multiple Products

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists in...

2025-11-21
CVE-2025-65018
7.1
LIBPNG Multiple Products

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files

2025-11-26
CVE-2025-65002
7.5
Fujitsu Multiple Products

Fujitsu iRMC S6 on M5 before 1

2025-11-14
CVE-2025-65001
8.2
Fujitsu Multiple Products

Fujitsu fbiosdrv

2025-11-13
CVE-2025-64989
7.2
Unknown Multiple Products

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-FindFileBySizeAndH...

2025-12-12
CVE-2025-64988
7.2
Unknown Multiple Products

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction...

2025-12-12
CVE-2025-64987
7.2
Unknown Multiple Products

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC ins...

2025-12-12
CVE-2025-64986
7.2
Unknown Multiple Products

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-DevicesListeningOn...

2025-12-12
CVE-2025-64983
Analyzed
8
Unknown Multiple Products

Smart Video Doorbell firmware versions prior to 2

2025-11-27
CVE-2025-6495
Analyzed
7.5
WordPress Multiple Products

The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1

2025-07-29
CVE-2025-64899
7.8
Adobe Multiple Products

Acrobat Reader versions 24

2025-12-11
CVE-2025-64785
7.8
Adobe Multiple Products

Acrobat Reader versions 24

2025-12-11
CVE-2025-64783
7.8
SDK Multiple Products

DNG SDK versions 1

2025-12-11
CVE-2025-64778
7.3
Unknown Multiple Products

NMIS/BioDose software V22

2025-12-03
CVE-2025-64775
Analyzed
7.5
Apache Multiple Products

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion

2025-12-02
CVE-2025-64772
7.8
INZONE Multiple Products

The installer of INZONE Hub 1

2025-12-02
CVE-2025-64767
Analyzed
9.1
HP Multiple Products

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal()...

2025-11-22
CVE-2025-64764
7.1
Astro Multiple Products

Astro is a web framework

2025-11-20
CVE-2025-64759
8.1
Homarr Multiple Products

Homarr is an open-source dashboard

2025-11-20
CVE-2025-64756
7.5
Glob Multiple Products

Glob matches files using patterns the shell uses

2025-11-18
CVE-2025-64741
Analyzed
8.1
Google Multiple Products

Improper authorization handling in Zoom Workplace for Android before version 6

2025-11-14
CVE-2025-64740
Analyzed
7.5
Microsoft Multiple Products

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct...

2025-11-14
CVE-2025-64729
8.1
Unknown Multiple Products

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed...

2026-01-16
CVE-2025-64720
7.1
LIBPNG Multiple Products

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files

2025-11-26
CVE-2025-64709
Analyzed
9.6
Kubernetes Multiple Products

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook bloc...

2025-11-14
CVE-2025-64701
7.8
QND Multiple Products

QND Premium/Advance/Standard Ver

2025-12-12