23871 Total CVEs
23776 AI Analyzed
336 CISA KEV
5459 Critical
All Vendors
Showing 22251-22300 of 23871 CVEs Page 446 of 478
CVE-2025-10078
Analyzed
7.3
SourceCodester Online Polling System

A vulnerability was detected in SourceCodester Online Polling System 1

2025-09-08
CVE-2025-10077
Analyzed
7.3
SourceCodester Online Polling System

A security vulnerability has been detected in SourceCodester Online Polling System 1

2025-09-08
CVE-2025-10076
Analyzed
7.3
SourceCodester Online Polling System

A weakness has been identified in SourceCodester Online Polling System 1

2025-09-08
CVE-2025-10068
Analyzed
7.3
itsourcecode Online Discussion Forum

A flaw has been found in itsourcecode Online Discussion Forum 1

2025-09-07
CVE-2025-10062
Analyzed
7.3
itsourcecode Student Information Management System

A vulnerability was determined in itsourcecode Student Information Management System 1

2025-09-07
CVE-2025-10058
Analyzed
8.1
smackcoders

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va...

2025-09-17
CVE-2025-10057
Analyzed
8.8
smackcoders

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi...

2025-09-17
CVE-2025-10051
Analyzed
7.2
themeinwp Demo Import Kit

The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and includ...

2025-10-16
CVE-2025-10041
Analyzed
9.8
ajitdas Flex QR Code Generator

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db()...

2025-10-15
CVE-2025-10040
Analyzed
7.7
smackcoders

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...

2025-09-10
CVE-2025-10035
KEV Analyzed
10
Fortra GoAnywhere MFT

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to...

2025-09-18
CVE-2025-10034
Analyzed
8.8
D-Link DIR-825

A vulnerability was found in D-Link DIR-825 1

2025-09-07
CVE-2025-10033
Analyzed
7.3
itsourcecode Online Discussion Forum

A vulnerability has been found in itsourcecode Online Discussion Forum 1

2025-09-07
CVE-2025-10031
Analyzed
7.3
Campcodes Grocery Sales and Inventory System

A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1

2025-09-07
CVE-2025-10030
Analyzed
7.3
Campcodes Grocery Sales and Inventory System

A weakness has been identified in Campcodes Grocery Sales and Inventory System 1

2025-09-07
CVE-2025-10024
Analyzed
7.5
EXERT Computer Technologies Software Education Management System

Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd

2026-01-23
CVE-2025-10020
Analyzed
9.9
Zohocorp ManageEngine ADManager Plus

Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script componen...

2025-10-21
CVE-2025-10004
Analyzed
7.5
GitLab GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13

2025-10-09
CVE-2025-0987
Analyzed
9.9
CB Project CVLand

Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection.This issue affects CVLand: fro...

2025-11-04
CVE-2025-0928
Analyzed
8.8
Canonical Juju

In Juju versions prior to 3

2025-07-10
CVE-2025-0886
Analyzed
7.8

An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to escalate priv...

2025-07-17
CVE-2025-0831
Analyzed
7.8
Dassault Systèmes SOLIDWORKS eDrawings

Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-0712
Analyzed
7
Elastic APM Server

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions

2025-07-30
CVE-2025-0645
Analyzed
7.2
Narkom Communication Pyxis Signage

Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd

2025-11-20
CVE-2025-0643
Analyzed
7.2
Narkom Communication Pyxis Signage

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Communication and Software Technol...

2025-11-20
CVE-2025-0636
Analyzed
8.4
Ericsson Site Controller 6610

EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Arb...

2025-10-13
CVE-2025-0616
Analyzed
8.2
Teknolojik Center Telecommunication Industry Trade B2B - Netsis Panel

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center Telecommunication Industry Tra...

2025-10-03
CVE-2025-0610
Analyzed
8.6
Akınsoft QR Menü

Cross-Site Request Forgery (CSRF) vulnerability in Akınsoft QR Menü allows Cross Site Request Forgery

2025-09-02
CVE-2025-0603
Analyzed
9.8
Callvision Healthcare Callvision Emergency Code

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code...

2025-10-07
CVE-2025-0280
Analyzed
7.5
HCL Software Compass

A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access

2025-09-03
CVE-2025-0248
Analyzed
8.1
HCL Software iNotes

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input

2025-11-26
CVE-2025-0093
Analyzed
7.5
Google Android

In handleBondStateChanged of AdapterService

2025-08-27
CVE-2025-0089
Analyzed
7.8
Google Android

In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code

2025-09-05
CVE-2025-0084
Analyzed
8.8
Google Android

In multiple locations, there is a possible out of bounds write due to a use after free

2025-08-27
CVE-2025-0081
Analyzed
7.5
Google Android

In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg

2025-08-27
CVE-2025-0080
Analyzed
7.8
Google Android

In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack

2025-08-27
CVE-2025-0079
Analyzed
7.8
Google Android

In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error in the code

2025-08-27
CVE-2025-0078
Analyzed
8.8
Google Android

In main of main

2025-08-27
CVE-2025-0075
Analyzed
9.8
Google Android

In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to rem...

2025-08-27
CVE-2025-0074
Analyzed
9.8
Google Android

In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote...

2025-08-27
CVE-2025-0032
Analyzed
7.2
AMD AMD EPYC™ 9005 Series Processors

Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potent...

2025-09-07
CVE-2025-0005
Analyzed
7.3
AMD Xilinx Run Time (XRT)

Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in crash...

2025-11-25
CVE-2025-0003
Analyzed
7.3
AMD Xilinx Run Time (XRT)

Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition potentially resulting in loss of co...

2025-11-25
CVE-2024-9684
Analyzed
7.5
FreyrSCADA IEC-60870-5-104

FreyrSCADA/IEC-60870-5-104 server v21

2025-12-24
CVE-2024-9408
Analyzed
9.8
Eclipse Foundation Eclipse Glassfish

In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.

2025-07-16
CVE-2024-9342
Analyzed
9.8
Eclipse Foundation Eclipse Glassfish

In Eclipse GlassFish version 7.0.16 or earlier it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed l...

2025-07-16
CVE-2024-9183
Analyzed
7.7
GitLab GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18

2025-12-06
CVE-2024-9126
Analyzed
7.5
Google Chrome

Use after free in Internals in Google Chrome on iOS prior to 127

2025-11-15
CVE-2024-8419
7.5
ifm electronic ifm Smart PLC AC402s

The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authent...

2025-07-06
CVE-2024-8069
KEV Analyzed
9.5
Citrix Session Recording Citrix Session Recording

Citrix Session Recording Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.

2025-08-25