Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
29,822 matching · page 442/597Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-33204(opens NVD record) | High | 7.8 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering. | Nov 25, 2025 |
| CVE-2025-33200(opens NVD record) | Low | 2.3 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to information disclosure. | Nov 25, 2025 |
| CVE-2025-33199(opens NVD record) | Low | 3.2 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow behavior. A successful exploit of this vulnerability might lead to data tampering. | Nov 25, 2025 |
| CVE-2025-33198(opens NVD record) | Low | 3.3 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to information disclosure. | Nov 25, 2025 |
| CVE-2025-33197(opens NVD record) | Medium | 4.3 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service. | Nov 25, 2025 |
| CVE-2025-33196(opens NVD record) | Medium | 4.4 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to information disclosure. | Nov 25, 2025 |
| CVE-2025-33195(opens NVD record) | Medium | 4.4 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer operations. A successful exploit of this vulnerability might lead to data tampering, denial of service, or escalation of privileges. | Nov 25, 2025 |
| CVE-2025-33194(opens NVD record) | Medium | 5.7 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this vulnerability might lead to information disclosure or denial of service. | Nov 25, 2025 |
| CVE-2025-33193(opens NVD record) | Medium | 5.7 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of integrity. A successful exploit of this vulnerability might lead to information disclosure. | Nov 25, 2025 |
| CVE-2025-33192(opens NVD record) | Medium | 5.7 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read. A successful exploit of this vulnerability might lead to denial of service. | Nov 25, 2025 |
| CVE-2025-33191(opens NVD record) | Medium | 5.7 | NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this vulnerability might lead to denial of service. | Nov 25, 2025 |
| CVE-2025-33190(opens NVD record) | Medium | 6.7 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or escalation of privileges. | Nov 25, 2025 |
| CVE-2025-33189(opens NVD record) | High | 7.8 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, information disclosure, or escalation of privileges. | Nov 25, 2025 |
| CVE-2025-33188(opens NVD record) | High | 8.0 | NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware controls. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service. | Nov 25, 2025 |
| CVE-2025-33187(opens NVD record) | Critical | 9.3 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, denial of service, or escalation of privileges. | Nov 25, 2025 |
| CVE-2025-36134(opens NVD record) | Low | 3.7 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a missing or insecure SameSite attribute for a sensitive cookie. | Nov 25, 2025 |
| CVE-2025-63674(opens NVD record) | Medium | 6.8 | An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card. | Nov 24, 2025 |
| CVE-2024-47856(opens NVD record) | Critical | 9.8 | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable. | Nov 24, 2025 |
| CVE-2025-36150(opens NVD record) | Medium | 5.9 | IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | Nov 24, 2025 |
| CVE-2025-64048(opens NVD record) | Medium | 6.1 | YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the ArticleAction.class.php file due to improper neutralization of user input in the article title field. | Nov 24, 2025 |
| CVE-2025-64047(opens NVD record) | Medium | 6.1 | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php. | Nov 24, 2025 |
| CVE-2025-56400(opens NVD record) | High | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile applications, as well as other third-party applications that integrate the SDK, allows an attacker to link their own Amazon Alexa account to a victim's Tuya account. The applications fail to validate the OAuth state parameter during the account linking flow, enabling a cross-site request forgery (CSRF)-like attack. By tricking the victim into clicking a crafted authorization link, an attacker can complete the OAuth flow on the victim's behalf, resulting in unauthorized Alexa access to the victim's Tuya-connected devices. This affects users regardless of prior Alexa linkage and does not require the Tuya application to be active at the time. Successful exploitation may allow remote control of devices such as cameras, doorbells, door locks, or alarms. | Nov 24, 2025 |
| CVE-2025-36112(opens NVD record) | Medium | 5.3 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information to an unauthorized user. | Nov 24, 2025 |
| CVE-2025-56401(opens NVD record) | High | 7.6 | ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName. | Nov 24, 2025 |
| CVE-2025-40213(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in set_mesh_sync due to memcpy from badly declared on-stack flexible array. Another crash is in set_mesh_complete() due to double list_del via mgmt_pending_valid + mgmt_pending_remove. Use DEFINE_FLEX to declare the flexible array right, and don't memcpy outside bounds. As mgmt_pending_valid removes the cmd from list, use mgmt_pending_free, and also report status on error. | Nov 24, 2025 |
| CVE-2025-40212(opens NVD record) | Critical | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nfsd exports a "pseudo root filesystem" which is used by NFSv4 to find the various exported filesystems using LOOKUP requests from a known root filehandle. NFSv3 uses the MOUNT protocol to find those exported filesystems and so is not given access to the pseudo root filesystem. If a v3 (or v2) client uses a filehandle from that filesystem, nfsd_set_fh_dentry() will report an error, but still stores the export in "struct svc_fh" even though it also drops the reference (exp_put()). This means that when fh_put() is called an extra reference will be dropped which can lead to use-after-free and possible denial of service. Normal NFS usage will not provide a pseudo-root filehandle to a v3 client. This bug can only be triggered by the client synthesising an incorrect filehandle. To fix this we move the assignments to the svc_fh later, after all possible error cases have been detected. | Nov 24, 2025 |
| CVE-2025-36149(opens NVD record) | Medium | 6.3 | IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim. | Nov 21, 2025 |
| CVE-2025-40210(opens NVD record) | High | 7.5 | In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" I've found that pynfs COMP6 now leaves the connection or lease in a strange state, which causes CLOSE9 to hang indefinitely. I've dug into it a little, but I haven't been able to root-cause it yet. However, I bisected to commit 48aab1606fa8 ("NFSD: Remove the cap on number of operations per NFSv4 COMPOUND"). Tianshuo Han also reports a potential vulnerability when decoding an NFSv4 COMPOUND. An attacker can place an arbitrarily large op count in the COMPOUND header, which results in: [ 51.410584] nfsd: vmalloc error: size 1209533382144, exceeds total pages, mode:0xdc0(GFP_KERNEL|__GFP_ZERO), nodemask=(null),cpuset=/,mems_allowed=0 when NFSD attempts to allocate the COMPOUND op array. Let's restore the operation-per-COMPOUND limit, but increased to 200 for now. | Nov 21, 2025 |
| CVE-2025-64695(opens NVD record) | High | 7.8 | Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invoking the installer. | Nov 21, 2025 |
| CVE-2025-64299(opens NVD record) | Low | 2.7 | LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes. | Nov 21, 2025 |
| CVE-2025-62687(opens NVD record) | Medium | 6.5 | Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed. | Nov 21, 2025 |
| CVE-2025-62189(opens NVD record) | Medium | 4.3 | LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request. | Nov 21, 2025 |
| CVE-2025-61949(opens NVD record) | Medium | 5.4 | LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page. | Nov 21, 2025 |
| CVE-2025-58097(opens NVD record) | High | 7.8 | The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege. | Nov 21, 2025 |
| CVE-2025-64660(opens NVD record) | High | 8.0 | Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | Nov 20, 2025 |
| CVE-2025-64655(opens NVD record) | High | 8.8 | Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. | Nov 20, 2025 |
| CVE-2025-62459(opens NVD record) | High | 8.3 | Microsoft Defender Portal Spoofing Vulnerability | Nov 20, 2025 |
| CVE-2025-62207(opens NVD record) | High | 8.6 | Azure Monitor Elevation of Privilege Vulnerability | Nov 20, 2025 |
| CVE-2025-59245(opens NVD record) | Critical | 9.8 | Microsoft SharePoint Online Elevation of Privilege Vulnerability | Nov 20, 2025 |
| CVE-2025-49752(opens NVD record) | Critical | 10.0 | Azure Bastion Elevation of Privilege Vulnerability | Nov 20, 2025 |
| CVE-2025-36072(opens NVD record) | High | 8.8 | IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an authenticated user to execute arbitrary code on the system, caused by the deserialization of untrusted object graphs data. | Nov 20, 2025 |
| CVE-2025-36160(opens NVD record) | Medium | 5.3 | IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system. | Nov 20, 2025 |
| CVE-2025-36159(opens NVD record) | Medium | 6.2 | IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output. | Nov 20, 2025 |
| CVE-2025-36158(opens NVD record) | Medium | 5.1 | IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying. | Nov 20, 2025 |
| CVE-2025-36153(opens NVD record) | Medium | 6.1 | IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | Nov 20, 2025 |
| CVE-2025-25613(opens NVD record) | High | 7.5 | FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were transmitted in cleartext using simple base64 encoding during every POST request made to the server. | Nov 20, 2025 |
| CVE-2025-36161(opens NVD record) | Medium | 5.9 | IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | Nov 20, 2025 |
| CVE-2025-40605(opens NVD record) | Medium | 5.3 | A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path. | Nov 20, 2025 |
| CVE-2025-40604(opens NVD record) | Critical | 9.8 | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution. | Nov 20, 2025 |
| CVE-2025-40601(opens NVD record) | High | 7.5 | A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash. | Nov 20, 2025 |