8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 3901-3950 of 8341 CVEs Page 79 of 167
CVE-2025-54243
7.8
Viewer Multiple Products

Substance3D - Viewer versions 0

2025-09-09
CVE-2025-54242
7.8
Pro Multiple Products

Premiere Pro versions 25

2025-09-09
CVE-2025-54236
KEV Analyzed
9.1
Adobe Multiple Products

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vul...

2025-09-09
CVE-2025-54160
7.8
Synology Multiple Products

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1

2025-12-05
CVE-2025-54159
7.5
Synology Multiple Products

Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1

2025-12-05
CVE-2025-54158
7.8
Synology Multiple Products

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1

2025-12-05
CVE-2025-54156
7.4
PACS Multiple Products

The Sante PACS Server Web Portal sends credential information without encryption

2025-08-19
CVE-2025-54145
Analyzed
9.1
Apple Multiple Products

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL...

2025-08-20
CVE-2025-54143
Analyzed
9.8
Apple Multiple Products

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page...

2025-08-20
CVE-2025-54141
7.5
ViewVC Multiple Products

ViewVC is a browser interface for CVS and Subversion version control repositories

2025-07-23
CVE-2025-54140
7.5
Download Multiple Products

pyLoad is a free and open-source Download Manager written in pure Python

2025-07-23
CVE-2025-54138
Analyzed
7.5
HP Multiple Products

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating syst...

2025-07-23
CVE-2025-54137
7.3
HAX Multiple Products

HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend

2025-07-23
CVE-2025-54136
7.2
Unknown Multiple Products

Cursor is a code editor built for programming with AI

2025-08-04
CVE-2025-54135
8.5
Cursor Multiple Products

Cursor is a code editor built for programming with AI

2025-08-05
CVE-2025-54130
7.5
Cursor Multiple Products

Cursor is a code editor built for programming with AI

2025-08-05
CVE-2025-54123
9.8
Unknown Multiple Products

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly is vulnerable to command inject...

2025-09-10
CVE-2025-54122
Analyzed
10
Unknown Multiple Products

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified i...

2025-07-22
CVE-2025-54119
Analyzed
10
HP Multiple Products

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper...

2025-08-05
CVE-2025-54117
Analyzed
9
Unknown Multiple Products

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2...

2025-08-19
CVE-2025-54113
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-09-09
CVE-2025-54111
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54110
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54106
Analyzed
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-09-09
CVE-2025-54102
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54100
7.8
Microsoft Multiple Products

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute c...

2025-12-10
CVE-2025-54098
7.8
Microsoft Multiple Products

Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54092
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevat...

2025-09-09
CVE-2025-54091
7.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54072
7.5
Unknown Multiple Products

yt-dlp is a feature-rich command-line audio/video downloader

2025-07-23
CVE-2025-54065
7.9
Doom Multiple Products

GZDoom is a feature centric port for all Doom engine games

2025-12-03
CVE-2025-54063
8
Unknown Multiple Products

Cherry Studio is a desktop client that supports for multiple LLM providers

2025-08-11
CVE-2025-54052
7.5
HP Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin allows PHP Local File Inclusion

2025-08-20
CVE-2025-54049
Analyzed
9.9
WordPress Multiple Products

Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP allows Privilege Escalation. This issue affects Custom API for WP: from n...

2025-08-20
CVE-2025-54048
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP allows SQL Injectio...

2025-08-20
CVE-2025-54043
7.6
YayCommerce SMTP Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for Amazon SES allows SQL Injec...

2025-07-16
CVE-2025-54034
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Tribulant Software Newsletter...

2025-08-20
CVE-2025-54031
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board allows...

2025-08-20
CVE-2025-54029
7.7
Unknown Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons WooCommerce csv import export allows Path Tr...

2025-08-28
CVE-2025-54028
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Saleswonder Team Tobias CF7 W...

2025-08-20
CVE-2025-54026
8.5
QuanticaLabs GymBase Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBase Theme Classes allows SQL In...

2025-07-16
CVE-2025-54021
7.5
Mitchell Bennis Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List allows Path Traversal

2025-08-20
CVE-2025-54017
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscr...

2025-08-20
CVE-2025-54014
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic allows Object Injection. This issue affects MediCen...

2025-08-20
CVE-2025-54012
7.2
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in nanbu Welcart e-Commerce allows Object Injection

2025-08-20
CVE-2025-54010
9.6
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets allows Cross Site Request Forgery. This issue affects FluentSnippets...

2025-07-16
CVE-2025-54007
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Object Injection

2025-08-20
CVE-2025-53990
7.2
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder allows Object Injection

2025-07-16
CVE-2025-53970
Analyzed
9.8
HP Multiple Products

SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS co...

2025-08-28
CVE-2025-5397
Analyzed
9.8
WordPress Multiple Products

The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_lo...

2025-10-31