CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2025-10585Kritisch9.8
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-26399Kritisch9.8
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
- CVE-2025-59689Mittel6.1
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
- CVE-2025-48703Kritisch9.0
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
- CVE-2025-10035Kritisch10.0
Eine Deserialisierungsschwachstelle im License Servlet von Fortra's GoAnywhere MFT ermöglicht es einem Akteur mit einer gültig gefälschten Lizenzantwortsignatur, ein beliebiges, vom Akteur kontrolliertes Objekt zu deserialisieren, was möglicherweise zu Command Injection führt.
- CVE-2025-9242Kritisch9.8
Eine Out-of-bounds-Write-Schwachstelle im WatchGuard Fireware OS iked-Prozess kann es einem entfernten, nicht authentifizierten Angreifer ermöglichen, beliebigen Code auszuführen. Diese Schwachstelle betrifft sowohl das Mobile-User-VPN mit IKEv2 als auch das Branch-Office-VPN mit IKEv2, wenn es mit einem dynamischen Gateway-Peer konfiguriert ist. Wenn die Firebox zuvor mit dem Mobile-User-VPN mit IKEv2 oder einem Branch-Office-VPN mit IKEv2 zu einem dynamischen Gateway-Peer konfiguriert wurde und beide dieser Konfigurationen seitdem gelöscht wurden, kann diese Firebox weiterhin anfällig sein, wenn noch ein Branch-Office-VPN zu einem statischen Gateway-Peer konfiguriert ist.
- CVE-2025-21043Hoch8.8
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
- CVE-2025-21042Hoch8.8
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
- CVE-2025-54236Kritisch9.1
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
- CVE-2025-55241Kritisch10.0
Azure Entra ID-Schwachstelle zur Erhöhung von Berechtigungen
- CVE-2025-48543Hoch8.8
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-53690Kritisch9.0
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
- CVE-2025-9377Hoch7.2
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es).
- CVE-2025-55177Mittel5.4
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
- CVE-2025-57819Kritisch9.8
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
- CVE-2025-7775Kritisch9.8
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX
- CVE-2025-43300Kritisch10.0
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
- CVE-2025-8876Hoch8.8
Schwachstelle durch unsachgemäße Eingabevalidierung in N-able N-central ermöglicht OS Command Injection. Dieses Problem betrifft N-central: vor 2025.3.1.
- CVE-2025-8875Hoch7.8
Schwachstelle durch Deserialisierung nicht vertrauenswürdiger Daten in N-able N-central ermöglicht lokale Codeausführung. Dieses Problem betrifft N-central: vor 2025.3.1.
- CVE-2025-8714Hoch8.8
Die Einbindung nicht vertrauenswürdiger Daten in pg_dump in PostgreSQL ermöglicht es einem bösartigen Superuser des Ursprungsservers, über psql-Meta-Befehle beliebigen Code einzuschleusen, der zum Wiederherstellungszeitpunkt als das Client-Betriebssystemkonto ausgeführt wird, das psql zur Wiederherstellung des Dumps ausführt. pg_dumpall ist ebenfalls betroffen. pg_restore ist betroffen, wenn es zur Erzeugung eines Dumps im Plain-Format verwendet wird. Dies ähnelt MySQL CVE-2024-21096. Versionen vor PostgreSQL 17.6, 16.10, 15.14, 14.19 und 13.22 sind betroffen.
This product uses the NVD API but is not endorsed or certified by the NVD.