NVD · CISA KEV · CERT-In

CVE Tracker

Vulnerabilities ranked for Indian enterprises. Filter by severity, exploitation status and CERT-In advisories; sign in for WhatsApp/email alerts on your product stack.

Exploited (KEV)🇮🇳 CERT-InClear filters
8.9CVE-2025-9798Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability…Unknown8.8CVE-2024-32642Masa CMS is an open source Enterprise Content Management platform.Masacms8.8CVE-2025-13720Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised…Chrome8.8CVE-2025-13638Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to…Chrome8.8CVE-2025-13633Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker…Chrome8.8CVE-2025-13631Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a…Chrome8.8CVE-2025-11787Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through…Sge-Plc1000 Firmware8.8CVE-2025-13871Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26…Opinio8.8CVE-2025-66299Grav is a file-based Web platform.Grav8.8CVE-2025-66297Grav is a file-based Web platform.Grav8.8CVE-2025-66296Grav is a file-based Web platform.Grav8.8CVE-2025-66295Grav is a file-based Web platform.Grav8.8CVE-2025-66294Grav is a file-based Web platform.Grav8.8CVE-2025-48986Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker…Revive Adserver8.8CVE-2025-4721Apache Struts 2 Remote Code ExecutionApache Struts 2CERT-In8.8CVE-2025-13042Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to…Chrome8.8CVE-2024-32011A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown8.8CVE-2025-9223Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated…Unknown8.8CVE-2025-34312IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an…Ipfire8.8CVE-2025-34311IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an…Ipfire8.8CVE-2025-9890The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,…Unknown8.8CVE-2025-8593The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in…Unknown8.8CVE-2025-21064Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access…Smart Switch8.8CVE-2025-27059Memory corruption while performing SCM call.Immersive Home 214 Platform Firmware8.8CVE-2025-54400Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet…Wgr-500 Firmware8.8CVE-2025-11300A security flaw has been discovered in Belkin F9K1015 1.00.10.F9k1015 Firmware8.8CVE-2025-11297A vulnerability was found in Belkin F9K1015 1.00.10.F9k1015 Firmware8.8CVE-2025-11122A vulnerability was detected in Tenda AC18 15.03.05.19.Ac18 Firmware8.8CVE-2025-20334A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject…Unknown8.8CVE-2025-10891Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially…Chrome8.8CVE-2025-10501Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially…Chrome8.8CVE-2025-10500Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially…Chrome8.8CVE-2025-9900A flaw was found in Libtiff.Unknown8.8CVE-2025-9844Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace…Unknown8.8CVE-2025-58244Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This…Unknown8.8CVE-2025-10205Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON:…Unknown8.8CVE-2025-9216The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More…Unknown8.8CVE-2025-10057The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code…Unknown8.8CVE-2025-21042Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to…AndroidKEV8.8CVE-2025-8425The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead…Unknown8.8CVE-2025-10201Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127…Chrome8.8CVE-2025-10200Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote…Chrome8.8CVE-2025-7718The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to…Unknown8.8CVE-2025-53303Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object…Unknown8.8CVE-2025-9872Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a…Endpoint Manager8.8CVE-2025-9364An open database issue exists in the affected product and version.Factorytalk Analytics Logixai8.8CVE-2025-9866Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote…Chrome8.8CVE-2025-8299Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local…Wi-Fi Usb Driver8.8CVE-2025-9813A vulnerability was identified in Tenda CH22 1.0.0.1.Ch22 Firmware8.8CVE-2025-9812A vulnerability was determined in Tenda CH22 1.0.0.1.Ch22 Firmware8.8CVE-2025-9791A weakness has been identified in Tenda AC20 16.03.08.05.Ac20 Firmware8.8CVE-2025-9783A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423.A702r Firmware8.8CVE-2025-9782A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423.A702r Firmware8.8CVE-2025-9781A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423.A702r Firmware8.8CVE-2025-9780A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423.A702r Firmware8.8CVE-2025-9779A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423.A702r Firmware8.8CVE-2025-30264A command injection vulnerability has been reported to affect several QNAP operating system versions.Qts8.8CVE-2024-13986Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary…Nagios Xi8.8CVE-2025-54742Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object…Unknown8.8CVE-2025-8040Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140.Firefox8.8CVE-2025-8035Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird…Firefox8.8CVE-2025-8034Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR…Firefox8.8CVE-2025-6558Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157…ChromeKEV8.8CVE-2025-6426The executable file warning did not warn users before opening files with the `terminal` extension.Firefox8.8CVE-2025-4919An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array…Firefox8.8CVE-2025-2817Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level…Firefox8.8CVE-2025-1930On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a…Firefox8.8CVE-2025-1014Certificate length was not properly checked when added to a certificate store.Firefox8.8CVE-2025-1011A bug in WebAssembly code generation could have lead to a crash.Firefox8.8CVE-2025-1010An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially…Firefox8.8CVE-2024-7399Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server…Magicinfo 9 ServerKEV8.8CVE-2024-41062In the Linux kernel, the following vulnerability has been resolved: bluetooth/l2cap: sync sock recv cb…Linux Kernel8.8CVE-2021-26411Internet Explorer Memory Corruption VulnerabilityEdgeKEV8.8CVE-2017-6884A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware…Emg2926 FirmwareKEV8.6CVE-2025-55222A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function…Diris M-70 Firmware8.6CVE-2025-55221A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function…Diris M-70 Firmware8.6CVE-2025-26858A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9.Diris M-70 Firmware8.6CVE-2025-23417A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS…Diris M-70 Firmware8.6CVE-2024-48882A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9.Diris M-70 Firmware8.6CVE-2025-20315A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could…Unknown8.6CVE-2025-8085The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its…Ditty8.6CVE-2025-6432When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain…Firefox8.5CVE-2025-66300Grav is a file-based Web platform.Grav8.5CVE-2025-8067A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the…Unknown8.4CVE-2025-64298NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is…Biodose/Nmis8.4CVE-2024-45675IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server…Informix Dynamic Server8.4CVE-2025-10906A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS.Unknown8.4CVE-2023-52629In the Linux kernel, the following vulnerability has been resolved: sh: push-switch: Reorder cleanup…Linux Kernel8.3CVE-2025-62575NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database.Biodose/Nmis8.3CVE-2025-61940NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the…Biodose/Nmis8.3CVE-2025-61687Flowise is a drag & drop user interface to build a customized large language model flow.Flowise8.2CVE-2025-50538Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.Flowise8.2CVE-2025-29192Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.Flowise8.2CVE-2025-21488Information disclosure while decoding this RTP packet headers received by UE from the network when the…Fastconnect 6200 Firmware8.2CVE-2025-21487Information disclosure while decoding RTP packet received by UE from the network, when payload length…Apq8017 Firmware8.2CVE-2025-21484Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling…Sm8750 Firmware8.2CVE-2025-59430Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect.Unknown8.2CVE-2023-46805An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy…Connect SecureKEV8.1CVE-2025-13639Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker…Chrome8.1CVE-2024-39148The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an…Keros