8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 2401-2450 of 8341 CVEs Page 49 of 167
CVE-2025-62525
7.9
Linux Multiple Products

OpenWrt Project is a Linux operating system targeting embedded devices

2025-10-22
CVE-2025-62521
Analyzed
10
HP Multiple Products

ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's...

2025-12-18
CVE-2025-62519
Analyzed
7.2
HP Multiple Products

phpMyFAQ is an open source FAQ web application

2025-11-18
CVE-2025-62518
8.1
Unknown Multiple Products

astral-tokio-tar is a tar archive reading/writing library for async Rust

2025-10-21
CVE-2025-62516
Analyzed
9.8
Landlord Onboarding Multiple Products

Landlord Onboarding & Rental Signup introduces the landlord onboarding workflow and rental signup system for VivaTurbo Rentals & Property Services. In...

2025-10-27
CVE-2025-62515
9.8
Unknown Multiple Products

pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() t...

2025-10-17
CVE-2025-62514
8.3
Parsec Multiple Products

Parsec is a cloud-based application for cryptographically secure file sharing

2026-01-30
CVE-2025-62510
Analyzed
8.1
HP Multiple Products

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations

2025-10-20
CVE-2025-62509
Analyzed
8.1
HP Multiple Products

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations

2025-10-20
CVE-2025-62506
8.1
MinIO Multiple Products

MinIO is a high-performance object storage system

2025-10-16
CVE-2025-62498
8.8
Unknown Multiple Products

A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4

2025-10-23
CVE-2025-62484
8.1
Zoom Multiple Products

Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6

2025-11-14
CVE-2025-62481
Analyzed
9.8
Oracle Multiple Products

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected...

2025-10-21
CVE-2025-6248
7.4
Unknown Multiple Products

A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sensitive information if a user v...

2025-07-17
CVE-2025-62474
Analyzed
7.8
Microsoft Multiple Products

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62472
Analyzed
7.8
Microsoft Multiple Products

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62470
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62467
7.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62466
7.8
Microsoft Multiple Products

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62464
7.8
Microsoft Multiple Products

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62462
7.8
Microsoft Multiple Products

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62461
7.8
Microsoft Multiple Products

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62459
Analyzed
8.3
Microsoft Multiple Products

Microsoft Defender Portal Spoofing Vulnerability

2025-11-20
CVE-2025-62458
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62457
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62456
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network

2025-12-10
CVE-2025-62455
7.8
Microsoft Multiple Products

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62454
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62452
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-11-13
CVE-2025-62429
7.2
ClipBucket Multiple Products

ClipBucket v5 is an open source video sharing platform

2025-10-20
CVE-2025-62425
Analyzed
8.3
MAS Multiple Products

MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element

2025-10-16
CVE-2025-6242
7.1
Unknown Multiple Products

A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set

2025-10-07
CVE-2025-62406
8.1
Piwigo Multiple Products

Piwigo is a full featured open source photo gallery application for the web

2025-11-19
CVE-2025-62399
7.5
Unknown Multiple Products

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-fo...

2025-10-23
CVE-2025-62382
7.7
Frigate Multiple Products

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras

2025-10-16
CVE-2025-6238
8
WordPress Multiple Products

The AI Engine plugin for WordPress is vulnerable to open redirect in version 2

2025-07-06
CVE-2025-62371
7.4
OpenSearch Multiple Products

OpenSearch Data Prepper as an open source data collector for observability data

2025-10-16
CVE-2025-62370
Analyzed
7.5
Alloy Multiple Products

Alloy Core libraries at the root of the Rust Ethereum ecosystem

2025-10-16
CVE-2025-6237
Analyzed
9.8
Unknown Multiple Products

A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file deletion via the GET /api/v1/imag...

2025-09-18
CVE-2025-62368
Analyzed
9
Intel Multiple Products

Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerability exists in the Taiga API due...

2025-10-28
CVE-2025-62363
7.8
Unknown Multiple Products

yt-grabber-tui is a terminal user interface application for downloading videos

2025-10-13
CVE-2025-62356
7.5
Unknown Multiple Products

A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside of current...

2025-10-17
CVE-2025-62354
Analyzed
9.8
Unknown Multiple Products

Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands...

2025-11-27
CVE-2025-62353
9.8
Unknown Multiple Products

A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of cu...

2025-10-17
CVE-2025-62348
7.8
Unknown Multiple Products

Salt's junos execution module contained an unsafe YAML decode/load usage

2026-01-31
CVE-2025-6232
7.8
Unknown Multiple Products

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with el...

2025-07-17
CVE-2025-6231
7.8
Unknown Multiple Products

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with el...

2025-07-17
CVE-2025-62291
8.1
Unknown Multiple Products

In the eap-mschapv2 plugin (client-side) in strongSwan before 6

2026-01-17
CVE-2025-62290
7.2
Oracle Multiple Products

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage)

2025-10-21
CVE-2025-62232
7.5
Sensitive Multiple Products

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log...

2025-10-31