25704 Total CVEs
25609 AI Analyzed
356 CISA KEV
5950 Critical
All Vendors
Showing 20501-20550 of 25704 CVEs Page 411 of 515
CVE-2025-51991
Analyzed
8.8
Unknown

XWiki through version 17

2025-08-20
CVE-2025-51989
Analyzed
7
Unknown

HTML injection vulnerability in the registration interface in Evolution Consulting Kft

2025-08-23
CVE-2025-51986
Analyzed
7.5
Unknown

An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v

2025-08-14
CVE-2025-51970
Analyzed
7.7
Unknown

A SQL Injection vulnerability exists in the action

2025-07-29
CVE-2025-51958
Analyzed
9.8
Unknown

aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcomma...

2026-01-31
CVE-2025-51865
Analyzed
8.8
Unknown

Ai2 playground web service (playground

2025-07-23
CVE-2025-51846
Analyzed
7.5
CryptPad CryptPad

CryptPad 2025

2026-05-01
CVE-2025-51741
Analyzed
7.5
Community

An issue was discovered in Veal98 Echo Open-Source Community System 2

2025-11-26
CVE-2025-51735
Analyzed
7.5
HCL Technologies CSV

CSV formula injection vulnerability in HCL Technologies Ltd

2025-11-29
CVE-2025-51726
Analyzed
8.4
Unknown

CyberGhostVPNSetup

2025-08-05
CVE-2025-51679
Analyzed
9.1
Unknown OR1200

A mismatch between RTL and netlist in openRISC OR1200 commit 83ac6b can lead to unexpected behavior, potentially allowing unauthorized data access or...

2026-09-02
CVE-2025-51678
Analyzed
7.5
YosysHQ PicoRV32

An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.

2026-07-23
CVE-2025-51677
Analyzed
9.1
Unknown

An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to...

2026-07-23
CVE-2025-51675
Analyzed
7.5
Unknown OR1200

An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial of...

2026-09-01
CVE-2025-51667
Analyzed
7
Unknown

An issue was discovered in simple-admin-core v1

2025-08-27
CVE-2025-51663
Analyzed
7.5
Unknown

A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2

2025-11-20
CVE-2025-51661
Analyzed
7.5
Unknown

A path Traversal vulnerability found in FileCodeBox v2

2025-11-20
CVE-2025-51630
Analyzed
9.8

TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRules.

2025-07-17
CVE-2025-51629
Analyzed
8.8
PdfViewer

A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2

2025-08-07
CVE-2025-51628
Analyzed
7.5
Unknown

Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2

2025-08-05
CVE-2025-51624
Analyzed
7.6
Zone Bitaqati thru

Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3

2025-08-07
CVE-2025-51606
Analyzed
8.8
Unknown

hippo4j 1

2025-08-23
CVE-2025-51605
Analyzed
8.1
Unknown

An issue was discovered in Shopizer 3

2025-08-23
CVE-2025-51567
Analyzed
9.1
Unknown

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary...

2026-01-13
CVE-2025-51543
Analyzed
9.8
Unknown

An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password en...

2025-08-20
CVE-2025-51536
Analyzed
9.8
Austrian Archaeological Institute

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

2025-08-05
CVE-2025-51535
Analyzed
9.1
Austrian Archaeological Institute

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.

2025-08-05
CVE-2025-51534
Analyzed
8.1
Austrian

A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8

2025-08-05
CVE-2025-51532
Analyzed
7.5
Unknown

Incorrect access control in Sage DPW v2024

2025-08-07
CVE-2025-51511
Analyzed
9.8
Cadmium CMS

Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.

2025-12-24
CVE-2025-51504
Analyzed
7.6
Microweber

Microweber CMS 2

2025-08-01
CVE-2025-51503
Analyzed
7.6
Microweber CMS

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2

2025-07-31
CVE-2025-51495
Analyzed
7.5
Unknown

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7

2025-09-29
CVE-2025-51482
Analyzed
8.8
Unknown

Remote Code Execution in letta

2025-07-23
CVE-2025-51480
Analyzed
8.8
Path Traversal

Path Traversal vulnerability in onnx

2025-07-23
CVE-2025-51464
Analyzed
8.8
Unknown

Cross-site Scripting (XSS) in aimhubio Aim 3

2025-07-23
CVE-2025-51463
Analyzed
7
Path

Path Traversal in restore_run_backup() in AIM 3

2025-07-23
CVE-2025-51452
Analyzed
9.8

In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

2025-08-14
CVE-2025-51451
Analyzed
9.8

In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

2025-08-14
CVE-2025-51427
Analyzed
7.3
Unknown

An issue was discovered in ModelScope 1

2026-05-20
CVE-2025-51390
Analyzed
9.8

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig funct...

2025-08-05
CVE-2025-51387
Analyzed
9.8
Unknown

The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure set...

2025-08-05
CVE-2025-51281
Analyzed
7

D-Link DI-8100 16

2025-08-25
CVE-2025-5120
Analyzed
7.6
huggingface huggingface/smolagents

A sandbox escape vulnerability was identified in huggingface/smolagents version 1

2025-07-28
CVE-2025-5115
Analyzed
7.5
Eclipse Jetty Eclipse Jetty

In Eclipse Jetty, versions <=9

2025-08-20
CVE-2025-51087
Analyzed
8.6

Tenda AC8V4 V16

2025-07-25
CVE-2025-51056
Analyzed
8.2
Unknown

An unrestricted file upload vulnerability in Vedo Suite version 2024

2025-08-07
CVE-2025-51055
Analyzed
8.6
Insecure

Insecure Data Storage of credentials has been found in /api_vedo/configuration/config

2025-08-07
CVE-2025-51040
Analyzed
7.5
Electrolink

Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore

2025-08-07
CVE-2025-51006
Analyzed
7.8
Within

Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxs...

2025-09-22