51,518 indexed
CVECVE vulnerabilities
51,518 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 101–150 of 1,656 in KEV · page 3 of 34
| ID | Title | Summary |
|---|---|---|
| CVE-2026-0257 | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability KEVCVSS 9.1Palo Alto Networks | Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized V… |
| CVE-2025-9377 | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability KEVCVSS 7.2TP-Link | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could … |
| CVE-2025-9242 | WatchGuard Firebox Out-of-Bounds Write Vulnerability KEVCVSS 9.8WatchGuard | WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary c… |
| CVE-2025-8876 | N-able N-Central Command Injection Vulnerability KEVCVSS 8.8N-able | N-able N-Central contains a command injection vulnerability via improper sanitization of user input. |
| CVE-2025-8875 | N-able N-Central Insecure Deserialization Vulnerability KEVCVSS 7.8N-able | N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. |
| CVE-2025-8110 | Gogs Path Traversal Vulnerability KEVCVSS 8.8Gogs | Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution. |
| CVE-2025-8088 | RARLAB WinRAR Path Traversal Vulnerability KEVCVSS 8.8RARLAB | RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary … |
| CVE-2025-7775 | Citrix NetScaler Memory Overflow Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. |
| CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability KEVCVSS 5.9Fortinet | Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypa… |
| CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability KEVCVSS 8.8Synacor | Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/r… |
| CVE-2025-68613 | n8n Improper Control of Dynamically-Managed Code Resources Vulnerability KEVCVSS 8.8n8n | n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code e… |
| CVE-2025-68461 | RoundCube Webmail Cross-site Scripting Vulnerability KEVCVSS 6.1Roundcube | RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. |
| CVE-2025-67038 | Lantronix EDS5000 Code Injection Vulnerability KEVCVSS 9.8Lantronix | Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected comm… |
| CVE-2025-66644 | Array Networks ArrayOS AG OS Command Injection Vulnerability KEVCVSS 9.8Array Networks | Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands. |
| CVE-2025-66376 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability KEVCVSS 6.1Synacor | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CS… |
| CVE-2025-6558 | Google Chromium ANGLE and GPU Improper Input Validation Vulnerability KEVCVSS 8.8Google | Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a… |
| CVE-2025-6554 | Google Chromium V8 Type Confusion Vulnerability KEVCVSS 8.1Google | Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vul… |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability KEVCVSS 9.8Citrix | Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured… |
| CVE-2025-64446 | Fortinet FortiWeb Path Traversal Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system … |
| CVE-2025-64328 | Sangoma FreePBX OS Command Injection Vulnerability KEVCVSS 7.2Sangoma | Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticate… |
| CVE-2025-62221 | Microsoft Windows Use After Free Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. |
| CVE-2025-62215 | Microsoft Windows Race Condition Vulnerability KEVCVSS 7.0Microsoft | Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful expl… |
| CVE-2025-6218 | RARLAB WinRAR Path Traversal Vulnerability KEVCVSS 7.8RARLAB | RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user. |
| CVE-2025-6205 | Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability KEVCVSS 9.1Dassault Systèmes | Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application. |
| CVE-2025-6204 | Dassault Systèmes DELMIA Apriso Code Injection Vulnerability KEVCVSS 8.0Dassault Systèmes | Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. |
| CVE-2025-61932 | Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability KEVCVSS 9.8Motex | Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary … |
| CVE-2025-61884 | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability KEVCVSS 7.5Oracle | Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remo… |
| CVE-2025-61882 | Oracle E-Business Suite Unspecified Vulnerability KEVCVSS 9.8Oracle | Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with… |
| CVE-2025-61757 | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability KEVCVSS 9.8Oracle | Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity… |
| CVE-2025-60710 | Microsoft Windows Link Following Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows contains a link following vulnerability that allows for privilege escalation |
| CVE-2025-59718 | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unaut… |
| CVE-2025-59689 | Libraesva Email Security Gateway Command Injection Vulnerability KEVCVSS 6.1Libraesva | Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment. |
| CVE-2025-59374 | ASUS Live Update Embedded Malicious Code Vulnerability KEVCVSS 9.8ASUS | ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain co… |
| CVE-2025-59287 | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability KEVCVSS 9.8Microsoft | Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. |
| CVE-2025-59230 | Microsoft Windows Improper Access Control Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to ele… |
| CVE-2025-58360 | OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability KEVCVSS 9.8OSGeo | OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a sp… |
| CVE-2025-58034 | Fortinet FortiWeb OS Command Injection Vulnerability KEVCVSS 7.2Fortinet | Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system… |
| CVE-2025-57819 | Sangoma FreePBX Authentication Bypass Vulnerability KEVCVSS 9.8Sangoma | Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Adm… |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability KEVCVSS 7.5Citrix | Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overre… |
| CVE-2025-55182 | Meta React Server Components Remote Code Execution Vulnerability KEVCVSS 10.0Meta | Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how … |
| CVE-2025-55177 | Meta Platforms WhatsApp Incorrect Authorization Vulnerability KEVCVSS 5.4Meta Platforms | Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vu… |
| CVE-2025-54948 | Trend Micro Apex One OS Command Injection Vulnerability KEVCVSS 9.8Trend Micro | Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upl… |
| CVE-2025-54313 | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability KEVCVSS 7.5Prettier | Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the… |
| CVE-2025-54309 | CrushFTP Unprotected Alternate Channel Vulnerability KEVCVSS 9.8CrushFTP | CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows rem… |
| CVE-2025-54253 | Adobe Experience Manager Forms Code Execution Vulnerability KEVCVSS 10.0Adobe | Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. |
| CVE-2025-54236 | Adobe Commerce and Magento Improper Input Validation Vulnerability KEVCVSS 9.1Adobe | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through t… |
| CVE-2025-5419 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability KEVCVSS 8.8Google | Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a craft… |
| CVE-2025-54068 | Laravel Livewire Code Injection Vulnerability KEVCVSS 9.8Laravel | Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. |
| CVE-2025-53770 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability KEVCVSS 9.8Microsoft | Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code ov… |
| CVE-2025-53690 | Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability KEVCVSS 9.0Sitecore | Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerabili… |