17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 9901-9950 of 17874 CVEs Page 199 of 358
CVE-2025-68519
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-wooco...

2025-12-25
CVE-2025-68517
8.1
Essekia Tablesome Multiple Products

Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68516
7.5
Essekia Tablesome Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in Essekia Tablesome tablesome allows Retrieve Embedded Sensitive Data

2025-12-26
CVE-2025-68511
Analyzed
9.1
Unknown Multiple Products

Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Leve...

2025-12-25
CVE-2025-68508
Analyzed
9.1
Unknown Multiple Products

Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This is...

2025-12-25
CVE-2025-68506
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache do...

2025-12-25
CVE-2025-68505
Analyzed
8.8
Unknown Multiple Products

Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68500
Analyzed
9.1
WordPress Multiple Products

Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Server Side Request...

2025-12-25
CVE-2025-68496
Analyzed
9.8
WordPress Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allo...

2025-12-25
CVE-2025-68494
Analyzed
7.5
Intel Multiple Products

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-ele...

2025-12-26
CVE-2025-68493
Analyzed
8.1
Apache Multiple Products

Missing XML Validation vulnerability in Apache Struts, Apache Struts

2026-01-13
CVE-2025-68479
7.1
Discourse Multiple Products

Discourse is an open source discussion platform

2026-01-29
CVE-2025-68478
7.1
Langflow Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2025-12-20
CVE-2025-68477
7.7
Langflow Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2025-12-20
CVE-2025-68475
7.5
Unknown Multiple Products

Fedify is a TypeScript library for building federated server apps powered by ActivityPub

2025-12-23
CVE-2025-68472
8.1
Intel Multiple Products

MindsDB is a platform for building artificial intelligence from enterprise data

2026-01-13
CVE-2025-68461
KEV
7.2
Webmail Multiple Products

Roundcube Webmail before 1

2025-12-18
CVE-2025-68460
7.2
Webmail Multiple Products

Roundcube Webmail before 1

2025-12-18
CVE-2025-68459
7.2
Ruijie Multiple Products

RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co

2025-12-18
CVE-2025-68438
Analyzed
7.5
Apache Multiple Products

In Apache Airflow versions before 3

2026-01-18
CVE-2025-68435
Analyzed
9.1
Unknown Multiple Products

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication...

2025-12-18
CVE-2025-68434
Analyzed
8.8
HP Multiple Products

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework

2025-12-18
CVE-2025-68433
7.7
Unknown Multiple Products

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0

2025-12-18
CVE-2025-68432
7.7
Unknown Multiple Products

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0

2025-12-18
CVE-2025-68429
7.3
Storybook Multiple Products

Storybook is a frontend workshop for building user interface components and pages in isolation

2025-12-18
CVE-2025-68400
8.8
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-19
CVE-2025-68398
Analyzed
9.1
Unknown Multiple Products

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of it...

2025-12-19
CVE-2025-68385
7.2
Unknown Multiple Products

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script...

2025-12-20
CVE-2025-6830
Analyzed
9.8
Infor Xpoda Studio

Xpoda Studio is vulnerable to SQL injection due to improper neutralization of special elements, potentially allowing unauthorized database access and...

2026-02-10
CVE-2025-68279
7.7
Weblate Multiple Products

Weblate is a web based localization tool

2025-12-20
CVE-2025-68272
Analyzed
7.5
Signal Multiple Products

Signal K Server is a server application that runs on a central hub in a boat

2026-01-02
CVE-2025-68271
Analyzed
10
Unknown Multiple Products

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 C...

2026-01-14
CVE-2025-68270
Analyzed
9.9
Intel Multiple Products

The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are ab...

2025-12-17
CVE-2025-68156
7.5
Expr Multiple Products

Expr is an expression language and expression evaluation for Go

2025-12-17
CVE-2025-68155
7.5
React Multiple Products

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite

2025-12-17
CVE-2025-68154
8.1
Unknown Multiple Products

systeminformation is a System and OS information library for node

2025-12-17
CVE-2025-68147
Analyzed
8.1
HP Multiple Products

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework

2025-12-18
CVE-2025-68141
7.4
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-22
CVE-2025-6814
7.5
WordPress Multiple Products

The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in vers...

2025-07-06
CVE-2025-68137
8.3
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-22
CVE-2025-68136
7.4
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-22
CVE-2025-68134
7.4
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-22
CVE-2025-68133
7.4
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-21
CVE-2025-68119
7
Downloading Multiple Products

Downloading and building modules with malicious version strings can cause local code execution

2026-01-30
CVE-2025-68116
8.9
Unknown Multiple Products

FileRise is a self-hosted web file manager / WebDAV server

2025-12-17
CVE-2025-68112
Analyzed
9.6
Tenda Multiple Products

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor a...

2025-12-18
CVE-2025-68111
7.2
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-18
CVE-2025-68110
Analyzed
9.9
Unknown Multiple Products

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host...

2025-12-18
CVE-2025-6811
Analyzed
9.8
Mescius Multiple Products

Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot...

2025-07-07
CVE-2025-68109
Analyzed
9.1
HP Multiple Products

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or...

2025-12-18