8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 2951-3000 of 8341 CVEs Page 60 of 167
CVE-2025-59740
Analyzed
9.8
Unknown Multiple Products

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands...

2025-10-02
CVE-2025-59739
Analyzed
9.8
Unknown Multiple Products

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands...

2025-10-02
CVE-2025-59738
Analyzed
9.8
HP Multiple Products

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands...

2025-10-02
CVE-2025-59737
Analyzed
9.8
Unknown Multiple Products

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands...

2025-10-02
CVE-2025-59736
Analyzed
9.8
Unknown Multiple Products

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands...

2025-10-02
CVE-2025-59735
Analyzed
9.8
Unknown Multiple Products

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands...

2025-10-02
CVE-2025-59719
Analyzed
9.8
Fortinet Multiple Products

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4...

2025-12-10
CVE-2025-59718
KEV Analyzed
9.8
Apple Multiple Products

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 t...

2025-12-10
CVE-2025-59703
9.1
Entrust nShield Connect Multiple Products

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal compon...

2025-12-04
CVE-2025-59702
7.2
HSMi Multiple Products

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13

2025-12-03
CVE-2025-59697
7.2
HSMi Multiple Products

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13

2025-12-03
CVE-2025-59693
9.8
Unknown Multiple Products

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attac...

2025-12-04
CVE-2025-59689
KEV
9.5
Libraesva Email Security Gateway

Libraesva Email Security Gateway Command Injection Vulnerability - Active in CISA KEV catalog.

2025-09-29
CVE-2025-59684
Analyzed
8.8
DigiSigner Multiple Products

DigiSign DigiSigner ONE 1

2025-10-01
CVE-2025-59683
8.2
Pexip Multiple Products

Pexip Infinity 15

2025-12-25
CVE-2025-59681
7.1
Unknown Multiple Products

An issue was discovered in Django 4

2025-10-01
CVE-2025-59668
7.5
Unknown Multiple Products

Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability

2025-09-30
CVE-2025-5965
7.2
Unknown Multiple Products

In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup

2026-01-06
CVE-2025-59588
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad allows PH...

2025-09-22
CVE-2025-59580
Analyzed
8.8
GoodLayers Goodlayers Multiple Products

Incorrect Privilege Assignment vulnerability in GoodLayers Goodlayers Core goodlayers-core allows Privilege Escalation

2025-10-23
CVE-2025-59579
7.5
PressTigers Simple Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Da...

2025-10-23
CVE-2025-59578
7.5
Unknown Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Retrieve Embedded Sensitive Data

2025-10-22
CVE-2025-59572
Analyzed
8.8
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core allows Cross Site Request Forgery

2025-09-22
CVE-2025-59570
Analyzed
7.6
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint allows SQL Injection

2025-09-22
CVE-2025-59566
7.6
AmentoTech Workreap Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows P...

2025-10-22
CVE-2025-59564
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall all...

2025-10-23
CVE-2025-59558
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allow...

2025-10-23
CVE-2025-59557
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts Addons learts-addons allows SQL...

2025-10-23
CVE-2025-59555
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Medizin medizin all...

2025-10-23
CVE-2025-59550
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allo...

2025-10-23
CVE-2025-5955
Analyzed
8.1
WordPress Multiple Products

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2

2025-09-19
CVE-2025-59545
Analyzed
9
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt modu...

2025-09-23
CVE-2025-5954
Analyzed
9.8
WordPress Multiple Products

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2....

2025-08-01
CVE-2025-59538
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59537
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59534
Analyzed
7.3
CryptoLib Multiple Products

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2025-09-23
CVE-2025-59531
Analyzed
7.5
Kubernetes Multiple Products

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes

2025-10-01
CVE-2025-59530
7.5
Unknown Multiple Products

quic-go is an implementation of the QUIC protocol in Go

2025-10-10
CVE-2025-5953
Analyzed
8.8
WordPress Multiple Products

The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee()...

2025-07-05
CVE-2025-59528
Analyzed
10
Unknown Multiple Products

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execut...

2025-09-22
CVE-2025-59527
7.5
Unknown Multiple Products

Flowise is a drag & drop user interface to build a customized large language model flow

2025-09-22
CVE-2025-59518
8
Unknown Multiple Products

In LemonLDAP::NG before 2

2025-09-17
CVE-2025-59517
7.8
Microsoft Multiple Products

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-59516
7.8
Microsoft Multiple Products

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-59514
7.8
Microsoft Multiple Products

Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59512
7.8
Unknown Multiple Products

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59511
7.8
Microsoft Multiple Products

External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59505
7.8
Microsoft Multiple Products

Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59503
Analyzed
9.9
Microsoft Multiple Products

Server-side request forgery (ssrf) in Azure Compute Gallery allows an authorized attacker to elevate privileges over a network.

2025-10-23