21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 13301-13350 of 21553 CVEs Page 267 of 432
CVE-2025-69691
Analyzed
9.9
HP code

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only a...

2026-05-09
CVE-2025-69690
Analyzed
9.1
HP object containing

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboo...

2026-05-09
CVE-2025-69689
8.8
Unknown Multiple Products

The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog

2026-04-28
CVE-2025-6967
8.7
Sarman Soft Software Multiple Products

Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd

2026-02-11
CVE-2025-69662
Analyzed
8.6
Unknown Multiple Products

SQL injection vulnerability in geopandas before v

2026-01-31
CVE-2025-69634
Analyzed
9
HP Dolibarr ERP & CRM

A Cross-Site Request Forgery (CSRF) vulnerability in Dolibarr ERP & CRM v.22.0.9 allows remote attackers to escalate privileges by manipulating the no...

2026-02-13
CVE-2025-69627
8.4
Microsoft Multiple Products

Nitro PDF Pro for Windows 14

2026-04-15
CVE-2025-69624
7.5
Microsoft Multiple Products

Nitro PDF Pro for Windows 14

2026-04-14
CVE-2025-69620
Analyzed
7.5
Moo Chan Song Moo Chan Song v4

A path traversal in Moo Chan Song v4

2026-02-05
CVE-2025-69619
7.5
Unknown Multiple Products

A path traversal in My Text Editor v1

2026-02-07
CVE-2025-69615
Analyzed
9.1
Unknown Multiple Products

Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. A...

2026-03-11
CVE-2025-69614
Analyzed
9.4
Unknown Multiple Products

Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Af...

2026-03-11
CVE-2025-69581
7.5
Chamillo Multiple Products

An issue was discovered in Chamillo LMS 1

2026-01-18
CVE-2025-6953
8.8
TOTOLINK Multiple Products

A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3

2025-07-06
CVE-2025-69516
8.8
Unknown Multiple Products

A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equa...

2026-01-30
CVE-2025-6948
Analyzed
8.7
GitLab Multiple Products

An issue has been discovered in GitLab CE/EE affecting all versions from 17

2025-07-11
CVE-2025-69437
Analyzed
8.7
Unknown Multiple Products

PublicCMS v5

2026-02-28
CVE-2025-69428
7.5
Unknown Multiple Products

An issue in Pro-Bit before v1

2026-04-29
CVE-2025-69420
7.5
Unknown Multiple Products

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without f...

2026-01-29
CVE-2025-69415
Analyzed
7.1
Media Multiple Products

In Plex Media Server (PMS) through 1

2026-01-03
CVE-2025-69414
Analyzed
8.5
Media Multiple Products

Plex Media Server (PMS) through 1

2026-01-03
CVE-2025-6940
8.8
TOTOLINK Multiple Products

A vulnerability classified as critical was found in TOTOLINK A702R 4

2025-07-06
CVE-2025-6939
8.8
TOTOLINK Multiple Products

A vulnerability classified as critical has been found in TOTOLINK A3002RU 3

2025-07-06
CVE-2025-69347
8.5
Convers Lab Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Acc...

2026-03-27
CVE-2025-69342
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Calafate calafate a...

2026-01-07
CVE-2025-6934
Analyzed
9.8
WordPress Multiple Products

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vuln...

2025-07-06
CVE-2025-69338
Analyzed
9.3
WordPress Riode Core

The Riode Core plugin for WordPress is vulnerable to Blind SQL Injection due to improper neutralization of special elements, affecting versions up to...

2026-03-06
CVE-2025-69288
Analyzed
9.1
Unknown Multiple Products

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule i...

2026-01-01
CVE-2025-69279
7.5
Unknown Multiple Products

In nr modem, there is a possible system crash due to improper input validation

2026-03-10
CVE-2025-69278
7.5
Unknown Multiple Products

In nr modem, there is a possible system crash due to improper input validation

2026-03-10
CVE-2025-69264
8.8
Unknown Multiple Products

pnpm is a package manager

2026-01-08
CVE-2025-69263
7.5
Unknown Multiple Products

pnpm is a package manager

2026-01-08
CVE-2025-69262
7.5
Unknown Multiple Products

pnpm is a package manager

2026-01-08
CVE-2025-69260
7.5
Trend Micro Multiple Products

A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affect...

2026-01-09
CVE-2025-6926
8.8
Unknown Multiple Products

Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication

2025-07-06
CVE-2025-69259
7.5
Trend Micro Multiple Products

A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition...

2026-01-09
CVE-2025-69258
Analyzed
9.8
Unknown Multiple Products

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key...

2026-01-09
CVE-2025-69256
7.5
Unknown Multiple Products

The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications

2025-12-31
CVE-2025-69246
Analyzed
9.8
Raytha Raytha CMS

Raytha CMS lacks brute force protection, allowing unauthenticated attackers to perform unlimited automated login attempts without triggering lockouts...

2026-03-17
CVE-2025-69240
8.8
Raytha Multiple Products

Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain

2026-03-17
CVE-2025-69231
8.7
GAD Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application

2026-02-25
CVE-2025-69223
Analyzed
7.5
HTTP Multiple Products

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

2026-01-06
CVE-2025-69222
Analyzed
9.1
Docker Multiple Products

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing...

2026-01-08
CVE-2025-69220
7.1
LibreChat Multiple Products

LibreChat is a ChatGPT clone with additional features

2026-01-08
CVE-2025-69219
Analyzed
8.8
Apache Airflow

A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB...

2026-03-10
CVE-2025-69217
7.7
STUN Multiple Products

coturn is a free open source implementation of TURN and STUN Server

2025-12-30
CVE-2025-69200
Analyzed
7.5
HP Multiple Products

phpMyFAQ is an open source FAQ web application

2025-12-30
CVE-2025-69195
7.6
Unknown Multiple Products

A flaw was found in GNU Wget2

2026-01-09
CVE-2025-69194
8.8
Unknown Multiple Products

A security issue was discovered in GNU Wget2 when handling Metalink documents

2026-01-09
CVE-2025-6919
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development...

2025-10-13