8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 6851-6900 of 8341 CVEs Page 138 of 167
CVE-2025-12550
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes OchaHouse ochahouse...

2026-01-09
CVE-2025-12549
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Rozy - Flower Shop...

2026-01-09
CVE-2025-12548
Analyzed
9
Intel Multiple Products

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration...

2026-01-14
CVE-2025-12543
Analyzed
9.6
Apache Multiple Products

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pro...

2026-01-08
CVE-2025-12531
7.1
IBM Multiple Products

IBM InfoSphere Information Server 11

2025-11-04
CVE-2025-12529
Analyzed
8.8
WordPress Multiple Products

The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrders...

2025-12-03
CVE-2025-12528
8.1
WordPress Multiple Products

The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1

2025-11-19
CVE-2025-12514
Analyzed
7.2
Centreon Infra Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notifi...

2025-12-23
CVE-2025-12510
Analyzed
7.2
Google Multiple Products

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 13

2025-12-07
CVE-2025-12509
8.4
Unknown Multiple Products

On a client with an admin user, a Global_Shipping script can be implemented

2025-10-31
CVE-2025-12508
8.4
Unknown Multiple Products

When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted

2025-10-31
CVE-2025-12507
8.8
Communication Multiple Products

The service Bizerba Communication Server (BCS) has an unquoted service path

2025-10-31
CVE-2025-12504
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TalentSoft Software UNIS allows SQL Injection.Th...

2025-12-10
CVE-2025-12501
7.5
IDE Multiple Products

Integer overflow in GameMaker IDE below 2024

2025-10-31
CVE-2025-12499
Analyzed
7.2
Google Multiple Products

The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the contents of a Google Review in all ve...

2025-12-07
CVE-2025-12497
Analyzed
8.1
WordPress Multiple Products

The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2

2025-11-06
CVE-2025-12495
7.8
Academy Multiple Products

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-12493
Analyzed
9.8
WordPress Multiple Products

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerab...

2025-11-04
CVE-2025-12490
8.8
Netgate Multiple Products

Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability

2025-11-06
CVE-2025-12489
7.8
Unknown Multiple Products

evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability

2025-11-06
CVE-2025-12488
Analyzed
9.8
Intel Multiple Products

oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote a...

2025-11-06
CVE-2025-12487
Analyzed
9.8
Intel Multiple Products

oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote a...

2025-11-06
CVE-2025-12486
Analyzed
8.8
Heimdall Multiple Products

Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability

2025-11-06
CVE-2025-12485
8.8
Devolutions Multiple Products

Improper privilege management during pre-MFA cookie handling in Devolutions Server 2025

2025-11-06
CVE-2025-12484
Analyzed
7.2
WordPress Multiple Products

The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to St...

2025-11-20
CVE-2025-12482
Analyzed
7.5
WordPress Multiple Products

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versio...

2025-11-17
CVE-2025-12480
KEV Analyzed
9.1
Unknown Multiple Products

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after set...

2025-11-11
CVE-2025-12466
7.5
Drupal Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass

2025-10-30
CVE-2025-12463
Analyzed
9.8
Unknown Multiple Products

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Pa...

2025-11-04
CVE-2025-12438
Analyzed
8.8
Google Multiple Products

Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142

2025-11-11
CVE-2025-12432
Analyzed
8.8
Google Multiple Products

Race in V8 in Google Chrome prior to 142

2025-11-11
CVE-2025-12429
Analyzed
8.8
Google Multiple Products

Inappropriate implementation in V8 in Google Chrome prior to 142

2025-11-11
CVE-2025-12421
Analyzed
9.9
Intel Multiple Products

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code...

2025-11-28
CVE-2025-12419
Analyzed
9.9
Unknown Multiple Products

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during Op...

2025-11-28
CVE-2025-12411
Analyzed
7.1
WordPress Multiple Products

The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' parameter in versions up to, and incl...

2025-11-19
CVE-2025-12399
Analyzed
7.2
WordPress Multiple Products

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...

2025-11-09
CVE-2025-12384
Analyzed
8.6
WordPress Multiple Products

The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data i...

2025-11-06
CVE-2025-12380
Analyzed
9.8
Unknown Multiple Products

Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-rela...

2025-10-29
CVE-2025-12378
7.3
Unknown Multiple Products

A security flaw has been discovered in code-projects Simple Food Ordering System 1

2025-10-29
CVE-2025-12374
9.8
WordPress Multiple Products

The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerabl...

2025-12-06
CVE-2025-12357
8.3
Unknown Multiple Products

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle a...

2025-10-31
CVE-2025-12352
Analyzed
9.8
WordPress Multiple Products

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function i...

2025-11-08
CVE-2025-12342
7.3
Unknown Multiple Products

A flaw has been found in Serdar Bayram Ghost Hot Spot up to 20251014

2025-10-29
CVE-2025-12341
7.8
Unknown Multiple Products

A vulnerability was detected in ermig1979 AntiDupl up to 2

2025-10-28
CVE-2025-12339
7.3
Online Multiple Products

A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1

2025-10-29
CVE-2025-12338
7.3
Online Multiple Products

A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1

2025-10-29
CVE-2025-12337
7.3
Online Multiple Products

A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1

2025-10-29
CVE-2025-12336
7.3
Online Multiple Products

A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1

2025-10-29
CVE-2025-12326
7.3
Unknown Multiple Products

A vulnerability was found in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5

2025-10-27
CVE-2025-12325
7.3
Unknown Multiple Products

A vulnerability has been found in SourceCodester Best Salon Management System 1

2025-10-27