8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 5601-5650 of 8341 CVEs Page 113 of 167
CVE-2025-29534
Analyzed
8.8
Unknown Multiple Products

An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1

2025-07-28
CVE-2025-29523
7.2
D-Link Multiple Products

D-Link DSL-7740C with firmware DSL7740C

2025-08-25
CVE-2025-29516
7.2
D-Link Multiple Products

D-Link DSL-7740C with firmware DSL7740C

2025-08-25
CVE-2025-29515
9.8
D-Link Multiple Products

Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitra...

2025-08-25
CVE-2025-29514
9.8
D-Link Multiple Products

Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to download the conf...

2025-08-25
CVE-2025-29421
7.5
PerfreeBlog Multiple Products

PerfreeBlog v4

2025-08-26
CVE-2025-29420
7.5
PerfreeBlog Multiple Products

PerfreeBlog v4

2025-08-26
CVE-2025-29365
Analyzed
9.8
Unknown Multiple Products

spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.

2025-08-23
CVE-2025-2932
Analyzed
8.8
WordPress Multiple Products

The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' funct...

2025-07-05
CVE-2025-2928
7.2
Unknown Multiple Products

SQL Injection affecting the Archiver role

2025-07-29
CVE-2025-29270
Analyzed
10
Unknown Multiple Products

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the...

2025-10-31
CVE-2025-29229
Analyzed
9.8
Linksys Multiple Products

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

2025-12-24
CVE-2025-29228
9.8
Linksys Multiple Products

Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

2025-12-24
CVE-2025-29192
8.2
Flowise Multiple Products

Flowise before 3

2025-10-06
CVE-2025-29009
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce allows Upload a Web She...

2025-07-16
CVE-2025-29004
Analyzed
8.8
WordPress Multiple Products

Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing P...

2026-01-07
CVE-2025-29000
7.5
August Infotech Multiple Products

Missing Authorization vulnerability in August Infotech Multi-language Responsive Contact Form allows Accessing Functionality Not Properly Constrained...

2025-07-16
CVE-2025-28983
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Pri...

2025-07-06
CVE-2025-28982
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This is...

2025-07-16
CVE-2025-28980
7.7
Unknown Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Tra...

2025-07-06
CVE-2025-28979
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PHP...

2025-08-14
CVE-2025-28977
7.1
ThimPress WP Pipes Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS

2025-08-20
CVE-2025-28969
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widget allows SQL Injection

2025-07-06
CVE-2025-28967
8.5
Steve Truman Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LI...

2025-07-05
CVE-2025-28965
8.6
Md Yeasin Ul Haider Multiple Products

Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener allows Accessing Functionality Not Properly Constrained by ACLs

2025-07-16
CVE-2025-28961
Analyzed
9.8
Intel Multiple Products

Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener allows Object Injection. This issue affects URL Shortener: from n...

2025-07-16
CVE-2025-28959
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haider URL Shortener allows SQL Inj...

2025-07-16
CVE-2025-28955
Analyzed
7.5
WordPress Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Player Wordpress & WooCommerce all...

2025-07-16
CVE-2025-28951
9.1
Unknown Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image allows Upload a Web Shell to a Web Server. This issue a...

2025-07-06
CVE-2025-28949
Analyzed
8.5
WordPress Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Fol...

2026-01-01
CVE-2025-2843
8.8
Unknown Multiple Products

A flaw was found in the Observability Operator

2025-11-13
CVE-2025-28357
8.8
Unknown Multiple Products

A CRLF injection vulnerability in Neto CMS v6

2025-10-01
CVE-2025-2824
7.4
IBM Multiple Products

IBM Operational Decision Manager 8

2025-08-01
CVE-2025-28170
7.6
Grandstream Multiple Products

Grandstream Networks GXP1628 <=1

2025-07-29
CVE-2025-2813
Analyzed
7.5
Unknown Multiple Products

An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80

2025-07-31
CVE-2025-28041
8.6
Unknown Multiple Products

Incorrect access control in the doFilter function of itranswarp up to 2

2025-08-21
CVE-2025-2800
Analyzed
7.2
WordPress Multiple Products

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting...

2025-07-16
CVE-2025-27919
8.2
AnyDesk Multiple Products

An issue was discovered in AnyDesk through 9

2025-11-08
CVE-2025-27917
7.5
AnyDesk Multiple Products

An issue was discovered in AnyDesk through 9

2025-11-08
CVE-2025-27916
7.5
AnyDesk Multiple Products

An issue was discovered in AnyDesk through 9

2025-11-08
CVE-2025-27915
KEV
9.5
Synacor Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability - Active in CISA KEV catalog.

2025-10-07
CVE-2025-27845
Analyzed
9.8
Intel Multiple Products

In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This all...

2025-08-15
CVE-2025-27821
Analyzed
7.3
Apache Multiple Products

Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client

2026-01-27
CVE-2025-2776
KEV
9.5
SysAid SysAid On-Prem

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.

2025-07-23
CVE-2025-2775
KEV
9.5
SysAid SysAid On-Prem

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.

2025-07-23
CVE-2025-27724
Analyzed
9.3
HP Multiple Products

A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file...

2025-07-28
CVE-2025-27721
7.5
Unknown Multiple Products

Unauthorized users can access INFINITT PACS System Manager without proper authorization, which could lead to unauthorized access to system resources

2025-08-21
CVE-2025-27713
7.8
Microsoft Multiple Products

Out-of-bounds write for some Intel(R) QAT Windows software before version 2

2025-11-13
CVE-2025-27614
Analyzed
8.6
Intel Multiple Products

Gitk is a Tcl/Tk based Git history browser

2025-07-11
CVE-2025-27582
7.6
Unknown Multiple Products

The Secure Password extension in One Identity Password Manager before 5

2025-07-14