20297 Total CVEs
11590 AI Analyzed
295 CISA KEV
4359 Critical
All Vendors
Showing 1201-1250 of 20297 CVEs Page 25 of 406
CVE-2026-65552
Analyzed
9.8
HP Export User Data

The Export User Data WordPress plugin is vulnerable to PHP object injection, which allows unauthenticated attackers to execute arbitrary code or manip...

2026-08-06
CVE-2026-6555
Analyzed
9.8
WordPress is vulnerable

The ProSolution WP Client WordPress plugin is vulnerable to arbitrary file upload due to improper validation of the upload array, allowing remote code...

2026-05-20
CVE-2026-65548
Analyzed
9.9
WordPress Betheme

A critical remote code execution vulnerability exists in the Betheme WordPress theme, allowing authenticated contributors to execute arbitrary code on...

2026-08-06
CVE-2026-65547
Analyzed
8.5
WordPress Creative Mail

Subscriber SQL Injection in Creative Mail <= 1

2026-08-06
CVE-2026-65542
Analyzed
8.8
WordPress Super Socializer

Unauthenticated Broken Authentication in Super Socializer <= 7

2026-08-06
CVE-2026-65532
Analyzed
7.6
PersianScript Persian Woocommerce SMS

Shop manager SQL Injection in Persian Woocommerce SMS <= 7

2026-07-24
CVE-2026-65526
Analyzed
8.5
WordPress Visualizer

Contributor SQL Injection in Visualizer <= 4

2026-07-24
CVE-2026-6552
Analyzed
8.7
GitLab GitLab EE

GitLab has remediated an issue in GitLab EE affecting all versions from 15

2026-06-12
CVE-2026-65507
Analyzed
9.8
WordPress AIWU

The AIWU plugin for WordPress is susceptible to an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment.

2026-08-06
CVE-2026-65471
Analyzed
9.6
WordPress Avada Core

Avada Core versions 5.15.6 and below are vulnerable to an unauthenticated Cross-Site Request Forgery (CSRF) attack, potentially leading to unauthorize...

2026-07-24
CVE-2026-65462
Analyzed
7.6
WordPress Uncanny Automator

Administrator SQL Injection in Uncanny Automator <= 7

2026-07-24
CVE-2026-65454
Analyzed
8.5
WordPress Quiz And Survey Master

Contributor SQL Injection in Quiz And Survey Master <= 11

2026-07-24
CVE-2026-65451
Analyzed
8.5
WordPress MapSVG

Contributor SQL Injection in MapSVG <= 8

2026-07-24
CVE-2026-65450
Analyzed
8.5
WordPress MapSVG

Contributor SQL Injection in MapSVG <= 8

2026-07-24
CVE-2026-65442
Analyzed
7.2
WordPress FormCraft

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3

2026-07-28
CVE-2026-65431
Analyzed
9.8
Joomla GeoIP extension for Joomla

A path traversal vulnerability in the Regular Labs GeoIP extension for Joomla allows for arbitrary file writes during the extraction of database updat...

2026-08-02
CVE-2026-65430
Analyzed
7.5
Joomla GeoIP extension for Joomla

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a crede...

2026-08-02
CVE-2026-6543
8.8
IBM Langflow Desktop

IBM Langflow Desktop 1

2026-05-01
CVE-2026-65423
Analyzed
8.8
GitHub open62541

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write

2026-07-31
CVE-2026-6540
Analyzed
7.9
Tigera Calico

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization

2026-08-01
CVE-2026-65321
Analyzed
9.8
Unknown PyAthena

An SQL injection vulnerability in PyAthena versions prior to 3.35.4 allows unauthenticated attackers to execute arbitrary SQL commands due to improper...

2026-08-03
CVE-2026-65313
Analyzed
8.1
ANDRITZ HIPASE-250

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password

2026-08-01
CVE-2026-65310
Analyzed
7.5
ANDRITZ HIPASE-250

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any au...

2026-08-01
CVE-2026-65309
Analyzed
7.5
ANDRITZ HIPASE-250

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way passwo...

2026-08-01
CVE-2026-6518
8.8
WordPress is vulnerable

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all...

2026-04-18
CVE-2026-6516
Analyzed
10
Zohocorp ManageEngine ADAudit Plus

ManageEngine ADAudit Plus is vulnerable to unauthenticated remote code execution due to a flaw in the agent API, which fails to properly neutralize OS...

2026-07-24
CVE-2026-6512
Analyzed
9.1
WordPress is vulnerable

The InfusedWoo Pro plugin for WordPress is vulnerable to an authorization bypass that allows unauthenticated attackers to perform destructive actions...

2026-05-15
CVE-2026-6510
Analyzed
9.8
WordPress is vulnerable

The InfusedWoo Pro WordPress plugin is vulnerable to authentication bypass and privilege escalation via an insecure AJAX handler.

2026-05-14
CVE-2026-6509
Analyzed
7.8
TUBITAK BILGEM Pardus Update

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation

2026-07-06
CVE-2026-6508
Analyzed
9.8
Arch Institute Liderahenk

Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properl...

2026-05-08
CVE-2026-6507
7.5
Unknown Multiple Products

A flaw was found in dnsmasq

2026-04-18
CVE-2026-6506
Analyzed
8.8
WordPress is vulnerable

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5

2026-05-14
CVE-2026-65016
Analyzed
7.7
Unknown n8n

n8n versions before 1

2026-07-24
CVE-2026-65013
Analyzed
8.8
Onlook repo

Onlook through 0

2026-07-23
CVE-2026-6495
Analyzed
7.1
WordPress plugin before

The Ajax Load More WordPress plugin before 7

2026-05-19
CVE-2026-6490
7.3
HP of the

A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593

2026-04-18
CVE-2026-64873
9.8
Joomla Cache Cleaner Pro extension for Joomla

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

2026-08-03
CVE-2026-64835
Analyzed
8.8
F5 FFmpeg

FFmpeg versions 4

2026-07-23
CVE-2026-64832
Analyzed
8.8
FFmpeg FFmpeg

FFmpeg versions 4

2026-07-23
CVE-2026-64831
Analyzed
8.8
FFmpeg FFmpeg

FFmpeg versions 8

2026-07-23
CVE-2026-64830
Analyzed
8.8
FFmpeg FFmpeg

FFmpeg versions 2

2026-07-23
CVE-2026-6483
7.2
Unknown Multiple Products

A vulnerability was found in Wavlink WL-WN530H4 20220721

2026-04-18
CVE-2026-64827
Analyzed
9.8
HP TVox

Telenia Software TVox contains an authentication bypass vulnerability via set_env.php, allowing unauthenticated attackers to access restricted PHP scr...

2026-08-04
CVE-2026-64815
Analyzed
8.1
Intel IntelliJ IDEA

In JetBrains IntelliJ IDEA before 2026

2026-07-24
CVE-2026-64814
Analyzed
8.6
Intel IntelliJ IDEA

In JetBrains IntelliJ IDEA before 2026

2026-07-24
CVE-2026-64813
Analyzed
10
Intel IntelliJ IDEA

JetBrains IntelliJ IDEA is vulnerable to unauthorized settings modification during Remote Development sessions, enabling unauthenticated attackers to...

2026-07-24
CVE-2026-64812
Analyzed
10
Intel IntelliJ IDEA

JetBrains IntelliJ IDEA is susceptible to unauthorized input injection during Remote Development sessions, allowing unauthenticated remote attackers t...

2026-07-24
CVE-2026-64811
Analyzed
7.8
Intel IntelliJ IDEA

In JetBrains IntelliJ IDEA before 2026

2026-07-24
CVE-2026-64809
Analyzed
8.4
HP PhpStorm

In JetBrains PhpStorm before 2026

2026-07-24
CVE-2026-64808
Analyzed
8.4
HP PhpStorm

In JetBrains PhpStorm before 2026

2026-07-24