8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 2901-2950 of 8341 CVEs Page 59 of 167
CVE-2025-6000
Analyzed
9.1
Unknown Multiple Products

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plu...

2025-08-01
CVE-2025-5999
7.2
Unknown Multiple Products

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileg...

2025-08-01
CVE-2025-59978
Analyzed
9
Juniper Multiple Products

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attack...

2025-10-09
CVE-2025-59975
Analyzed
7.5
Juniper Multiple Products

An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based...

2025-10-09
CVE-2025-59974
8.4
Unknown Multiple Products

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attac...

2025-10-09
CVE-2025-5997
Analyzed
8.8
HP Multiple Products

Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse

2025-07-28
CVE-2025-59968
Analyzed
8.6
Juniper Multiple Products

A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read o...

2025-10-09
CVE-2025-59964
Analyzed
7.5
Juniper Multiple Products

A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4700 devices allows an unauthen...

2025-10-09
CVE-2025-59946
Analyzed
7.5
NanoMQ Multiple Products

NanoMQ MQTT Broker (NanoMQ) is an Edge Messaging Platform

2025-12-27
CVE-2025-59945
Analyzed
8.1
SysReptor Multiple Products

SysReptor is a fully customizable pentest reporting platform

2025-09-28
CVE-2025-59944
8
Cursor Multiple Products

Cursor is a code editor built for programming with AI

2025-10-03
CVE-2025-59943
Analyzed
8.1
HP Multiple Products

phpMyFAQ is an open source FAQ web application

2025-10-03
CVE-2025-59942
7.5
Unknown Multiple Products

go-f3 is a Golang implementation of Fast Finality for Filecoin (F3)

2025-09-30
CVE-2025-59939
Analyzed
8.8
HP Multiple Products

WeGIA is a Web manager for charitable institutions

2025-09-28
CVE-2025-59936
Analyzed
9.4
Unknown Multiple Products

get-jwks contains fetch utils for JWKS keys. In versions prior to 11.0.2, a vulnerability in get-jwks can lead to cache poisoning in the JWKS key-fetc...

2025-09-28
CVE-2025-59934
Analyzed
9.4
Unknown Multiple Products

Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems...

2025-09-26
CVE-2025-59932
Analyzed
8.6
Apache Multiple Products

Flag Forge is a Capture The Flag (CTF) platform

2025-09-28
CVE-2025-59890
Analyzed
7.3
Unknown Multiple Products

Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an attac...

2025-11-28
CVE-2025-59889
8.6
Unknown Multiple Products

Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to...

2025-10-14
CVE-2025-59887
Analyzed
8.6
Unknown Multiple Products

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the...

2025-12-26
CVE-2025-59886
8.8
Unknown Multiple Products

Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the devi...

2025-12-24
CVE-2025-59870
7.4
HCL Multiple Products

HCL MyXalytics v6

2026-01-18
CVE-2025-59845
8.2
Apollo Multiple Products

Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL

2025-09-26
CVE-2025-59841
Analyzed
9.8
Unknown Multiple Products

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session inva...

2025-09-25
CVE-2025-59840
8.1
Vega Multiple Products

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs

2025-11-14
CVE-2025-59839
8.6
EmbedVideo Multiple Products

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from vario...

2025-09-25
CVE-2025-59837
7.2
Astro Multiple Products

Astro is a web framework that includes an image proxy

2025-10-29
CVE-2025-59834
Analyzed
9.8
Google Multiple Products

ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server...

2025-09-25
CVE-2025-59833
7.5
Flag Multiple Products

Flag Forge is a Capture The Flag (CTF) platform

2025-09-24
CVE-2025-59832
Analyzed
9.9
Unknown Multiple Products

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket c...

2025-09-25
CVE-2025-59830
Analyzed
7.5
Unknown Multiple Products

Rack is a modular Ruby web server interface

2025-09-25
CVE-2025-59827
8.2
Flag Multiple Products

Flag Forge is a Capture The Flag (CTF) platform

2025-09-24
CVE-2025-59826
7.6
Flag Multiple Products

Flag Forge is a Capture The Flag (CTF) platform

2025-09-23
CVE-2025-59823
Analyzed
9.9
Kubernetes Multiple Products

Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Ext...

2025-09-25
CVE-2025-59817
9.1
Unknown Multiple Products

This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successf...

2025-09-25
CVE-2025-59816
Analyzed
8.1
Unknown Multiple Products

This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, i...

2025-09-25
CVE-2025-59815
Analyzed
9.1
Unknown Multiple Products

This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting s...

2025-09-25
CVE-2025-59814
Analyzed
9.8
Unknown Multiple Products

This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them...

2025-09-25
CVE-2025-59802
Analyzed
7.5
Reader Multiple Products

Foxit PDF Editor and Reader before 2025

2025-12-12
CVE-2025-59789
Analyzed
7.5
Apache Multiple Products

Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1

2025-12-02
CVE-2025-59781
7.5
Unknown Multiple Products

When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilizati...

2025-10-16
CVE-2025-59780
Analyzed
7.5
Unknown Multiple Products

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET req...

2025-11-15
CVE-2025-59778
7.5
F5 Multiple Products

When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to termin...

2025-10-16
CVE-2025-59777
7.5
IBM Multiple Products

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1

2025-11-11
CVE-2025-59775
7.5
Microsoft Multiple Products

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to pot...

2025-12-06
CVE-2025-59745
7.5
Unknown Multiple Products

Vulnerability in the cryptographic algorithm of AndSoft's e-TMS v25

2025-10-02
CVE-2025-59744
7.5
Path traversal Multiple Products

Path traversal vulnerability in AndSoft's e-TMS v25

2025-10-02
CVE-2025-59743
Analyzed
9.8
Unknown Multiple Products

SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by...

2025-10-02
CVE-2025-59742
Analyzed
9.8
Unknown Multiple Products

SQL injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability could allow an attacker to retrieve, create, update, and delete databases by...

2025-10-02
CVE-2025-59741
Analyzed
9.8
Unknown Multiple Products

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands...

2025-10-02