25704 Total CVEs
25609 AI Analyzed
356 CISA KEV
5950 Critical
All Vendors
Showing 20451-20500 of 25704 CVEs Page 410 of 515
CVE-2025-52513
Analyzed
7.5
Processor

An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500

2025-11-04
CVE-2025-52496
Analyzed
7.8
Mbed mbedtls

Mbed TLS before 3

2025-07-06
CVE-2025-52494
Analyzed
7.5
Web

Adacore Ada Web Server (AWS) before 25

2025-09-03
CVE-2025-52490
Analyzed
7.3
Sync

An issue was discovered in Couchbase Sync Gateway before 3

2025-07-29
CVE-2025-52482
Analyzed
8.3
chamilo chamilo-lms

Chamilo is a learning management system

2026-03-03
CVE-2025-52478
Analyzed
8.7
n8n-io n8n

n8n is a workflow automation platform

2025-08-19
CVE-2025-52469
Analyzed
7.1
chamilo chamilo-lms

Chamilo is a learning management system

2026-03-03
CVE-2025-52468
Analyzed
8.8
chamilo chamilo-lms

Chamilo is a learning management system

2026-03-03
CVE-2025-52461
Analyzed
8.2
The Biosig Project libbiosig

An out-of-bounds read vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3

2025-08-25
CVE-2025-52456
Analyzed
8.8
SAIL Image Decoding Library SAIL Image Decoding Library

A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0

2025-08-25
CVE-2025-52451
Analyzed
8.5
Salesforce Tableau Server

Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allo...

2025-08-23
CVE-2025-52436
Analyzed
8.8
Fortinet FortiSandbox

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox...

2026-02-11
CVE-2025-5243
Analyzed
10
SMG Software Information Portal

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabil...

2025-07-25
CVE-2025-52395
Analyzed
9.8
Unknown

An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails...

2025-08-21
CVE-2025-52390
Analyzed
9.1
Unknown

Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in...

2025-08-01
CVE-2025-52389
Analyzed
8.8
Insecure

An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40

2025-09-08
CVE-2025-52385
Analyzed
9.8
Unknown

An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process module

2025-08-14
CVE-2025-52376
Analyzed
9.8
Unknown

An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, al...

2025-07-15
CVE-2025-52365
Analyzed
7.8
Unknown

A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary system comma...

2026-03-04
CVE-2025-52364
Analyzed
7.5
Tenda Insecure

Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22

2025-07-11
CVE-2025-52353
Analyzed
9.8
Unknown

An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP c...

2025-08-27
CVE-2025-52352
Analyzed
9.8
Unknown

Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-...

2025-08-21
CVE-2025-52351
Analyzed
8.8
Aikaan

Aikaan IoT management platform v3

2025-08-21
CVE-2025-52347
Analyzed
7.8
Unknown

An issue in the component DirectIo64

2026-05-02
CVE-2025-52293
Analyzed
7.5
GPAC GPAC (media tools/av parsers)

A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers

2026-06-15
CVE-2025-52292
Analyzed
7.5
Unknown

A stack buffer overflow in the filein_process function (in_file

2026-06-15
CVE-2025-52289
Analyzed
8
Unknown

A Broken Access Control vulnerability in MagnusBilling v7

2025-07-31
CVE-2025-52288
Analyzed
7.5
Assertion

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build

2025-09-08
CVE-2025-52287
Analyzed
8.8
Script

OperaMasks SDK ELite Script Engine v0

2025-08-23
CVE-2025-52268
Analyzed
7.5
StarCharge

StarCharge Artemis AC Charger 7-22 kW v1

2025-10-27
CVE-2025-52263
Analyzed
8
Unknown

An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1

2025-10-27
CVE-2025-52239
Analyzed
9.8
Unknown

An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.

2025-08-05
CVE-2025-52218
Analyzed
7.5
Platform

SelectZero Data Observability Platform before 2025

2025-08-27
CVE-2025-52203
Analyzed
7.6
Unknown

A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1

2025-07-31
CVE-2025-52196
Analyzed
7.5
Unknown

Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8

2025-12-18
CVE-2025-52194
Analyzed
7.5
Unknown

A buffer overflow vulnerability exists in libsndfile version 1

2025-08-21
CVE-2025-52187
Analyzed
8.2
Unknown

GetProjectsIdea Create School Management System 1

2025-07-30
CVE-2025-52161
Analyzed
9.8
Unknown

Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.

2025-09-08
CVE-2025-52159
Analyzed
8.8
Hardcoded

Hardcoded credentials in default configuration of PPress 0

2025-09-19
CVE-2025-52122
Analyzed
9.8
Freeform

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code...

2025-08-27
CVE-2025-52101
Analyzed
9.8
Unknown

linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authenticati...

2025-07-06
CVE-2025-52099
Analyzed
7.5
SQLite Integer

Integer Overflow vulnerability in SQLite SQLite3 v

2025-10-24
CVE-2025-52079
Analyzed
8.8

The administrator password setting of the D-Link DIR-820L 1

2025-10-22
CVE-2025-52053
Analyzed
9.8

TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter....

2025-09-15
CVE-2025-52044
Analyzed
7.5

In Frappe ERPNext v15

2025-09-17
CVE-2025-52042
Analyzed
8.2

In Frappe ERPNext 15

2025-10-01
CVE-2025-52041
Analyzed
8.2

In Frappe ERPNext 15

2025-10-01
CVE-2025-52040
Analyzed
8.2

In Frappe ERPNext 15

2025-10-01
CVE-2025-52039
Analyzed
8.2

In Frappe ERPNext 15

2025-10-01
CVE-2025-52021
Analyzed
9.8
Unknown

A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter...

2025-10-08