18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 13501-13550 of 18466 CVEs Page 271 of 370
CVE-2025-50187
Analyzed
9.8
Chamilo Chamilo LMS

Chamilo LMS is vulnerable to Remote Code Execution via an unvetted SOAP request parameter, allowing unauthenticated attackers to execute arbitrary com...

2026-03-03
CVE-2025-50177
Analyzed
8.1
Microsoft Multiple Products

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network

2025-08-12
CVE-2025-50176
7.8
Access Multiple Products

Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally

2025-08-12
CVE-2025-50175
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-50173
7.8
Microsoft Multiple Products

Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-50171
Analyzed
9.1
Unknown Multiple Products

Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.

2025-08-12
CVE-2025-50170
7.8
Microsoft Multiple Products

Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privile...

2025-08-12
CVE-2025-50168
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-50165
Analyzed
9.8
Microsoft Multiple Products

Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

2025-08-12
CVE-2025-50164
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-50163
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-08-12
CVE-2025-50162
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-50160
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-50155
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-50153
7.8
Microsoft Multiple Products

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-50152
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-50151
8.8
File Multiple Products

File access paths in configuration files uploaded by users with administrator access are not validated

2025-07-22
CVE-2025-5014
Analyzed
8.8
WordPress Multiple Products

The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in...

2025-07-05
CVE-2025-50130
7.8
Unknown Multiple Products

A heap-based buffer overflow vulnerability exists in VS6Sim

2025-07-10
CVE-2025-50129
Analyzed
8.8
Unknown Multiple Products

A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0

2025-08-25
CVE-2025-50128
Analyzed
9.6
Unknown Multiple Products

A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8...

2025-07-25
CVE-2025-50110
Analyzed
8.8
Unknown Multiple Products

An issue was discovered in the method push

2025-09-15
CVE-2025-50109
7.7
Emerson Multiple Products

Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere

2025-07-11
CVE-2025-50106
Analyzed
8.1
Oracle Multiple Products

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D)

2025-07-15
CVE-2025-50105
Analyzed
8.1
Oracle Multiple Products

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration)

2025-07-15
CVE-2025-50069
Analyzed
7.7
Oracle Multiple Products

Vulnerability in the Java VM component of Oracle Database Server

2025-07-15
CVE-2025-50067
Analyzed
9
Oracle Multiple Products

Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5....

2025-07-15
CVE-2025-50063
7.3
Oracle Multiple Products

Vulnerability in Oracle Java SE (component: Install)

2025-07-15
CVE-2025-50062
Analyzed
8.1
Oracle Multiple Products

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core)

2025-07-15
CVE-2025-50060
Analyzed
8.1
Oracle Multiple Products

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server)

2025-07-15
CVE-2025-50059
Analyzed
8.6
Oracle Multiple Products

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

2025-07-15
CVE-2025-50053
Analyzed
7.1
Apple Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin & Your nati...

2026-01-01
CVE-2025-49950
7.3
Unknown Multiple Products

Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation

2025-10-23
CVE-2025-49943
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Femme femme allo...

2025-12-19
CVE-2025-49942
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gardis gardis al...

2025-12-19
CVE-2025-49941
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes GlamChic glamchi...

2025-12-19
CVE-2025-4994
Analyzed
8.7
SafeLine SafeLine SL6/SL6+

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass

2026-06-23
CVE-2025-49935
7.4
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allo...

2025-10-23
CVE-2025-49931
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrocoBlock JetSearch jet-search allows Blind SQL...

2025-10-23
CVE-2025-49926
7.3
Laborator Kalium Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection

2025-10-23
CVE-2025-49925
7.3
VibeThemes WPLMS Multiple Products

Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-23
CVE-2025-49924
7.3
Josh Kohlbach Multiple Products

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation

2025-10-23
CVE-2025-49921
7.3
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CrocoBlock JetReviews jet-rev...

2025-10-23
CVE-2025-49916
8.6
MultiVendorX Multiple Products

Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained b...

2025-10-23
CVE-2025-49915
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-al...

2025-10-23
CVE-2025-49910
8.2
AmentoTech Private Multiple Products

Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-23
CVE-2025-49907
8.2
Unknown Multiple Products

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control...

2025-10-22
CVE-2025-49901
Analyzed
9.8
Unknown Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentic...

2025-10-23
CVE-2025-49897
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 al...

2025-08-15
CVE-2025-49895
Analyzed
8.8
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy

2025-08-17