17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 9951-10000 of 17874 CVEs Page 200 of 358
CVE-2025-6810
Analyzed
9.8
Mescius Multiple Products

Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers...

2025-07-07
CVE-2025-68068
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm stock...

2025-12-17
CVE-2025-68067
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm Core...

2025-12-17
CVE-2025-68066
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad a...

2025-12-17
CVE-2025-68065
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LiquidThemes Hub Core hub-cor...

2025-12-17
CVE-2025-68064
Analyzed
7.5
Everthemess Goya Core

Contributor Local File Inclusion in Goya Core < 1

2026-06-28
CVE-2025-68063
Analyzed
7.5
WordPress Splash - Sport Club WordPress Theme

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4

2026-06-28
CVE-2025-68062
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog a...

2025-12-17
CVE-2025-68061
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall all...

2025-12-17
CVE-2025-68060
7.6
WPMart Team Member Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member allows Blind SQL Injection

2026-05-09
CVE-2025-68056
8.5
Zoom Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutsl...

2025-12-17
CVE-2025-68055
8.5
Themefic Hydra Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL...

2025-12-17
CVE-2025-68054
Analyzed
8.5
Intel Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Backg...

2025-12-17
CVE-2025-68053
Analyzed
8.5
Intel Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows B...

2025-12-17
CVE-2025-68052
Analyzed
8.8
Eagle-Themes Eagle Booking

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1

2026-06-27
CVE-2025-68044
8.6
Rustaurius Five Star Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configure...

2026-01-06
CVE-2025-68038
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Ic...

2025-12-25
CVE-2025-68036
7.5
Emraan Cheema CubeWP Multiple Products

Missing Authorization vulnerability in Emraan Cheema CubeWP allows Accessing Functionality Not Properly Constrained by ACLs

2025-12-30
CVE-2025-68033
7.5
Brecht Custom Related Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts allows Retrieve Embedded Sensitive Data

2026-01-06
CVE-2025-6802
Analyzed
9.8
Unknown Multiple Products

Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex...

2025-07-07
CVE-2025-67962
Analyzed
7.6
AIOSEO Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AIOSEO Plugin Team Broken Link Checker broken-li...

2025-12-17
CVE-2025-67950
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-p...

2025-12-17
CVE-2025-6794
Analyzed
9.8
Unknown Multiple Products

Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb...

2025-07-07
CVE-2025-67937
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon a...

2026-01-09
CVE-2025-67936
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly all...

2026-01-09
CVE-2025-67935
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimi...

2026-01-09
CVE-2025-67934
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring well...

2026-01-09
CVE-2025-67931
7.5
AITpro BulletProof Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in AITpro BulletProof Security bulletproof-security allows Retrieve Embedded Sensitive...

2026-01-09
CVE-2025-67928
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows...

2026-01-09
CVE-2025-67926
8.8
Shahjahan Jewel Multiple Products

Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security...

2026-01-09
CVE-2025-67925
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zozothemes Corpkit corpkit al...

2026-01-09
CVE-2025-67924
Analyzed
9.8
Unknown Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affec...

2026-01-09
CVE-2025-67921
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.T...

2026-01-09
CVE-2025-67920
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Neo Ocular neoo...

2026-01-09
CVE-2025-67919
Analyzed
8.1
WofficeIO Woffice Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access...

2026-01-09
CVE-2025-67917
8.1
Unknown Multiple Products

Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels

2026-01-09
CVE-2025-67915
Analyzed
9.8
Unknown Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects T...

2026-01-09
CVE-2025-67914
7.5
Path Multiple Products

Path Traversal: '

2026-01-09
CVE-2025-67913
Analyzed
9.8
Unknown Multiple Products

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by...

2026-01-09
CVE-2025-67911
Analyzed
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newslett...

2026-01-09
CVE-2025-67910
Analyzed
9.8
Unknown Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.T...

2026-01-09
CVE-2025-6791
8.8
Unknown Multiple Products

On the monitoring event logs page, it is possible to alter the http request to insert a payload in the DB

2025-08-23
CVE-2025-67909
Analyzed
8.1
WP Swings Membership Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting In...

2025-12-25
CVE-2025-67905
8.7
Malwarebytes Multiple Products

Malwarebytes AdwCleaner before v

2026-02-18
CVE-2025-67900
Analyzed
8.1
Agent Multiple Products

NXLog Agent before 6

2025-12-15
CVE-2025-67895
Analyzed
9.8
Apache Multiple Products

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on A...

2025-12-18
CVE-2025-67877
8.8
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-19
CVE-2025-67853
7.5
Unknown Multiple Products

A flaw was found in Moodle

2026-02-04
CVE-2025-67850
7.3
Unknown Multiple Products

A flaw was found in moodle

2026-02-04
CVE-2025-67849
7.3
Unknown Multiple Products

A flaw was found in Moodle

2026-02-04