8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 6751-6800 of 8341 CVEs Page 136 of 167
CVE-2025-13088
Analyzed
8.8
WordPress Multiple Products

The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2025-11-19
CVE-2025-13084
Analyzed
7.6
Unknown Multiple Products

The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys

2025-11-27
CVE-2025-13077
Analyzed
7.5
WordPress Multiple Products

The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'col...

2025-12-14
CVE-2025-13073
7.1
WordPress Multiple Products

The HandL UTM Grabber / Tracker WordPress plugin before 2

2025-12-12
CVE-2025-13072
7.1
WordPress Multiple Products

The HandL UTM Grabber / Tracker WordPress plugin before 2

2025-12-12
CVE-2025-13069
8.8
WordPress Multiple Products

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1

2025-11-19
CVE-2025-13068
Analyzed
7.2
WordPress Multiple Products

The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username in all versions up to, and incl...

2025-11-26
CVE-2025-13066
8.8
WordPress Multiple Products

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2

2025-12-06
CVE-2025-13065
Analyzed
8.8
WordPress Multiple Products

The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4

2025-12-07
CVE-2025-13063
7.3
Dee Multiple Products

A flaw has been found in DinukaNavaratna Dee Store 1

2025-11-14
CVE-2025-13062
Analyzed
8.8
WordPress Multiple Products

The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2

2026-01-16
CVE-2025-13060
7.3
Unknown Multiple Products

A security vulnerability has been detected in SourceCodester Survey Application System 1

2025-11-14
CVE-2025-13047
7.5
Bacteriology Multiple Products

Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers...

2025-11-14
CVE-2025-13046
7.5
Bacteriology Multiple Products

Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers...

2025-11-14
CVE-2025-13042
8.8
Google Multiple Products

Inappropriate implementation in V8 in Google Chrome prior to 142

2025-11-13
CVE-2025-13035
Analyzed
8
HP Multiple Products

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3

2025-11-20
CVE-2025-13033
7.5
Unknown Multiple Products

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses

2025-11-15
CVE-2025-13027
8.1
Unknown Multiple Products

Memory safety bugs present in Firefox 144 and Thunderbird 144

2025-11-13
CVE-2025-13020
8.8
Unknown Multiple Products

Use-after-free in the WebRTC: Audio/Video component

2025-11-13
CVE-2025-13019
8.1
Unknown Multiple Products

Same-origin policy bypass in the DOM: Workers component

2025-11-13
CVE-2025-13018
8.1
Mitigation Multiple Products

Mitigation bypass in the DOM: Security component

2025-11-13
CVE-2025-13017
8.1
Unknown Multiple Products

Same-origin policy bypass in the DOM: Notifications component

2025-11-13
CVE-2025-13014
8.8
Unknown Multiple Products

Use-after-free in the Audio/Video component

2025-11-13
CVE-2025-13003
7.6
Aksis Computer Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc

2025-12-12
CVE-2025-13000
Analyzed
7.7
WordPress Multiple Products

The db-access WordPress plugin through 0

2025-12-03
CVE-2025-12995
8.1
Unknown Multiple Products

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determin...

2025-12-05
CVE-2025-12985
8.4
IBM Multiple Products

IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running...

2026-01-21
CVE-2025-12980
Analyzed
7.5
WordPress Multiple Products

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access of data due to a m...

2025-12-21
CVE-2025-12977
Analyzed
9.1
Fluent Bit Multiple Products

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to w...

2025-11-25
CVE-2025-12974
8.1
WordPress Multiple Products

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechan...

2025-11-19
CVE-2025-12973
Analyzed
7.2
WordPress Multiple Products

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing...

2025-11-22
CVE-2025-12970
Analyzed
8.8
Docker Multiple Products

The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length

2025-11-25
CVE-2025-12968
Analyzed
8.8
WordPress Multiple Products

The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all vers...

2025-12-13
CVE-2025-12967
Analyzed
8
Unknown Multiple Products

An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role

2025-11-11
CVE-2025-12966
Analyzed
8.8
WordPress Multiple Products

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_di...

2025-12-07
CVE-2025-12963
Analyzed
9.8
WordPress Multiple Products

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via ac...

2025-12-13
CVE-2025-12957
Analyzed
8.8
WordPress Multiple Products

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4

2026-01-16
CVE-2025-12956
8.7
Unknown Multiple Products

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Releas...

2025-12-09
CVE-2025-12955
Analyzed
7.5
WordPress Multiple Products

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2

2025-11-19
CVE-2025-12938
7.3
Admission Multiple Products

A vulnerability was identified in projectworlds Online Admission System 1

2025-11-11
CVE-2025-12934
Analyzed
8.1
WordPress Multiple Products

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabi...

2025-12-24
CVE-2025-12929
7.3
Unknown Multiple Products

A flaw has been found in SourceCodester Survey Application System 1

2025-11-11
CVE-2025-12928
7.3
Search Multiple Products

A vulnerability was detected in code-projects Online Job Search Engine 1

2025-11-11
CVE-2025-12925
7.3
Unknown Multiple Products

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224

2025-11-11
CVE-2025-12904
Analyzed
7.2
WordPress Multiple Products

The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up...

2025-11-15
CVE-2025-12903
7.5
WordPress Multiple Products

The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-b...

2025-11-14
CVE-2025-12879
8.8
WordPress Multiple Products

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1

2025-12-06
CVE-2025-12871
Analyzed
9.8
Unknown Multiple Products

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access toke...

2025-11-13
CVE-2025-12870
Analyzed
9.8
Unknown Multiple Products

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain...

2025-11-13
CVE-2025-12868
Analyzed
9.8
Unknown Multiple Products

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the...

2025-11-11