8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 3351-3400 of 8341 CVEs Page 68 of 167
CVE-2025-57615
7.5
Unknown Multiple Products

An issue was discovered in rust-ffmpeg 0

2025-09-03
CVE-2025-57614
7.5
Unknown Multiple Products

An issue was discovered in rust-ffmpeg 0

2025-09-03
CVE-2025-57613
7.5
Unknown Multiple Products

An issue was discovered in rust-ffmpeg 0

2025-09-03
CVE-2025-57612
7.5
Unknown Multiple Products

An issue was discovered in rust-ffmpeg 0

2025-09-02
CVE-2025-57605
Analyzed
8.8
Lack Multiple Products

Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by...

2025-09-23
CVE-2025-57602
Analyzed
9.8
Unknown Multiple Products

Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, a...

2025-09-23
CVE-2025-57601
Analyzed
9.8
Unknown Multiple Products

AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge device...

2025-09-23
CVE-2025-57579
8
TOTOLINK Multiple Products

An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2

2025-09-12
CVE-2025-57578
Analyzed
8
H3C Multiple Products

An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password

2025-09-12
CVE-2025-57577
Analyzed
8
H3C Multiple Products

An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password

2025-09-12
CVE-2025-57567
Analyzed
9.1
HP Multiple Products

A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme...

2025-10-17
CVE-2025-57564
Analyzed
8.2
CubeAPM Multiple Products

CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/insert/elastics...

2025-10-08
CVE-2025-57528
7.7
Tenda Multiple Products

An issue was discovered in Tenda AC6 US_AC6V1

2025-09-19
CVE-2025-57515
Analyzed
9.8
Unknown Multiple Products

A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to inject arbitrary SQL commands vi...

2025-10-06
CVE-2025-57489
8.1
Unknown Multiple Products

Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3

2025-12-02
CVE-2025-57483
Analyzed
8.1
Unknown Multiple Products

A reflected cross-site scripting (XSS) vulnerability in tawk

2025-09-29
CVE-2025-5746
Analyzed
9.8
WordPress Multiple Products

The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...

2025-07-06
CVE-2025-57457
8.8
Unknown Multiple Products

An OS Command Injection vulnerability in the Admin panel in Curo UC300 5

2025-10-08
CVE-2025-57446
7.5
Subscription Multiple Products

An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a denial of service (DoS) via a craf...

2025-09-26
CVE-2025-57441
Analyzed
9.8
Unknown Multiple Products

The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upo...

2025-09-22
CVE-2025-57437
Analyzed
9.8
Unknown Multiple Products

The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected,...

2025-09-22
CVE-2025-57434
8.8
Unknown Multiple Products

Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation

2025-09-22
CVE-2025-57432
Analyzed
9.8
Unknown Multiple Products

Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows remote attackers...

2025-09-23
CVE-2025-57430
7.5
Creabox Multiple Products

Creacast Creabox Manager 4

2025-09-23
CVE-2025-57424
7.3
Unknown Multiple Products

A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field

2025-09-29
CVE-2025-57403
Analyzed
7.5
Cola Multiple Products

Cola Dnslog v1

2025-12-27
CVE-2025-57393
8.8
Unknown Multiple Products

A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2

2025-10-01
CVE-2025-57392
7.8
BenimPOS Multiple Products

BenimPOS Masaustu 3

2025-09-10
CVE-2025-57350
8.6
Unknown Multiple Products

The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in...

2025-09-24
CVE-2025-57323
7.5
Unknown Multiple Products

mpregular is a package that provides a small program development framework based on RegularJS

2025-09-24
CVE-2025-57318
7.5
Unknown Multiple Products

A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5

2025-09-25
CVE-2025-57317
Analyzed
7.5
Intel Multiple Products

apidoc-core is the core parser library to generate apidoc result following the apidoc-spec

2025-09-25
CVE-2025-57310
8.8
Unknown Multiple Products

A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1

2025-11-14
CVE-2025-57295
8
H3C Multiple Products

H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials

2025-09-19
CVE-2025-57293
8.8
Unknown Multiple Products

A command injection vulnerability in COMFAST CF-XR11 (firmware V2

2025-09-19
CVE-2025-57285
Analyzed
9.8
Unknown Multiple Products

codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the...

2025-09-08
CVE-2025-57283
7.8
Unknown Multiple Products

The Node

2026-01-30
CVE-2025-57266
Analyzed
9.8
Unknown Multiple Products

An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sen...

2025-09-30
CVE-2025-57248
7.3
Unknown Multiple Products

A null pointer dereference vulnerability was discovered in SumatraPDF 3

2025-09-15
CVE-2025-57247
Analyzed
9.1
Unknown Multiple Products

The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorrect access...

2025-10-06
CVE-2025-57227
7.8
Unknown Multiple Products

An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1

2025-10-29
CVE-2025-57215
7.5
Tenda Multiple Products

Tenda AC10 v4

2025-08-28
CVE-2025-57213
7.5
Unknown Multiple Products

Incorrect access control in the component orderService

2025-12-06
CVE-2025-57212
7.5
Unknown Multiple Products

Incorrect access control in the component ApiOrderService

2025-12-06
CVE-2025-57210
7.5
Unknown Multiple Products

Incorrect access control in the component ApiPayController

2025-12-06
CVE-2025-57201
8.8
SMB Multiple Products

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB...

2025-12-03
CVE-2025-57199
8.8
NetFailDetectD Multiple Products

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetF...

2025-12-03
CVE-2025-57198
8.8
AVTECH Multiple Products

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Mach...

2025-12-03