CVE Vulnerability Database

Search and browse 397,814 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-60477MEDIUM5A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Pr...
CVE-2024-47273MEDIUM4.3An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functiona...
CVE-2024-47263MEDIUM4.1An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository web...
CVE-2023-52951MEDIUM5.9A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows ...
CVE-2022-49042HIGH7.8An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backu...
CVE-2022-49036HIGH7.8An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Ba...
CVE-2026-35085HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system acces...
CVE-2026-35084HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access ...
CVE-2026-35083HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
CVE-2026-35082HIGH8.8The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient...
CVE-2026-35081HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficien...
CVE-2026-35080HIGH8.1The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic...
CVE-2026-35079HIGH8.1The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient...
CVE-2026-35078HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien...
CVE-2026-35077HIGH8.1The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi...
CVE-2026-35076HIGH8.1The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici...
CVE-2026-35075CRITICAL9.8An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full a...
CVE-2026-10722MEDIUM5.5A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go...
CVE-2025-41259HIGH7.3SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivilege...
CVE-2026-47065CRITICAL9.8ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Ful...
CVE-2026-41032HIGH7.5It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some...
CVE-2025-15656HIGH8.8Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affe...
CVE-2025-15655HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Ma...
CVE-2025-14774HIGH7.4Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
CVE-2025-14773MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. T...