8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 4901-4950 of 8341 CVEs Page 99 of 167
CVE-2025-46295
Analyzed
9.8
Apache Multiple Products

Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the te...

2025-12-17
CVE-2025-46281
8.8
Unknown Multiple Products

A logic issue was addressed with improved checks

2025-12-19
CVE-2025-46269
Analyzed
7.8
Intel Multiple Products

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12

2025-08-19
CVE-2025-46255
7.5
Marketing Fire LLC Multiple Products

Missing Authorization vulnerability in Marketing Fire LLC LoginWP - Pro allows Accessing Functionality Not Properly Constrained by ACLs

2026-01-06
CVE-2025-46205
8.1
Unknown Multiple Products

A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0

2025-10-01
CVE-2025-46183
8.2
Unknown Multiple Products

The Utils

2025-10-24
CVE-2025-46117
8.8
Unknown Multiple Products

An issue was discovered in CommScope Ruckus Unleashed prior to 200

2025-07-22
CVE-2025-46116
8.8
Unknown Multiple Products

An issue was discovered in CommScope Ruckus Unleashed prior to 200

2025-07-22
CVE-2025-46099
7.1
Pluck Multiple Products

In Pluck CMS 4

2025-07-23
CVE-2025-46093
Analyzed
9.9
LiquidFiles before Multiple Products

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by le...

2025-08-05
CVE-2025-46070
Analyzed
9.8
Unknown Multiple Products

An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

2026-01-13
CVE-2025-46068
Analyzed
8.8
Intel Multiple Products

An issue in Automai Director v

2026-01-13
CVE-2025-46067
Analyzed
8.2
Unknown Multiple Products

An issue in Automai Director v

2026-01-13
CVE-2025-46066
Analyzed
9.9
Unknown Multiple Products

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

2026-01-13
CVE-2025-4606
9.8
WordPress Multiple Products

The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in...

2025-07-10
CVE-2025-46059
Analyzed
9.8
Unknown Multiple Products

langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows att...

2025-07-29
CVE-2025-46014
8.8
Unknown Multiple Products

Several services in Honor Device Co

2025-07-06
CVE-2025-45968
9.8
Unknown Multiple Products

An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Inse...

2025-08-25
CVE-2025-45931
9.8
D-Link Multiple Products

An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goa...

2025-07-06
CVE-2025-45814
9.8
Unknown Multiple Products

Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to ex...

2025-07-06
CVE-2025-45813
9.8
ENENSYS IPGuard Multiple Products

ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

2025-07-06
CVE-2025-45805
7.6
HP Multiple Products

In phpgurukul Doctor Appointment Management System 1

2025-09-03
CVE-2025-45770
7
Unknown Multiple Products

jwt v5

2025-07-31
CVE-2025-45769
Analyzed
7.3
HP Multiple Products

php-jwt v6

2025-07-31
CVE-2025-45768
7
Unknown Multiple Products

pyjwt v2

2025-07-31
CVE-2025-45767
7
Unknown Multiple Products

jose v6

2025-08-01
CVE-2025-45766
7
Unknown Multiple Products

poco v1

2025-08-07
CVE-2025-45620
8.1
Unknown Multiple Products

An issue in Aver PTC310UV2 v

2025-07-30
CVE-2025-45379
Analyzed
8.4
Dell Multiple Products

Dell CloudLink, versions prior to 8

2025-11-06
CVE-2025-45376
Analyzed
7.5
Dell Multiple Products

Dell Repository Manager (DRM), versions 3

2025-09-30
CVE-2025-45346
Analyzed
8.1
Unknown Multiple Products

SQL Injection vulnerability in Bacula-web before v

2025-07-29
CVE-2025-4519
Analyzed
8.8
WordPress Multiple Products

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capabili...

2025-11-08
CVE-2025-45150
Analyzed
9.8
Intel Multiple Products

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted...

2025-08-01
CVE-2025-45146
Analyzed
9.8
Unknown Multiple Products

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerab...

2025-08-11
CVE-2025-45095
7.3
Lavasoft Multiple Products

Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8

2025-10-09
CVE-2025-45081
8.8
Unknown Multiple Products

Misconfigured settings in IITB SSO v1

2025-07-06
CVE-2025-45080
8.8
YONO Multiple Products

YONO SBI: Banking & Lifestyle v1

2025-07-06
CVE-2025-45065
9.8
HP Multiple Products

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

2025-07-08
CVE-2025-45006
9.1
F5 Multiple Products

Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential...

2025-07-06
CVE-2025-44963
Analyzed
9
RUCKUS Network Director Multiple Products

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

2025-08-05
CVE-2025-44961
Analyzed
9.9
Unknown Multiple Products

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

2025-08-05
CVE-2025-44960
8.5
RUCKUS Multiple Products

RUCKUS SmartZone (SZ) before 6

2025-08-05
CVE-2025-44957
8.5
Ruckus Multiple Products

Ruckus SmartZone (SZ) before 6

2025-08-05
CVE-2025-44955
Analyzed
8.8
RUCKUS Multiple Products

RUCKUS Network Director (RND) before 4

2025-08-05
CVE-2025-44954
Analyzed
9
RUCKUS SmartZone Multiple Products

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

2025-08-05
CVE-2025-44824
Analyzed
8.5
Log Multiple Products

Nagios Log Server before 2024R1

2025-10-07
CVE-2025-44823
Analyzed
9.9
HP Multiple Products

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/syst...

2025-10-07
CVE-2025-44643
8.6
DrayTek Multiple Products

Certain Draytek products are affected by Insecure Configuration

2025-08-05
CVE-2025-44594
9.1
Unknown Multiple Products

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.

2025-09-10
CVE-2025-4439
7.7
GitLab Multiple Products

An issue has been discovered in GitLab CE/EE affecting all versions from 15

2025-07-23