24458 Total CVEs
24363 AI Analyzed
343 CISA KEV
5636 Critical
All Vendors
Showing 20701-20750 of 24458 CVEs Page 415 of 490
CVE-2025-30628
Analyzed
8.5
AA-Team

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Pag...

2026-01-01
CVE-2025-30519
Analyzed
9.8
Dover Fueling Solutions ProGauge MagLink LX 4

Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An a...

2025-09-18
CVE-2025-30513
Analyzed
7.9
Unknown TDX Module

Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege

2026-02-11
CVE-2025-30479
Analyzed
8.4
Dell CloudLink

Dell CloudLink, versions prior to 8

2025-11-06
CVE-2025-3046
Analyzed
7.5
run-llama run-llama/llama index

A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0

2025-07-07
CVE-2025-30416
Analyzed
10
Acronis Acronis Cyber Protect 16

Acronis Cyber Protect (Linux and Windows) is vulnerable to sensitive data disclosure and manipulation due to missing authorization in versions 15 and...

2026-02-20
CVE-2025-30412
Analyzed
10
Acronis Acronis Cyber Protect 16

Acronis Cyber Protect (Linux and Windows) suffers from an improper authentication vulnerability allowing sensitive data disclosure and manipulation in...

2026-02-20
CVE-2025-30411
Analyzed
10
Acronis Acronis Cyber Protect 16

Acronis Cyber Protect (Linux and Windows) is vulnerable to sensitive data disclosure and manipulation due to improper authentication in versions 15 an...

2026-02-20
CVE-2025-30410
Analyzed
9.8
Acronis Acronis Cyber Protect Cloud Agent

Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linu...

2026-02-20
CVE-2025-30398
Analyzed
8.1
Microsoft Nuance PowerScribe 360 version 4.0.1

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network

2025-11-13
CVE-2025-30276
Analyzed
8.8
QNAP Systems Qsync Central

An out-of-bounds write vulnerability has been reported to affect Qsync Central

2026-02-12
CVE-2025-30269
Analyzed
8.1
QNAP Systems Qsync Central

A use of externally-controlled format string vulnerability has been reported to affect Qsync Central

2026-02-12
CVE-2025-30256
Analyzed
8.6
Tenda AC6 V5.0

A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5

2025-08-20
CVE-2025-30255
Analyzed
8.2
Intel Intel(R) PROSet/Wireless WiFi Software for Windows

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23

2025-11-13
CVE-2025-3025
Analyzed
7.3
Gen Digital CCleaner

Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6

2025-09-15
CVE-2025-30241
Analyzed
8.6
TP-Link HB810(US2) V1.0/1.6/2.0/2.6

Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to sys...

2026-08-11
CVE-2025-30239
Analyzed
8.5
TP-Link HB810(US2) V1.0/1.6/2.0/2.6

In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an...

2026-08-11
CVE-2025-30238
Analyzed
8.6
TP-Link HB810(US2) V1.0/1.6/2.0/2.6

In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged opera...

2026-08-11
CVE-2025-30237
Analyzed
8.7
TP-Link HB810(US2) V1.0/1.6/2.0/2.6

The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certai...

2026-08-11
CVE-2025-30201
Analyzed
7.7
wazuh wazuh

Wazuh is a free and open source platform used for threat prevention, detection, and response

2025-11-22
CVE-2025-30189
Analyzed
7.4
Open-Xchange OX Dovecot Pro

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for the...

2025-10-31
CVE-2025-30188
Analyzed
7.5
Open-Xchange OX App Suite

Malicious or unintentional API requests can be used to add significant amount of data to caches

2025-10-31
CVE-2025-30185
Analyzed
7.9
Intel Intel UEFI reference platforms

Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege

2025-11-13
CVE-2025-30156
Analyzed
8.9
ceph ceph

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authe...

2026-08-28
CVE-2025-30127
Analyzed
9.8
Unknown

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video re...

2025-08-07
CVE-2025-3012
Analyzed
7.5
Unisoc T8100/T9100/T8200/T8300

In dpc modem, there is a possible system crash due to null pointer dereference

2025-12-02
CVE-2025-30105
Analyzed
8.8
Dell XtremIO

Dell XtremIO, version(s) 6

2025-07-30
CVE-2025-30099
Analyzed
7.8
Dell PowerProtect Data Domain Feature Release

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7

2025-08-05
CVE-2025-30033
Analyzed
7.8
Siemens Automation License Manager V6.0

The affected setup component is vulnerable to DLL hijacking

2025-08-12
CVE-2025-30028
Analyzed
8.6
Synology Active Backup for Business

A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files

2026-05-29
CVE-2025-30007
Analyzed
8.8
hestiacp hestiacp

HestiaCP before 1

2026-07-11
CVE-2025-30001
Analyzed
7.3
Apache Apache StreamPark

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark

2025-10-10
CVE-2025-29992
Analyzed
7.5
Mahara

Mahara before 24

2025-08-27
CVE-2025-29846
Analyzed
7.2
Synology Synology Router Manager (SRM)

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages

2025-12-05
CVE-2025-29745
Analyzed
7.5
Unknown

A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024

2025-08-05
CVE-2025-29635
KEV Analyzed
9.5
D-Link DIR-823X

D-Link DIR-823X Command Injection Vulnerability - Active in CISA KEV catalog.

2026-04-25
CVE-2025-29556
Analyzed
7.3
ExaGrid

ExaGrid EX10 6

2025-07-31
CVE-2025-29534
Analyzed
8.8
Unknown

An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1

2025-07-28
CVE-2025-29523
Analyzed
7.2

D-Link DSL-7740C with firmware DSL7740C

2025-08-25
CVE-2025-29516
Analyzed
7.2

D-Link DSL-7740C with firmware DSL7740C

2025-08-25
CVE-2025-29515
Analyzed
9.8

Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitra...

2025-08-25
CVE-2025-29514
Analyzed
9.8

Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to download the conf...

2025-08-25
CVE-2025-29421
Analyzed
7.5
PerfreeBlog

PerfreeBlog v4

2025-08-26
CVE-2025-29420
Analyzed
7.5
PerfreeBlog

PerfreeBlog v4

2025-08-26
CVE-2025-29365
Analyzed
9.8
Unknown

spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.

2025-08-23
CVE-2025-2932
Analyzed
8.8
jkdevstudio JKDEVKIT

The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' funct...

2025-07-05
CVE-2025-29296
Analyzed
9.8
H3C

Multiple H3C network devices contain command injection vulnerabilities in the /api/esps request handler, allowing unauthenticated remote attackers to...

2026-08-05
CVE-2025-2928
Analyzed
7.2
Genetec Genetec Security Center

SQL Injection affecting the Archiver role

2025-07-29
CVE-2025-29270
Analyzed
10
Unknown

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the...

2025-10-31
CVE-2025-29229
Analyzed
9.8

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

2025-12-24