Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2009-0556 KEV |
|
[KEV] Code Injection in Microsoft office (CVE-2009-0556)
code injection in Microsoft office (CVE-2009-0556). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-37164 KEV |
|
[KEV] Code Injection in Hewlett packard enterprise (hpe) hewlett-packard-enterprise-hpe (CVE-2025-37164)
code injection in Hewlett packard enterprise (hpe) hewlett-packard-enterprise-hpe (CVE-2025-37164). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-62842 |
|
Vulnerability in qnap (CVE-2025-62842)
vulnerability in qnap (CVE-2025-62842). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58315 |
|
Vulnerability in tosi (CVE-2024-58315)
vulnerability in tosi (CVE-2024-58315). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66835 |
|
Vulnerability in trueconf (CVE-2025-66835)
vulnerability in trueconf (CVE-2025-66835). Confidential information can be exposed externally.
|
| CVE-2025-66824 |
|
Cross-Site Scripting (XSS) in trueconf (CVE-2025-66824)
cross-site scripting in trueconf (CVE-2025-66824). Confidential information can be exposed externally.
|
| CVE-2025-66834 |
|
Vulnerability in trueconf (CVE-2025-66834)
vulnerability in trueconf (CVE-2025-66834). Confidential information can be exposed externally.
|
| CVE-2023-54285 |
|
Out-of-Bounds Write in linux (CVE-2023-54285)
out-of-bounds write in linux (CVE-2023-54285). Data can be tampered with by attackers.
|
| CVE-2025-14847 KEV |
|
[KEV] Vulnerability in Mongodb cisa (CVE-2025-14847)
vulnerability in Mongodb cisa (CVE-2025-14847). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-66738 |
|
Command Injection in yealink (CVE-2025-66738)
command injection in yealink (CVE-2025-66738). Successful exploitation can lead to full system takeover.
|
| CVE-2025-68749 |
|
Vulnerability in linux (CVE-2025-68749)
vulnerability in linux (CVE-2025-68749). Successful exploitation can lead to full system takeover.
|
| CVE-2025-68365 |
|
Vulnerability in linux (CVE-2025-68365)
vulnerability in linux (CVE-2025-68365). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-68340 |
|
Vulnerability in linux (CVE-2025-68340)
vulnerability in linux (CVE-2025-68340). Successful exploitation can lead to full system takeover.
|
| CVE-2023-52163 KEV |
|
[KEV] Vulnerability in Digiever ds-2105-pro (CVE-2023-52163)
vulnerability in Digiever ds-2105-pro (CVE-2023-52163). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-14300 |
|
Vulnerability in dos (CVE-2025-14300)
vulnerability in dos (CVE-2025-14300). Data can be tampered with by attackers.
|
| CVE-2020-36890 |
|
Vulnerability in kentico (CVE-2020-36890)
vulnerability in kentico (CVE-2020-36890). Successful exploitation can lead to full system takeover.
|
| CVE-2025-46291 |
|
Vulnerability in apple (CVE-2025-46291)
vulnerability in apple (CVE-2025-46291). Successful exploitation can lead to full system takeover.
|
| CVE-2025-46281 |
|
Vulnerability in apple (CVE-2025-46281)
vulnerability in apple (CVE-2025-46281). Successful exploitation can lead to full system takeover.
|
| CVE-2025-20393 KEV |
|
[KEV] Vulnerability in Cisco multiple-products (CVE-2025-20393)
vulnerability in Cisco multiple-products (CVE-2025-20393). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-59374 KEV |
|
[KEV] Vulnerability in Asus live-update (CVE-2025-59374)
vulnerability in Asus live-update (CVE-2025-59374). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-40602 KEV |
|
[KEV] Vulnerability in Sonicwall sma1000-appliance (CVE-2025-40602)
vulnerability in Sonicwall sma1000-appliance (CVE-2025-40602). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-68065 |
|
Vulnerability in CVE-2025-68065 (CVE-2025-68065)
vulnerability in CVE-2025-68065 (CVE-2025-68065). Successful exploitation can lead to full system takeover.
|
| CVE-2023-53888 |
|
Code Injection in zomp (CVE-2023-53888)
code injection in zomp (CVE-2023-53888). Successful exploitation can lead to full system takeover.
|
| CVE-2025-43529 KEV |
|
[KEV] Use-After-Free in Apple multiple-products (CVE-2025-43529)
vulnerability in Apple multiple-products (CVE-2025-43529). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-14611 KEV |
|
[KEV] Vulnerability in Gladinet centrestack-and-triofox (CVE-2025-14611)
vulnerability in Gladinet centrestack-and-triofox (CVE-2025-14611). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-4063 KEV |
|
[KEV] Unrestricted File Upload in Sierra wireless sierra-wireless (CVE-2018-4063)
vulnerability in Sierra wireless sierra-wireless (CVE-2018-4063). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-14174 KEV |
|
[KEV] Vulnerability in Google chromium (CVE-2025-14174)
vulnerability in Google chromium (CVE-2025-14174). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-58360 KEV |
|
[KEV] XXE (XML External Entity) in Osgeo geoserver (CVE-2025-58360)
vulnerability in Osgeo geoserver (CVE-2025-58360). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-61813 |
|
XXE (XML External Entity) in adobe (CVE-2025-61813)
vulnerability in adobe (CVE-2025-61813). Confidential information can be exposed externally.
|
| CVE-2025-65594 |
|
Vulnerability in os4ed (CVE-2025-65594)
vulnerability in os4ed (CVE-2025-65594). Confidential information can be exposed externally.
|
| CVE-2025-64666 |
|
Vulnerability in microsoft (CVE-2025-64666)
vulnerability in microsoft (CVE-2025-64666). Successful exploitation can lead to full system takeover.
|
| CVE-2025-62557 |
|
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
|
| CVE-2025-62554 |
|
Vulnerability in microsoft (CVE-2025-62554)
vulnerability in microsoft (CVE-2025-62554). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53679 |
|
OS Command Injection in fortinet (CVE-2025-53679)
OS command injection in fortinet (CVE-2025-53679). Successful exploitation can lead to full system takeover.
|
| CVE-2025-56704 |
|
Unrestricted File Upload in lepton-cms (CVE-2025-56704)
vulnerability in lepton-cms (CVE-2025-56704). Successful exploitation can lead to full system takeover.
|
| CVE-2025-62221 KEV |
|
[KEV] Use-After-Free in Microsoft windows (CVE-2025-62221)
vulnerability in Microsoft windows (CVE-2025-62221). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-6218 KEV |
|
[KEV] Path Traversal in Rarlab winrar (CVE-2025-6218)
path traversal in Rarlab winrar (CVE-2025-6218). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-48615 |
|
Vulnerability in google (CVE-2025-48615)
vulnerability in google (CVE-2025-48615). Successful exploitation can lead to full system takeover.
|
| CVE-2025-48612 |
|
Vulnerability in google (CVE-2025-48612)
vulnerability in google (CVE-2025-48612). Successful exploitation can lead to full system takeover.
|
| CVE-2022-37055 KEV |
|
[KEV] Vulnerability in D-link routers (CVE-2022-37055)
vulnerability in D-link routers (CVE-2022-37055). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-66644 KEV |
|
[KEV] OS Command Injection in Array networks array-networks (CVE-2025-66644)
OS command injection in Array networks array-networks (CVE-2025-66644). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-34291 KEV |
|
[KEV] Vulnerability in langflow (CVE-2025-34291)
vulnerability in langflow (CVE-2025-34291). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2025-1545 |
|
Vulnerability in watchguard (CVE-2025-1545)
vulnerability in watchguard (CVE-2025-1545). Confidential information can be exposed externally.
|
| CVE-2025-1547 |
|
Vulnerability in watchguard (CVE-2025-1547)
vulnerability in watchguard (CVE-2025-1547). Successful exploitation can lead to full system takeover.
|
| CVE-2025-12196 |
|
Out-of-Bounds Write in watchguard (CVE-2025-12196)
out-of-bounds write in watchguard (CVE-2025-12196). Successful exploitation can lead to full system takeover.
|
| CVE-2025-11838 |
|
Vulnerability in dos (CVE-2025-11838)
vulnerability in dos (CVE-2025-11838). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-12026 |
|
Out-of-Bounds Write in watchguard (CVE-2025-12026)
out-of-bounds write in watchguard (CVE-2025-12026). Successful exploitation can lead to full system takeover.
|
| CVE-2025-12195 |
|
Out-of-Bounds Write in watchguard (CVE-2025-12195)
out-of-bounds write in watchguard (CVE-2025-12195). Successful exploitation can lead to full system takeover.
|
| CVE-2025-40251 |
|
Vulnerability in c (CVE-2025-40251)
vulnerability in c (CVE-2025-40251). Successful exploitation can lead to full system takeover. Exploitable via ``rate_leaf_parent_set``.
|
| CVE-2021-26828 KEV |
|
[KEV] Unrestricted File Upload in Openplc scadabr (CVE-2021-26828)
vulnerability in Openplc scadabr (CVE-2021-26828). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|