21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 13351-13400 of 21553 CVEs Page 268 of 432
CVE-2025-69180
8.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themepassion Ultra Portfolio ultra-portfolio all...

2026-01-24
CVE-2025-6918
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection....

2025-07-28
CVE-2025-6916
8.8
TOTOLINK Multiple Products

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4

2025-07-06
CVE-2025-69139
Analyzed
8.6
Car Zone Car Zone

Unauthenticated Arbitrary File Deletion in Car Zone <= 3

2026-06-18
CVE-2025-69138
Analyzed
8.8
Genemy Genemy

Subscriber Privilege Escalation in Genemy <= 1

2026-06-18
CVE-2025-69135
Analyzed
8.5
WordPress Events Schedule Plugin

Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2

2026-06-18
CVE-2025-69130
Analyzed
8.8
HP Entrepreneur Booking Theme

Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme <= 3

2026-06-18
CVE-2025-69129
Analyzed
10
WordPress WooCommerce Scraper Plugin

An unauthenticated arbitrary file upload vulnerability exists in the WordPress & WooCommerce Scraper Plugin, allowing attackers to upload malicious fi...

2026-06-18
CVE-2025-69128
Analyzed
8.6
EMV JobCareer

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal

2026-06-18
CVE-2025-69094
Analyzed
8.5
WordPress Unicamp

Subscriber SQL Injection in Unicamp <= 2

2026-07-03
CVE-2025-69087
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes FreeAgent allows PH...

2026-01-06
CVE-2025-69086
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Jwsthemes Issabella allows PH...

2026-01-07
CVE-2025-69085
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank allows Reflected XSS

2026-01-07
CVE-2025-69084
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3 themes Photo Gallery allows Reflected XSS

2026-01-07
CVE-2025-69083
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Frappé allows P...

2026-01-07
CVE-2025-69082
7.1
Frenify Arlo arlo Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS

2026-01-08
CVE-2025-69081
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Group Hope charity-i...

2026-01-08
CVE-2025-69080
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko allows PHP Lo...

2026-01-08
CVE-2025-69039
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allo...

2026-01-24
CVE-2025-6901
7.3
Unknown Multiple Products

A vulnerability was found in code-projects Inventory Management System 1

2025-07-06
CVE-2025-68996
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Pos...

2025-12-31
CVE-2025-68990
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-...

2025-12-31
CVE-2025-68989
7.5
Renzo Johnson Contact Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp contact-form-7-mailchimp-exten...

2025-12-31
CVE-2025-68988
7.5
Unknown Multiple Products

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia einvoiceapp-malaysia allows Re...

2025-12-31
CVE-2025-68987
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama - A Word...

2025-12-31
CVE-2025-68985
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP...

2025-12-31
CVE-2025-68984
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Puca puca allows PHP...

2025-12-31
CVE-2025-68983
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart a...

2025-12-31
CVE-2025-68982
8.1
Unknown Multiple Products

Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Cont...

2025-12-31
CVE-2025-68981
8.8
Unknown Multiple Products

Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting Incorrectly Configured Access...

2025-12-31
CVE-2025-68980
8.1
Unknown Multiple Products

Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Incorrectly Configured Access Cont...

2025-12-31
CVE-2025-68979
Analyzed
8.1
Google Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Incor...

2025-12-31
CVE-2025-68976
8.8
Unknown Multiple Products

Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Level...

2025-12-31
CVE-2025-68975
8.1
Authorization Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Ac...

2025-12-31
CVE-2025-68974
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social L...

2025-12-31
CVE-2025-68973
Analyzed
7.8
Linux Multiple Products

In GnuPG through 2

2025-12-29
CVE-2025-68960
8.4
Unknown Multiple Products

Multi-thread race condition vulnerability in the video framework module

2026-01-14
CVE-2025-68958
8
Unknown Multiple Products

Multi-thread race condition vulnerability in the card framework module

2026-01-14
CVE-2025-68957
8.4
Unknown Multiple Products

Multi-thread race condition vulnerability in the card framework module

2026-01-14
CVE-2025-68956
8
Unknown Multiple Products

Multi-thread race condition vulnerability in the card framework module

2026-01-14
CVE-2025-68955
8
Unknown Multiple Products

Multi-thread race condition vulnerability in the card framework module

2026-01-14
CVE-2025-68953
Analyzed
7.5
Frappe Multiple Products

Frappe is a full-stack web application framework

2026-01-06
CVE-2025-6895
9.8
WordPress Multiple Products

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_...

2025-07-28
CVE-2025-68939
Analyzed
8.2
Gitea Multiple Products

Gitea before 1

2025-12-26
CVE-2025-68930
7.1
Unknown Multiple Products

Versions of the Traccar open-source GPS tracking system up to and including 6

2026-02-24
CVE-2025-68929
Analyzed
9
Unknown Multiple Products

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tric...

2025-12-30
CVE-2025-68926
Analyzed
9.8
Unknown Multiple Products

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.77, RustFS implements gRPC authentication using a hardco...

2025-12-31
CVE-2025-68924
7.5
UmbracoForms Multiple Products

In Umbraco UmbracoForms through 8

2026-01-18
CVE-2025-68922
7.4
OpenOps Multiple Products

OpenOps before 0

2025-12-26
CVE-2025-68921
7.8
SteelSeries Multiple Products

SteelSeries Nahimic 3 1

2026-01-17