8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 4001-4050 of 8341 CVEs Page 81 of 167
CVE-2025-53766
Analyzed
9.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

2025-08-12
CVE-2025-53763
Analyzed
9.8
Microsoft Multiple Products

Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

2025-08-21
CVE-2025-53761
7.8
Microsoft Multiple Products

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53759
7.8
Microsoft Multiple Products

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53741
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53740
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53739
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53738
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53737
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53735
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53734
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53733
8.4
Microsoft Multiple Products

Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53732
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53731
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53730
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53729
7.8
Microsoft Multiple Products

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53727
8.8
Unknown Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12
CVE-2025-53726
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53725
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53724
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53723
7.8
Microsoft Multiple Products

Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53720
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-53710
7.5
Unknown Multiple Products

Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each othe...

2025-12-20
CVE-2025-53705
Analyzed
7.8
Intel Multiple Products

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12

2025-08-19
CVE-2025-53704
7.5
Unknown Multiple Products

The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account

2025-12-05
CVE-2025-53703
7.5
DuraComm Multiple Products

DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted by attackers

2025-07-23
CVE-2025-53694
7.5
Experience Multiple Products

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (X...

2025-09-03
CVE-2025-53693
Analyzed
9.8
Unknown Multiple Products

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecor...

2025-09-03
CVE-2025-53692
Analyzed
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM)...

2025-09-22
CVE-2025-53691
Analyzed
8.8
Intel Multiple Products

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (R...

2025-09-03
CVE-2025-53690
KEV Analyzed
9
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issu...

2025-09-03
CVE-2025-53689
Analyzed
8.8
Apache Multiple Products

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2

2025-07-14
CVE-2025-53652
Analyzed
8.2
Jenkins Multiple Products

Jenkins Git Parameter Plugin 439

2025-07-10
CVE-2025-53650
Analyzed
7.3
Jenkins Multiple Products

Jenkins Credentials Binding Plugin 687

2025-07-11
CVE-2025-53645
7.5
Zimbra Multiple Products

Zimbra Collaboration Suite (ZCS) before 9

2025-07-11
CVE-2025-53629
7.5
Unknown Multiple Products

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library

2025-07-11
CVE-2025-53624
10
GitHub Multiple Products

The Docusaurus gists plugin adds a page to your Docusaurus instance, displaying all public gists of a GitHub user. docusaurus-plugin-content-gists ver...

2025-07-10
CVE-2025-53619
7.4
Grassroot Multiple Products

An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3

2025-12-17
CVE-2025-53618
7.4
Grassroot Multiple Products

An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3

2025-12-17
CVE-2025-53606
Analyzed
9.8
Apache Multiple Products

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recomme...

2025-08-08
CVE-2025-53603
7.5
Unknown Multiple Products

In Alinto SOPE SOGo 2

2025-07-06
CVE-2025-53599
9.8
Apple Multiple Products

Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.

2025-07-08
CVE-2025-53588
7.7
Dmitry Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V

2025-08-28
CVE-2025-53587
8.8
ApusTheme Findgo Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo allows Cross Site Request Forgery

2025-08-14
CVE-2025-53585
7.1
NooTheme WeMusic Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme WeMusic noo-wemusic allows Reflected XS...

2025-11-08
CVE-2025-53584
8.1
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System allows Object Injection

2025-08-28
CVE-2025-53583
8.1
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight allows Object Injection

2025-08-28
CVE-2025-53580
9.8
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Busi...

2025-08-20
CVE-2025-53579
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captcha

2025-08-28
CVE-2025-53578
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso allows PHP Local...

2025-08-28