18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 10601-10650 of 18466 CVEs Page 213 of 370
CVE-2025-67738
8.5
Unknown Multiple Products

squid/cachemgr

2025-12-12
CVE-2025-67733
8.5
Infor Multiple Products

Valkey is a distributed key-value database

2026-02-24
CVE-2025-67729
Analyzed
8.8
LMDeploy Multiple Products

LMDeploy is a toolkit for compressing, deploying, and serving LLMs

2025-12-27
CVE-2025-67728
Analyzed
9.8
Fireshare facilitates Multiple Products

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public...

2025-12-13
CVE-2025-67726
7.5
Tornado Multiple Products

Tornado is a Python web framework and asynchronous networking library

2025-12-13
CVE-2025-67725
7.5
Tornado Multiple Products

Tornado is a Python web framework and asynchronous networking library

2025-12-13
CVE-2025-67648
7.1
Shopware Multiple Products

Shopware is an open commerce platform

2025-12-12
CVE-2025-67645
8.8
OpenEMR Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application

2026-01-28
CVE-2025-67644
Analyzed
7.3
LangGraph Multiple Products

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite)

2025-12-12
CVE-2025-67641
8
Jenkins Multiple Products

Jenkins Coverage Plugin 2

2025-12-11
CVE-2025-67635
7.5
Jenkins Multiple Products

Jenkins 2

2025-12-12
CVE-2025-67625
Analyzed
8.8
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forgery

2025-12-25
CVE-2025-67623
Analyzed
9.1
Unknown Multiple Products

Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6...

2025-12-25
CVE-2025-67622
Analyzed
8.8
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Stored XSS

2025-12-25
CVE-2025-67621
7.5
Unknown Multiple Products

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Workflow eight-day-week-print-wo...

2025-12-26
CVE-2025-67601
8.3
Rancher Multiple Products

A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher C...

2026-02-26
CVE-2025-6758
Analyzed
9.8
WordPress Multiple Products

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' functio...

2025-08-19
CVE-2025-6754
Analyzed
8.8
WordPress Multiple Products

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_...

2025-08-04
CVE-2025-67511
Analyzed
9.6
Cybersecurity AI Multiple Products

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below...

2025-12-11
CVE-2025-67510
Analyzed
9.4
HP Multiple Products

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided b...

2025-12-11
CVE-2025-67509
Analyzed
8.2
HP Multiple Products

Neuron is a PHP framework for creating and orchestrating AI Agents

2025-12-11
CVE-2025-67508
8
Unknown Multiple Products

gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools

2025-12-13
CVE-2025-67507
8.1
Filament Multiple Products

Filament is a collection of full-stack components for accelerated Laravel development

2025-12-11
CVE-2025-67506
Analyzed
9.8
Microsoft Multiple Products

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/r...

2025-12-11
CVE-2025-67505
Analyzed
8.4
Okta Multiple Products

Okta Java Management SDK facilitates interactions with the Okta management API

2025-12-11
CVE-2025-67504
Analyzed
9.1
HP Multiple Products

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand()...

2025-12-10
CVE-2025-67495
8
ZITADEL Multiple Products

ZITADEL is an open-source identity infrastructure tool

2025-12-10
CVE-2025-67494
Analyzed
9.3
Unknown Multiple Products

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. T...

2025-12-10
CVE-2025-67493
7.5
Homarr Multiple Products

Homarr is an open-source dashboard

2025-12-18
CVE-2025-67489
Analyzed
9.8
Intel Multiple Products

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution...

2025-12-10
CVE-2025-67488
7.8
SiYuan Multiple Products

SiYuan is self-hosted, open source personal knowledge management software

2025-12-11
CVE-2025-67460
Analyzed
7.8
Microsoft Multiple Products

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6

2025-12-11
CVE-2025-6746
Analyzed
8.8
WordPress Multiple Products

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8

2025-07-08
CVE-2025-67450
Analyzed
7.8
Unknown Multiple Products

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitr...

2025-12-26
CVE-2025-67447
Analyzed
9.8
Neterbit NW-431F Router

The network diagnosis module in Neterbit NW-431F routers is vulnerable to OS command injection due to improper input sanitization.

2026-06-05
CVE-2025-67446
Analyzed
9.8
Neterbit NW-431F Router

Neterbit NW-431F routers use weak, predictable cookie values for authentication, allowing unauthenticated attackers to gain unauthorized administrativ...

2026-06-05
CVE-2025-67445
7.5
TOTOLINK Multiple Products

TOTOLINK X5000R V9

2026-02-26
CVE-2025-67442
7.6
Unknown Multiple Products

EVE-NG 6

2025-12-20
CVE-2025-67432
7.5
Unknown Multiple Products

A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21

2026-02-14
CVE-2025-6742
Analyzed
7.5
HP Multiple Products

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...

2025-07-11
CVE-2025-67419
7.5
Unknown Multiple Products

A Denial of Service (DoS) vulnerability in evershop 2

2026-01-06
CVE-2025-67418
Analyzed
9.8
ClipBucket Multiple Products

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative creden...

2025-12-23
CVE-2025-6741
7.7
Devolutions Multiple Products

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure me...

2025-07-23
CVE-2025-6737
Analyzed
7.2
Vendor Multiple Products

Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants

2025-08-25
CVE-2025-67366
7.5
Unknown Multiple Products

@sylphxltd/filesystem-mcp v0

2026-01-08
CVE-2025-67364
7.5
Unknown Multiple Products

fast-filesystem-mcp version 3

2026-01-08
CVE-2025-67325
Analyzed
9.8
Unknown Multiple Products

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote c...

2026-01-09
CVE-2025-67303
7.5
Unknown Multiple Products

An issue in ComfyUI-Manager prior to version 3

2026-01-06
CVE-2025-67298
8.1
Unknown Multiple Products

An issue in ClasroomIO before v

2026-03-12
CVE-2025-67289
Analyzed
9.6
HP Multiple Products

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading...

2025-12-23