CVE Dashboard

CVE-2025-57819

Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user...

MEDIUM Published: 2025-08-29
CVE-2025-7775

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow...

MEDIUM Published: 2025-08-26
CVE-2025-48384

Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriag...

MEDIUM Published: 2025-08-25
CVE-2024-8068

Citrix Session Recording contains an improper privilege management vulnerability that could allow fo...

MEDIUM Published: 2025-08-25
CVE-2024-8069

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limi...

MEDIUM Published: 2025-08-25
CVE-2025-43300

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework...

MEDIUM Published: 2025-08-21
CVE-2025-54948

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability...

MEDIUM Published: 2025-08-18
CVE-2025-8876

N-able N-Central contains a command injection vulnerability via improper sanitization of user input....

MEDIUM Published: 2025-08-13
CVE-2025-8875

N-able N-Central contains an insecure deserialization vulnerability that could lead to command execu...

MEDIUM Published: 2025-08-13
CVE-2025-8088

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This...

MEDIUM Published: 2025-08-12
CVE-2007-0671

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a s...

MEDIUM Published: 2025-08-12
CVE-2013-3893

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code e...

MEDIUM Published: 2025-08-12
CVE-2020-25078

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for re...

MEDIUM Published: 2025-08-05
CVE-2020-25079

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddn...

MEDIUM Published: 2025-08-05
CVE-2022-40799

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow a...

MEDIUM Published: 2025-08-05
CVE-2023-2533

PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific con...

MEDIUM Published: 2025-07-28
CVE-2025-20337

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE an...

MEDIUM Published: 2025-07-28
CVE-2025-20281

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE an...

MEDIUM Published: 2025-07-28
CVE-2025-2775

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in th...

MEDIUM Published: 2025-07-22
CVE-2025-2776

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in th...

MEDIUM Published: 2025-07-22
CVE-2025-6558

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerabi...

MEDIUM Published: 2025-07-22
CVE-2025-54309

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not...

MEDIUM Published: 2025-07-22
CVE-2025-49704

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker...

MEDIUM Published: 2025-07-22
CVE-2025-49706

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized att...

MEDIUM Published: 2025-07-22
CVE-2025-53770

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability t...

MEDIUM Published: 2025-07-20
CVE-2025-25257

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker...

MEDIUM Published: 2025-07-18
CVE-2025-47812

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that...

MEDIUM Published: 2025-07-14
CVE-2025-5777

Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient inp...

MEDIUM Published: 2025-07-10
CVE-2019-9621

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability...

MEDIUM Published: 2025-07-07
CVE-2019-5418

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept...

MEDIUM Published: 2025-07-07
CVE-2016-10033

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied inpu...

MEDIUM Published: 2025-07-07
CVE-2014-3931

Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote a...

MEDIUM Published: 2025-07-07
CVE-2025-6554

Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to per...

MEDIUM Published: 2025-07-02
CVE-2025-48928

TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnera...

MEDIUM Published: 2025-07-01
CVE-2025-48927

TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability....

MEDIUM Published: 2025-07-01
CVE-2025-6543

Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended contr...

MEDIUM Published: 2025-06-30
CVE-2019-6693

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker...

MEDIUM Published: 2025-06-25
CVE-2024-0769

D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the compone...

MEDIUM Published: 2025-06-25
CVE-2024-54085

AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Inte...

MEDIUM Published: 2025-06-25
CVE-2023-0386

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to t...

MEDIUM Published: 2025-06-17
CVE-2023-33538

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerabi...

MEDIUM Published: 2025-06-16
CVE-2025-43200

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processin...

MEDIUM Published: 2025-06-16
CVE-2025-33053

Microsoft Windows contains an external control of file name or path vulnerability that could allow a...

MEDIUM Published: 2025-06-10
CVE-2025-24016

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code executi...

MEDIUM Published: 2025-06-10
CVE-2024-42009

RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a re...

MEDIUM Published: 2025-06-09
CVE-2025-32433

Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability....

MEDIUM Published: 2025-06-09
CVE-2025-5419

Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote...

MEDIUM Published: 2025-06-05
CVE-2025-21479

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allo...

MEDIUM Published: 2025-06-03
CVE-2025-21480

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allo...

MEDIUM Published: 2025-06-03
CVE-2025-27038

Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for mem...

MEDIUM Published: 2025-06-03