21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 13401-13450 of 21553 CVEs Page 269 of 432
CVE-2025-68920
Analyzed
8.9
Unknown Multiple Products

C-Kermit (aka ckermit) through 10

2025-12-25
CVE-2025-68916
Analyzed
9.1
Riello UPS NetMan Multiple Products

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

2025-12-25
CVE-2025-6891
7.3
Unknown Multiple Products

A vulnerability classified as critical has been found in code-projects Inventory Management System 1

2025-07-06
CVE-2025-68897
Analyzed
9.9
HP Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode allows Code Injection.This issue affects...

2025-12-30
CVE-2025-6889
7.3
Unknown Multiple Products

A vulnerability was found in code-projects Movie Ticketing System 1

2025-07-06
CVE-2025-68889
7.1
Pinpoll Pinpoll Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pinpoll Pinpoll pinpoll allows Reflected XSS

2026-01-10
CVE-2025-68887
7.1
WordPress Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins...

2026-01-10
CVE-2025-68885
7.1
Page Carbajal Custom Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Page Carbajal Custom Post Status allows Stored XSS

2026-01-01
CVE-2025-6888
7.3
HP Multiple Products

A vulnerability was found in PHPGurukul Teachers Record Management System 2

2025-07-06
CVE-2025-68879
7.1
Councilsoft Content Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Councilsoft Content Grid Slider allows Reflected...

2025-12-30
CVE-2025-68878
7.1
Prasadkirpekar Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasadkirpekar Advanced Custom CSS allows Reflec...

2025-12-30
CVE-2025-68877
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CedCommerce CedCommerce Integ...

2025-12-30
CVE-2025-68876
7.1
INVELITY Invelity SPS Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity SPS connect allows Reflected X...

2025-12-30
CVE-2025-68874
7.1
Shahjada Visitor Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Visitor Stats Widget visitor-stats-widg...

2026-01-10
CVE-2025-68873
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chloédigital PRIMER by chloédigital primer-by-ch...

2026-01-10
CVE-2025-68870
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in reDim GmbH CookieHint WP allo...

2025-12-30
CVE-2025-6887
8.8
Tenda Multiple Products

A vulnerability was found in Tenda AC5 15

2025-07-06
CVE-2025-68865
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global allows SQL Injection.Th...

2026-01-06
CVE-2025-68861
7.1
Unknown Multiple Products

Missing Authorization vulnerability in Plugin Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-30
CVE-2025-68860
Analyzed
9.8
Unknown Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder allows Authentication Abuse.This issue affects...

2025-12-30
CVE-2025-6886
8.8
Tenda Multiple Products

A vulnerability has been found in Tenda AC5 15

2025-07-06
CVE-2025-68850
7.5
Codepeople Sell Multiple Products

Missing Authorization vulnerability in Codepeople Sell Downloads allows Exploiting Incorrectly Configured Access Control Security Levels

2026-01-06
CVE-2025-6885
7.3
HP Multiple Products

A vulnerability, which was classified as critical, was found in PHPGurukul Teachers Record Management System 2

2025-07-06
CVE-2025-6882
8.8
D-Link Multiple Products

A vulnerability classified as critical has been found in D-Link DIR-513 1

2025-07-06
CVE-2025-6881
8.8
D-Link Multiple Products

A vulnerability was found in D-Link DI-8100 16

2025-07-06
CVE-2025-68722
8.8
Mail Multiple Products

Axigen Mail Server before 10

2026-02-06
CVE-2025-68721
Analyzed
9.1
Unknown Axigen Mail Server

An improper access control vulnerability in the Axigen Mail Server WebAdmin interface allows delegated admins with zero permissions to manage and mani...

2026-02-06
CVE-2025-68719
8.8
Unknown Multiple Products

KAYSUS KS-WR3600 routers with firmware 1

2026-01-09
CVE-2025-68717
Analyzed
9.4
KAYSUS Multiple Products

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /c...

2026-01-09
CVE-2025-68716
8.4
Unknown Multiple Products

KAYSUS KS-WR3600 routers with firmware 1

2026-01-09
CVE-2025-6871
7.3
Unknown Multiple Products

A vulnerability classified as critical has been found in SourceCodester Simple Company Website 1

2025-07-06
CVE-2025-68697
Analyzed
7.1
Unknown Multiple Products

n8n is an open source workflow automation platform

2025-12-27
CVE-2025-68686
KEV Analyzed
9.5
Apple FortiOS

A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.

2026-07-28
CVE-2025-68675
Analyzed
7.5
Apache Multiple Products

In Apache Airflow versions before 3

2026-01-18
CVE-2025-68670
Analyzed
9.1
Unknown Multiple Products

xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from imp...

2026-01-28
CVE-2025-68669
Analyzed
9.6
Intel Multiple Products

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerabili...

2025-12-24
CVE-2025-68668
Analyzed
9.9
HP Multiple Products

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node...

2025-12-27
CVE-2025-68665
8.6
LangChain Multiple Products

LangChain is a framework for building LLM-powered applications

2025-12-24
CVE-2025-68664
Analyzed
9.3
Unknown Multiple Products

LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability...

2025-12-24
CVE-2025-68662
7.6
Discourse Multiple Products

Discourse is an open source discussion platform

2026-01-29
CVE-2025-68645
KEV Analyzed
8.8
Unknown Multiple Products

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10

2025-12-23
CVE-2025-68644
Analyzed
7.4
RPS Multiple Products

Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses

2025-12-21
CVE-2025-68637
Analyzed
9.1
Unknown Multiple Products

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration expose...

2026-01-08
CVE-2025-6863
7.3
HP Multiple Products

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2

2025-07-06
CVE-2025-68623
8.8
Microsoft DirectX End

In Microsoft DirectX End-User Runtime Web Installer 9

2026-03-12
CVE-2025-68621
7.4
Arch Multiple Products

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases

2026-02-07
CVE-2025-68620
Analyzed
9.1
Unknown Multiple Products

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained togethe...

2026-01-02
CVE-2025-68616
Analyzed
7.5
Intel Multiple Products

WeasyPrint helps web developers to create PDF documents

2026-01-20
CVE-2025-68615
Analyzed
9.8
Unknown Multiple Products

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd d...

2025-12-23
CVE-2025-68613
KEV Analyzed
9.9
Unknown Multiple Products

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remot...

2025-12-20