24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 21051-21100 of 24021 CVEs Page 422 of 481
CVE-2025-14936
Analyzed
7.8
NSF Unidata NetCDF-C

NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14935
Analyzed
7.8
NSF Unidata NetCDF-C

NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14934
Analyzed
7.8
NSF Unidata NetCDF-C

NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14933
Analyzed
7.8
NSF Unidata NetCDF-C

NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14932
Analyzed
7.8
NSF Unidata NetCDF-C

NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14931
Analyzed
10
Hugging Face smolagents

Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote...

2025-12-24
CVE-2025-14930
Analyzed
7.8
Hugging Face Transformers

Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14929
Analyzed
7.8
Hugging Face Transformers

Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14928
Analyzed
7.8
Hugging Face Transformers

Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14927
Analyzed
7.8
Hugging Face Transformers

Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14926
Analyzed
7.8
Hugging Face Transformers

Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14925
Analyzed
7.8
Hugging Face Accelerate

Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14924
Analyzed
7.8
Hugging Face Transformers

Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14922
Analyzed
7.8
Hugging Face Diffusers

Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14921
Analyzed
7.8
Hugging Face Transformers

Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14920
Analyzed
7.8
Hugging Face Transformers

Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14914
Analyzed
7.6
IBM WebSphere Application Server Liberty

IBM WebSphere Application Server Liberty 17

2026-02-03
CVE-2025-14905
Analyzed
7.2

A flaw was found in the 389-ds-base server

2026-02-24
CVE-2025-14896
Analyzed
7.5
yuzutech kroki

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array

2025-12-20
CVE-2025-14894
Analyzed
7.5
bee interactive Livewire Filemanager

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent

2026-01-18
CVE-2025-14892
Analyzed
9.8
WordPress Prime Listing Manager

The Prime Listing Manager plugin for WordPress contains a hardcoded secret that allows unauthenticated attackers to gain administrative access to the...

2026-02-13
CVE-2025-14884
Analyzed
7.2
D-Link DIR-605

A vulnerability was detected in D-Link DIR-605 202WWB03

2025-12-20
CVE-2025-14879
Analyzed
9.8
Tenda WH450

A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request...

2025-12-19
CVE-2025-14878
Analyzed
9.8
Tenda WH450

A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HTT...

2025-12-19
CVE-2025-14877
Analyzed
7.3
Campcodes Supplier Management System

A vulnerability was identified in Campcodes Supplier Management System 1

2025-12-20
CVE-2025-14868
Analyzed
8.8
shahinurislam Career Section

The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versi...

2026-04-16
CVE-2025-14866
Analyzed
8.8
melapress Melapress Role Editor

The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-01-24
CVE-2025-14861
Analyzed
8.8
Mozilla Firefox

Memory safety bugs present in Firefox 146

2025-12-19
CVE-2025-14855
Analyzed
7.2
brainstormforce

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2

2025-12-21
CVE-2025-14850
Analyzed
8.1
Advantech WebAccess/SCADA

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files

2025-12-20
CVE-2025-14849
Analyzed
8.8
Advantech WebAccess/SCADA

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code

2025-12-19
CVE-2025-14847
KEV Analyzed
7.5
MongoDB MongoDB Server

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client

2025-12-20
CVE-2025-14844
Analyzed
8.2
stellarwp Membership Plugin – Restrict Content

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3

2026-01-17
CVE-2025-14840
Analyzed
7.5
Drupal HTTP Client Manager

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing

2026-01-30
CVE-2025-14835
Analyzed
7.1
opajaap WP Photo Album Plus

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and...

2026-01-08
CVE-2025-14833
Analyzed
7.3
code-projects Online Appointment Booking System

A security flaw has been discovered in code-projects Online Appointment Booking System 1

2025-12-18
CVE-2025-14832
Analyzed
7.3
itsourcecode Online Cake Ordering System

A vulnerability was identified in itsourcecode Online Cake Ordering System 1

2025-12-18
CVE-2025-14829
Analyzed
9.1
WordPress E-xact | Hosted Payment |

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This mak...

2026-01-14
CVE-2025-14821
Analyzed
7.8
Red Hat Red Hat Hardened Images

A flaw was found in libssh

2026-04-08
CVE-2025-14812
Analyzed
7.5
The Browser Company of New York ArcSearch

ArcSearch for iOS versions prior to 1

2025-12-20
CVE-2025-14809
Analyzed
7.4
The Browser Company of New York ArcSearch

ArcSearch for Android versions prior to 1

2025-12-20
CVE-2025-14804
Analyzed
7.7
WordPress Frontend File Manager Plugin

The Frontend File Manager Plugin WordPress plugin before 23

2026-01-08
CVE-2025-14800
Analyzed
8.1
Themeisle Redirection for Contact Form 7

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_...

2025-12-21
CVE-2025-14772
Analyzed
8.8
ABB T-MAC Plus

Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus

2026-06-04
CVE-2025-14771
Analyzed
9.9
ABB T-MAC Plus

A vulnerability in ABB T-MAC Plus allows unauthorized external parties to access restricted files or directories.

2026-06-04
CVE-2025-14769
Analyzed
7.5
FreeBSD FreeBSD

In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine

2026-03-10
CVE-2025-14765
Analyzed
8.8
Google Chrome

Use after free in WebGPU in Google Chrome prior to 143

2025-12-18
CVE-2025-14741
Analyzed
9.1
shabti Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a m...

2026-01-10
CVE-2025-14736
Analyzed
9.8
shabti Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due...

2026-01-09
CVE-2025-14733
KEV Analyzed
9.8
WatchGuard Fireware OS

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerabili...

2025-12-20