Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
30,193 matching · page 470/604Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-62386(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62385(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62384(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-62383(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-11623(opens NVD record) | Medium | 6.5 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | Oct 13, 2025 |
| CVE-2025-9713(opens NVD record) | High | 8.8 | Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | Oct 13, 2025 |
| CVE-2025-11622(opens NVD record) | High | 7.8 | Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges. | Oct 13, 2025 |
| CVE-2025-43991(opens NVD record) | Medium | 6.3 | SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A low privileged attacker with local access to the system could potentially exploit this vulnerability to delete arbitrary files only in that affected system. | Oct 13, 2025 |
| CVE-2025-39965(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create states and add them to the byspi list with this value. __xfrm_state_delete doesn't remove those states from the byspi list, since they shouldn't be there, and this shows up as a UAF the next time we go through the byspi list. | Oct 13, 2025 |
| CVE-2025-39964(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing. | Oct 13, 2025 |
| CVE-2025-36087(opens NVD record) | High | 8.1 | IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | Oct 13, 2025 |
| CVE-2025-33096(opens NVD record) | Medium | 6.5 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion. | Oct 12, 2025 |
| CVE-2025-2140(opens NVD record) | Medium | 5.7 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data. | Oct 12, 2025 |
| CVE-2025-2139(opens NVD record) | Low | 3.5 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security. | Oct 12, 2025 |
| CVE-2025-2138(opens NVD record) | Low | 3.5 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security. | Oct 12, 2025 |
| CVE-2025-61884(opens NVD record) | High | 7.5 | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | Oct 12, 2025 |
| CVE-2025-58301(opens NVD record) | Medium | 6.2 | Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58300(opens NVD record) | Medium | 6.2 | Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58293(opens NVD record) | Medium | 5.5 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58289(opens NVD record) | Medium | 5.9 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58299(opens NVD record) | High | 8.4 | Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58298(opens NVD record) | High | 7.3 | Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58297(opens NVD record) | Medium | 5.9 | Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58295(opens NVD record) | Medium | 5.9 | Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58292(opens NVD record) | Low | 3.3 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58291(opens NVD record) | Low | 3.3 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58290(opens NVD record) | Low | 3.3 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58288(opens NVD record) | Medium | 5.5 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58287(opens NVD record) | High | 7.8 | Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58286(opens NVD record) | Low | 3.3 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 |
| CVE-2025-58285(opens NVD record) | Medium | 5.3 | Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58284(opens NVD record) | Medium | 5.9 | Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58283(opens NVD record) | Medium | 5.5 | Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58282(opens NVD record) | Low | 2.8 | Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58278(opens NVD record) | Medium | 6.2 | Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-58277(opens NVD record) | Medium | 4.0 | Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality. | Oct 11, 2025 |
| CVE-2025-54654(opens NVD record) | Medium | 6.2 | Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality | Oct 11, 2025 |
| CVE-2025-60838(opens NVD record) | Medium | 6.5 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. | Oct 10, 2025 |
| CVE-2025-60308(opens NVD record) | Medium | 4.1 | code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room function of the online hotel reservation system. Malicious JavaScript code is entered in the Description field, which can leak the administrator's cookie information when browsing this room information | Oct 10, 2025 |
| CVE-2025-60306(opens NVD record) | Critical | 9.9 | code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations. | Oct 10, 2025 |
| CVE-2025-60307(opens NVD record) | Critical | 9.8 | code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts. | Oct 10, 2025 |
| CVE-2025-60305(opens NVD record) | High | 8.8 | SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations. | Oct 10, 2025 |
| CVE-2025-48043(opens NVD record) | Unscored | — | Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2. This issue affects ash: from 0.1.0 before 3.6.2. | Oct 10, 2025 |
| CVE-2025-60378(opens NVD record) | High | 8.1 | Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients. | Oct 10, 2025 |
| CVE-2025-59286(opens NVD record) | Critical | 9.3 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | Oct 9, 2025 |
| CVE-2025-59272(opens NVD record) | Critical | 9.3 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | Oct 9, 2025 |
| CVE-2025-59271(opens NVD record) | High | 8.7 | Redis Enterprise Elevation of Privilege Vulnerability | Oct 9, 2025 |
| CVE-2025-59252(opens NVD record) | Critical | 9.3 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | Oct 9, 2025 |
| CVE-2025-59247(opens NVD record) | High | 8.8 | Azure PlayFab Elevation of Privilege Vulnerability | Oct 9, 2025 |
| CVE-2025-59246(opens NVD record) | Critical | 9.8 | Azure Entra ID Elevation of Privilege Vulnerability | Oct 9, 2025 |