Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
26,802 matching · page 414/537Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-10242(opens NVD record) | High | 7.2 | OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | Oct 14, 2025 |
| CVE-2025-47856(opens NVD record) | High | 7.2 | Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or commands via crafted HTTP/HTTPS or CLI requests. | Oct 14, 2025 |
| CVE-2025-11719(opens NVD record) | Critical | 9.8 | Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144. | Oct 14, 2025 |
| CVE-2025-62392(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62391(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62390(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62389(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62388(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62387(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62386(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62385(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62384(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62383(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-11623(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-9713(opens NVD record) | High | 8.8 | Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | Oct 13, 2025 |
| CVE-2025-11622(opens NVD record) | High | 7.8 | Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges. | Oct 13, 2025 |
| CVE-2025-43991(opens NVD record) | Medium | 6.3 | SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrary files only in that affected system. | Oct 13, 2025 |
| CVE-2025-39964(opens NVD record) | Low | 3.3 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing. | Oct 13, 2025 |
| CVE-2025-36087(opens NVD record) | High | 8.1 | IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | Oct 13, 2025 |
| CVE-2025-33096(opens NVD record) | Medium | 6.5 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion. | Oct 12, 2025 |
| CVE-2025-2140(opens NVD record) | Medium | 5.7 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data. | Oct 12, 2025 |
| CVE-2025-2139(opens NVD record) | Low | 3.5 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security. | Oct 12, 2025 |
| CVE-2025-2138(opens NVD record) | Low | 3.5 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security. | Oct 12, 2025 |
| CVE-2025-61884(opens NVD record) | High | 7.5 | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | Oct 12, 2025 |
| CVE-2025-58301(opens NVD record) | Medium | 6.2 | Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58300(opens NVD record) | Medium | 6.2 | Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58293(opens NVD record) | Medium | 5.5 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58289(opens NVD record) | Medium | 5.9 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58299(opens NVD record) | High | 8.4 | Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58298(opens NVD record) | High | 7.3 | Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58297(opens NVD record) | Medium | 5.9 | Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58295(opens NVD record) | Medium | 5.9 | Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58292(opens NVD record) | Low | 3.3 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58291(opens NVD record) | Low | 3.3 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58290(opens NVD record) | Low | 3.3 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58288(opens NVD record) | Medium | 5.5 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58287(opens NVD record) | High | 7.8 | Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58286(opens NVD record) | Low | 3.3 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58285(opens NVD record) | Medium | 5.3 | Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58284(opens NVD record) | Medium | 5.9 | Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58283(opens NVD record) | Medium | 5.5 | Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58282(opens NVD record) | Low | 2.8 | Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58278(opens NVD record) | Medium | 6.2 | Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58277(opens NVD record) | Medium | 4.0 | Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-54654(opens NVD record) | Medium | 6.2 | Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality | Oct 11, 2025 |
| CVE-2025-60838(opens NVD record) | Medium | 6.5 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. | Oct 10, 2025 |
| CVE-2025-60308(opens NVD record) | Medium | 4.1 | code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room function of the online hotel reservation system. Malicious JavaScript code is entered in the Description field, which can leak the administrator's cookie information when browsing this room information | Oct 10, 2025 |
| CVE-2025-60306(opens NVD record) | Critical | 9.9 | code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations. | Oct 10, 2025 |
| CVE-2025-60307(opens NVD record) | Critical | 9.8 | code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts. | Oct 10, 2025 |
| CVE-2025-60305(opens NVD record) | High | 8.8 | SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations. | Oct 10, 2025 |