17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 10451-10500 of 17874 CVEs Page 210 of 358
CVE-2025-64359
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting con...

2025-10-31
CVE-2025-64353
8.8
Chouby Polylang Multiple Products

Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection

2025-10-31
CVE-2025-64349
8.8
ELOG Multiple Products

ELOG allows an authenticated user to modify another user's profile

2025-10-31
CVE-2025-64348
7.1
ELOG Multiple Products

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service

2025-10-31
CVE-2025-64347
Analyzed
7.5
Apollo Multiple Products

Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2

2025-11-08
CVE-2025-64344
7.5
NSM Multiple Products

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community

2025-11-27
CVE-2025-64343
7.8
Unknown Multiple Products

(conda) Constructor is a tool that enables users to create installers for conda package collections

2025-11-08
CVE-2025-64335
7.5
NSM Multiple Products

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community

2025-11-27
CVE-2025-64334
7.5
NSM Multiple Products

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community

2025-11-27
CVE-2025-64333
7.5
NSM Multiple Products

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community

2025-11-27
CVE-2025-64332
7.5
NSM Multiple Products

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community

2025-11-27
CVE-2025-64331
7.5
NSM Multiple Products

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community

2025-11-27
CVE-2025-64330
7.5
NSM Multiple Products

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community

2025-11-27
CVE-2025-64328
KEV
9.5
Sangoma FreePBX

Sangoma FreePBX OS Command Injection Vulnerability - Active in CISA KEV catalog.

2026-02-04
CVE-2025-64314
Analyzed
9.3
Intel Multiple Products

Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability may affect confidentiality.

2025-11-29
CVE-2025-64310
Analyzed
9.8
Unknown Multiple Products

EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's p...

2025-11-22
CVE-2025-64309
8.6
Brightpick Multiple Products

Brightpick Mission Control discloses device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users when...

2025-11-15
CVE-2025-64308
Analyzed
7.5
Unknown Multiple Products

The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle

2025-11-15
CVE-2025-64301
7.8
Unknown Multiple Products

An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity

2026-03-18
CVE-2025-64298
8.4
Unknown Multiple Products

NMIS/BioDose V22

2025-12-03
CVE-2025-64293
7.6
Golemiq Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Analytics allows SQL Injection

2025-11-13
CVE-2025-64287
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Alloggio - Hotel...

2025-11-06
CVE-2025-64284
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Sup...

2025-10-29
CVE-2025-64266
8.8
Rental Multiple Products

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object...

2025-12-19
CVE-2025-64236
Analyzed
9.8
Unknown Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: fro...

2025-12-19
CVE-2025-64233
Analyzed
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2....

2025-12-19
CVE-2025-64232
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Import from YML import-from-yml allows...

2025-11-06
CVE-2025-64231
Analyzed
9.8
Google Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpr...

2025-12-19
CVE-2025-64227
Analyzed
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue aff...

2025-12-19
CVE-2025-64224
7.1
ThemeGoods Grand Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference Theme Custom Post Ty...

2025-11-06
CVE-2025-64216
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeSphere SmartMag smart-ma...

2025-10-29
CVE-2025-64206
Analyzed
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.

2025-12-19
CVE-2025-64205
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows...

2025-12-19
CVE-2025-64198
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Easy Social Share Buttons easy-social-s...

2025-11-06
CVE-2025-64196
7.1
Pluggabl Booster Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jet...

2025-11-06
CVE-2025-64195
Analyzed
7.6
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Eduma eduma allows...

2025-10-29
CVE-2025-64188
Analyzed
9.8
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <...

2025-12-19
CVE-2025-64186
8.7
Evervault Multiple Products

Evervault is a payment security solution

2025-11-13
CVE-2025-64184
Analyzed
8.8
Dosage Multiple Products

Dosage is a comic strip downloader and archiver

2025-11-08
CVE-2025-64180
Analyzed
10
Intel Multiple Products

Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorize...

2025-11-08
CVE-2025-64173
7.5
Apollo Multiple Products

Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation 2

2025-11-06
CVE-2025-64168
7.1
Agno Multiple Products

Agno is a multi-agent framework, runtime and control plane

2025-10-31
CVE-2025-64167
7.1
Combodo Multiple Products

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-64155
Analyzed
9.8
Fortinet Multiple Products

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3...

2026-01-14
CVE-2025-64140
Analyzed
8.8
Microsoft Multiple Products

Jenkins Azure CLI Plugin 0

2025-10-29
CVE-2025-64134
Analyzed
7.1
Jenkins Multiple Products

Jenkins JDepend Plugin 1

2025-10-29
CVE-2025-64131
Analyzed
7.5
Jenkins Multiple Products

Jenkins SAML Plugin 4

2025-10-29
CVE-2025-64130
Analyzed
9.8
Zenitel Multiple Products

Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript...

2025-11-27
CVE-2025-64129
Analyzed
7.6
Zenitel Multiple Products

Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the device

2025-11-27
CVE-2025-64128
Analyzed
10
HP Multiple Products

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting...

2025-11-27