17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 13451-13500 of 17874 CVEs Page 270 of 358
CVE-2025-4606
Analyzed
9.8
WordPress Multiple Products

The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in...

2025-07-10
CVE-2025-46059
Analyzed
9.8
Unknown Multiple Products

langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows att...

2025-07-29
CVE-2025-46014
8.8
Unknown Multiple Products

Several services in Honor Device Co

2025-07-06
CVE-2025-45968
Analyzed
9.8
Unknown Multiple Products

An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Inse...

2025-08-25
CVE-2025-45931
9.8
D-Link Multiple Products

An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goa...

2025-07-06
CVE-2025-45814
Analyzed
9.8
Unknown Multiple Products

Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to ex...

2025-07-06
CVE-2025-45813
Analyzed
9.8
ENENSYS IPGuard Multiple Products

ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

2025-07-06
CVE-2025-45805
Analyzed
7.6
HP Multiple Products

In phpgurukul Doctor Appointment Management System 1

2025-09-03
CVE-2025-45770
7
Unknown Multiple Products

jwt v5

2025-07-31
CVE-2025-45769
Analyzed
7.3
HP Multiple Products

php-jwt v6

2025-07-31
CVE-2025-45768
7
Unknown Multiple Products

pyjwt v2

2025-07-31
CVE-2025-45767
7
Unknown Multiple Products

jose v6

2025-08-01
CVE-2025-45766
7
Unknown Multiple Products

poco v1

2025-08-07
CVE-2025-45691
7.5
Unknown Multiple Products

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0

2026-03-07
CVE-2025-45620
8.1
Unknown Multiple Products

An issue in Aver PTC310UV2 v

2025-07-30
CVE-2025-45422
Analyzed
8.1
GitHub b-box

Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port fo...

2026-07-12
CVE-2025-45379
Analyzed
8.4
Dell Multiple Products

Dell CloudLink, versions prior to 8

2025-11-06
CVE-2025-45376
Analyzed
7.5
Dell Multiple Products

Dell Repository Manager (DRM), versions 3

2025-09-30
CVE-2025-45346
Analyzed
8.1
Unknown Multiple Products

SQL Injection vulnerability in Bacula-web before v

2025-07-29
CVE-2025-4521
8.8
WordPress is vulnerable

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capabili...

2026-02-20
CVE-2025-4519
Analyzed
8.8
WordPress Multiple Products

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capabili...

2025-11-08
CVE-2025-45150
Analyzed
9.8
Intel Multiple Products

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted...

2025-08-01
CVE-2025-45146
Analyzed
9.8
Unknown Multiple Products

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerab...

2025-08-11
CVE-2025-45095
7.3
Lavasoft Multiple Products

Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8

2025-10-09
CVE-2025-45081
8.8
Unknown Multiple Products

Misconfigured settings in IITB SSO v1

2025-07-06
CVE-2025-45080
8.8
YONO Multiple Products

YONO SBI: Banking & Lifestyle v1

2025-07-06
CVE-2025-45065
Analyzed
9.8
HP Multiple Products

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

2025-07-08
CVE-2025-45058
7.5
D-Link DI

D-Link DI-8300 v16

2026-04-10
CVE-2025-45057
7.5
D-Link DI

D-Link DI-8300 v16

2026-04-10
CVE-2025-45006
Analyzed
9.1
F5 Multiple Products

Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential...

2025-07-06
CVE-2025-44963
Analyzed
9
RUCKUS Network Director Multiple Products

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

2025-08-05
CVE-2025-44961
Analyzed
9.9
Unknown Multiple Products

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

2025-08-05
CVE-2025-44960
8.5
RUCKUS Multiple Products

RUCKUS SmartZone (SZ) before 6

2025-08-05
CVE-2025-44957
8.5
Ruckus Multiple Products

Ruckus SmartZone (SZ) before 6

2025-08-05
CVE-2025-44955
Analyzed
8.8
RUCKUS Multiple Products

RUCKUS Network Director (RND) before 4

2025-08-05
CVE-2025-44954
Analyzed
9
RUCKUS SmartZone Multiple Products

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

2025-08-05
CVE-2025-44824
Analyzed
8.5
Log Multiple Products

Nagios Log Server before 2024R1

2025-10-07
CVE-2025-44823
Analyzed
9.9
HP Multiple Products

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/syst...

2025-10-07
CVE-2025-44643
8.6
DrayTek Multiple Products

Certain Draytek products are affected by Insecure Configuration

2025-08-05
CVE-2025-44594
Analyzed
9.1
Unknown Multiple Products

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.

2025-09-10
CVE-2025-4439
7.7
GitLab Multiple Products

An issue has been discovered in GitLab CE/EE affecting all versions from 15

2025-07-23
CVE-2025-4425
8.2
Unknown Multiple Products

The vulnerability was identified in the code developed specifically for Lenovo

2025-07-30
CVE-2025-4423
8.2
Unknown Multiple Products

The vulnerability was identified in the code developed specifically for Lenovo

2025-07-30
CVE-2025-4422
8.2
Unknown Multiple Products

The vulnerability was identified in the code developed specifically for Lenovo

2025-07-30
CVE-2025-4421
8.2
Unknown Multiple Products

The vulnerability was identified in the code developed specifically for Lenovo

2025-07-30
CVE-2025-44177
8.2
Protop Multiple Products

A directory traversal vulnerability was discovered in White Star Software Protop version 4

2025-07-10
CVE-2025-4414
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content...

2025-07-06
CVE-2025-44137
Analyzed
8.2
HP Multiple Products

MapTiler Tileserver-php v2

2025-07-29
CVE-2025-44136
Analyzed
9.8
HP Multiple Products

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html enco...

2025-07-29
CVE-2025-4410
7.5
Unknown Multiple Products

A buffer overflow vulnerability exists in the module SetupUtility

2025-08-14