CVE.report search for "CVE-2025-22012"

Listed below are 50 relevant search results for "CVE-2025-22012" based on Vendor, Software, and CVE description

These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.

If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.

Search Results

CVE ID Vendor Software Description
CVE-2026-101878Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalI...
CVE-2026-101082A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloader.asp...
CVE-2026-100255In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
CVE-2026-100254In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via ...
CVE-2026-100253In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the vers...
CVE-2026-97952In the Linux kernel, the following vulnerability has been resolved: sunvdc: unmap LDC cookies when the descriptor send fails...
CVE-2026-96429SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allo...
CVE-2026-96428SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allow...
CVE-2026-94152A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function...
CVE-2026-94091A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/...
CVE-2026-93348Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injecti...
CVE-2026-93310A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. T...
CVE-2026-93309A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the co...
CVE-2026-93308A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the c...
CVE-2026-93307A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector...
CVE-2026-93255In the Linux kernel, the following vulnerability has been resolved: btrfs: make sure EXTENT_BUFFER_READING is cleared under ...
CVE-2026-92419WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople...
CVE-2026-91855A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the...
CVE-2026-89212A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted ...
CVE-2026-89089A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian an...
CVE-2026-86698Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization members...
CVE-2026-86498In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked enti...
CVE-2026-86479In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted R...
CVE-2026-86478In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticate...
CVE-2026-85979Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administr...
CVE-2026-84675OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environ...
CVE-2026-80652In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Treat zero-length cert chain as query for ...
CVE-2026-78397The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back t...
CVE-2026-78329ApacheCamelImproper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 b...
CVE-2026-78205BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-loca...
CVE-2026-77680An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. ...
CVE-2026-75554Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an o...
CVE-2026-75542Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories p...
CVE-2026-75045JetbrainsYoutrackIn JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database ...
CVE-2026-75044JetbrainsYoutrackIn JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user ...
CVE-2026-73557vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vl...
CVE-2026-70559Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that s...
CVE-2026-69263FlowiseaiFlowiseFlowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for C...
CVE-2026-68456In the Linux kernel, the following vulnerability has been resolved: usb: atm: ueagle-atm: wait for pre-firmware load in .dis...
CVE-2026-67967Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incompl...
CVE-2026-65907In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
CVE-2026-65906In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
CVE-2026-64593In the Linux kernel, the following vulnerability has been resolved: btrfs: do not trim a device which is not writeable [BUG...
CVE-2026-64100LinuxLinux KernelIn the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix shrinker deadlock With PROVE_LOCKING on an...
CVE-2026-64065LinuxLinux KernelIn the Linux kernel, the following vulnerability has been resolved: netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin(...
CVE-2026-63884In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: T...
CVE-2026-63794LinuxLinux KernelIn the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRY...
CVE-2026-63621ApacheCamelImproper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')...
CVE-2026-63077JetbrainsTeamcityIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling pro...
CVE-2026-62987Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 f...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report