51,518 indexed

CVECVE vulnerabilities

51,518 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 101–150 of 1,656 in KEV · page 3 of 34

IDTitleSummary
CVE-2026-0257Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
KEVCVSS 9.1Palo Alto Networks
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized V…
CVE-2025-9377TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
KEVCVSS 7.2TP-Link
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could …
CVE-2025-9242WatchGuard Firebox Out-of-Bounds Write Vulnerability
KEVCVSS 9.8WatchGuard
WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary c…
CVE-2025-8876N-able N-Central Command Injection Vulnerability
KEVCVSS 8.8N-able
N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-8875N-able N-Central Insecure Deserialization Vulnerability
KEVCVSS 7.8N-able
N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
CVE-2025-8110Gogs Path Traversal Vulnerability
KEVCVSS 8.8Gogs
Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
CVE-2025-8088RARLAB WinRAR Path Traversal Vulnerability
KEVCVSS 8.8RARLAB
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary …
CVE-2025-7775Citrix NetScaler Memory Overflow Vulnerability
KEVCVSS 9.8Citrix
Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
CVE-2025-68686Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
KEVCVSS 5.9Fortinet
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypa…
CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
KEVCVSS 8.8Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/r…
CVE-2025-68613n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
KEVCVSS 8.8n8n
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code e…
CVE-2025-68461RoundCube Webmail Cross-site Scripting Vulnerability
KEVCVSS 6.1Roundcube
RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2025-67038Lantronix EDS5000 Code Injection Vulnerability
KEVCVSS 9.8Lantronix
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected comm…
CVE-2025-66644Array Networks ArrayOS AG OS Command Injection Vulnerability
KEVCVSS 9.8Array Networks
Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.
CVE-2025-66376Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
KEVCVSS 6.1Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CS…
CVE-2025-6558Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
KEVCVSS 8.8Google
Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a…
CVE-2025-6554Google Chromium V8 Type Confusion Vulnerability
KEVCVSS 8.1Google
Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vul…
CVE-2025-6543Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
KEVCVSS 9.8Citrix
Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured…
CVE-2025-64446Fortinet FortiWeb Path Traversal Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system …
CVE-2025-64328Sangoma FreePBX OS Command Injection Vulnerability
KEVCVSS 7.2Sangoma
Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticate…
CVE-2025-62221Microsoft Windows Use After Free Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
CVE-2025-62215Microsoft Windows Race Condition Vulnerability
KEVCVSS 7.0Microsoft
Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful expl…
CVE-2025-6218RARLAB WinRAR Path Traversal Vulnerability
KEVCVSS 7.8RARLAB
RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-6205Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
KEVCVSS 9.1Dassault Systèmes
Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.
CVE-2025-6204Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
KEVCVSS 8.0Dassault Systèmes
Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
CVE-2025-61932Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
KEVCVSS 9.8Motex
Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary …
CVE-2025-61884Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
KEVCVSS 7.5Oracle
Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remo…
CVE-2025-61882Oracle E-Business Suite Unspecified Vulnerability
KEVCVSS 9.8Oracle
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with…
CVE-2025-61757Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
KEVCVSS 9.8Oracle
Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity…
CVE-2025-60710Microsoft Windows Link Following Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2025-59718Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unaut…
CVE-2025-59689Libraesva Email Security Gateway Command Injection Vulnerability
KEVCVSS 6.1Libraesva
Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.
CVE-2025-59374ASUS Live Update Embedded Malicious Code Vulnerability
KEVCVSS 9.8ASUS
ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain co…
CVE-2025-59287Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
KEVCVSS 9.8Microsoft
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2025-59230Microsoft Windows Improper Access Control Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to ele…
CVE-2025-58360OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
KEVCVSS 9.8OSGeo
OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a sp…
CVE-2025-58034Fortinet FortiWeb OS Command Injection Vulnerability
KEVCVSS 7.2Fortinet
Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system…
CVE-2025-57819Sangoma FreePBX Authentication Bypass Vulnerability
KEVCVSS 9.8Sangoma
Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Adm…
CVE-2025-5777Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
KEVCVSS 7.5Citrix
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overre…
CVE-2025-55182Meta React Server Components Remote Code Execution Vulnerability
KEVCVSS 10.0Meta
Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how …
CVE-2025-55177Meta Platforms WhatsApp Incorrect Authorization Vulnerability
KEVCVSS 5.4Meta Platforms
Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vu…
CVE-2025-54948Trend Micro Apex One OS Command Injection Vulnerability
KEVCVSS 9.8Trend Micro
Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upl…
CVE-2025-54313Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
KEVCVSS 7.5Prettier
Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the…
CVE-2025-54309 CrushFTP Unprotected Alternate Channel Vulnerability
KEVCVSS 9.8CrushFTP
CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows rem…
CVE-2025-54253Adobe Experience Manager Forms Code Execution Vulnerability
KEVCVSS 10.0Adobe
Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
CVE-2025-54236Adobe Commerce and Magento Improper Input Validation Vulnerability
KEVCVSS 9.1Adobe
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through t…
CVE-2025-5419Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
KEVCVSS 8.8Google
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a craft…
CVE-2025-54068Laravel Livewire Code Injection Vulnerability
KEVCVSS 9.8Laravel
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CVE-2025-53770Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
KEVCVSS 9.8Microsoft
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code ov…
CVE-2025-53690Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
KEVCVSS 9.0Sitecore
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerabili…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.