17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 12951-13000 of 17874 CVEs Page 260 of 358
CVE-2025-50053
Analyzed
7.1
Apple Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin & Your nati...

2026-01-01
CVE-2025-49950
7.3
Unknown Multiple Products

Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation

2025-10-23
CVE-2025-49943
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Femme femme allo...

2025-12-19
CVE-2025-49942
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gardis gardis al...

2025-12-19
CVE-2025-49941
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes GlamChic glamchi...

2025-12-19
CVE-2025-4994
Analyzed
8.7
SafeLine SafeLine SL6/SL6+

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass

2026-06-23
CVE-2025-49935
7.4
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allo...

2025-10-23
CVE-2025-49931
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrocoBlock JetSearch jet-search allows Blind SQL...

2025-10-23
CVE-2025-49926
7.3
Laborator Kalium Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection

2025-10-23
CVE-2025-49925
7.3
VibeThemes WPLMS Multiple Products

Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-23
CVE-2025-49924
7.3
Josh Kohlbach Multiple Products

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation

2025-10-23
CVE-2025-49921
7.3
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CrocoBlock JetReviews jet-rev...

2025-10-23
CVE-2025-49916
8.6
MultiVendorX Multiple Products

Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained b...

2025-10-23
CVE-2025-49915
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-al...

2025-10-23
CVE-2025-49910
8.2
AmentoTech Private Multiple Products

Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-23
CVE-2025-49907
8.2
Unknown Multiple Products

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control...

2025-10-22
CVE-2025-49901
Analyzed
9.8
Unknown Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentic...

2025-10-23
CVE-2025-49897
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 al...

2025-08-15
CVE-2025-49895
Analyzed
8.8
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy

2025-08-17
CVE-2025-49888
7.1
Unknown Multiple Products

Missing Authorization vulnerability in pimwick PW WooCommerce On Sale! allows Exploiting Incorrectly Configured Access Control Security Levels

2025-07-16
CVE-2025-49887
Analyzed
9.9
WordPress Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce allows Remote Code Inclu...

2025-08-14
CVE-2025-49876
8.5
Metagauss ProfileGrid Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows SQL Injection

2025-07-16
CVE-2025-49870
7.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions allows SQL...

2025-07-06
CVE-2025-49869
8.8
Arraytics Eventin Multiple Products

Deserialization of Untrusted Data vulnerability in Arraytics Eventin allows Object Injection

2025-08-14
CVE-2025-49867
9.8
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege Escalation. This issue affects RealHomes: from n/a through 4....

2025-07-06
CVE-2025-49844
Analyzed
9.9
Unknown Multiple Products

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua...

2025-10-03
CVE-2025-49826
7.5
Unknown Multiple Products

Next

2025-07-06
CVE-2025-49809
7.8
Unknown Multiple Products

mtr through 0

2025-07-06
CVE-2025-49761
7.8
Microsoft Multiple Products

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-49759
8.8
Unknown Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12
CVE-2025-49758
8.8
Unknown Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12
CVE-2025-49757
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-08-12
CVE-2025-49753
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49752
Analyzed
10
Microsoft Multiple Products

Azure Bastion Elevation of Privilege Vulnerability

2025-11-20
CVE-2025-49741
7.4
Microsoft Multiple Products

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network

2025-07-06
CVE-2025-49740
8.8
Microsoft Multiple Products

Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network

2025-07-08
CVE-2025-49739
8.8
Unknown Multiple Products

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network

2025-07-10
CVE-2025-49735
8.1
Microsoft Multiple Products

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network

2025-07-10
CVE-2025-49729
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49724
8.8
Microsoft Multiple Products

Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49723
8.8
Microsoft Multiple Products

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally

2025-07-08
CVE-2025-49717
8.5
Unknown Multiple Products

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network

2025-07-10
CVE-2025-49713
Analyzed
8.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over...

2025-07-05
CVE-2025-49712
Analyzed
8.8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-49708
Analyzed
9.9
Microsoft Multiple Products

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

2025-10-14
CVE-2025-49707
7.9
Microsoft Multiple Products

Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally

2025-08-12
CVE-2025-49704
8.8
Microsoft Multiple Products

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-07-08
CVE-2025-49701
Analyzed
8.8
Microsoft Multiple Products

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-07-08
CVE-2025-49697
8.4
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally

2025-07-08
CVE-2025-49696
8.4
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally

2025-07-08