21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 13651-13700 of 21553 CVEs Page 274 of 432
CVE-2025-67504
Analyzed
9.1
HP Multiple Products

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand()...

2025-12-10
CVE-2025-67495
8
ZITADEL Multiple Products

ZITADEL is an open-source identity infrastructure tool

2025-12-10
CVE-2025-67494
Analyzed
9.3
Unknown Multiple Products

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. T...

2025-12-10
CVE-2025-67493
7.5
Homarr Multiple Products

Homarr is an open-source dashboard

2025-12-18
CVE-2025-67489
Analyzed
9.8
Intel Multiple Products

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution...

2025-12-10
CVE-2025-67488
7.8
SiYuan Multiple Products

SiYuan is self-hosted, open source personal knowledge management software

2025-12-11
CVE-2025-67460
Analyzed
7.8
Microsoft Multiple Products

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6

2025-12-11
CVE-2025-6746
Analyzed
8.8
WordPress Multiple Products

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8

2025-07-08
CVE-2025-67450
Analyzed
7.8
Unknown Multiple Products

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitr...

2025-12-26
CVE-2025-67447
Analyzed
9.8
Neterbit NW-431F Router

The network diagnosis module in Neterbit NW-431F routers is vulnerable to OS command injection due to improper input sanitization.

2026-06-05
CVE-2025-67446
Analyzed
9.8
Neterbit NW-431F Router

Neterbit NW-431F routers use weak, predictable cookie values for authentication, allowing unauthenticated attackers to gain unauthorized administrativ...

2026-06-05
CVE-2025-67445
7.5
TOTOLINK Multiple Products

TOTOLINK X5000R V9

2026-02-26
CVE-2025-67442
7.6
Unknown Multiple Products

EVE-NG 6

2025-12-20
CVE-2025-67432
7.5
Unknown Multiple Products

A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21

2026-02-14
CVE-2025-6742
Analyzed
7.5
HP Multiple Products

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...

2025-07-11
CVE-2025-67419
7.5
Unknown Multiple Products

A Denial of Service (DoS) vulnerability in evershop 2

2026-01-06
CVE-2025-67418
Analyzed
9.8
ClipBucket Multiple Products

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative creden...

2025-12-23
CVE-2025-6741
7.7
Devolutions Multiple Products

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure me...

2025-07-23
CVE-2025-6737
Analyzed
7.2
Vendor Multiple Products

Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants

2025-08-25
CVE-2025-67366
7.5
Unknown Multiple Products

@sylphxltd/filesystem-mcp v0

2026-01-08
CVE-2025-67364
7.5
Unknown Multiple Products

fast-filesystem-mcp version 3

2026-01-08
CVE-2025-67325
Analyzed
9.8
Unknown Multiple Products

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote c...

2026-01-09
CVE-2025-67303
7.5
Unknown Multiple Products

An issue in ComfyUI-Manager prior to version 3

2026-01-06
CVE-2025-67298
8.1
Unknown Multiple Products

An issue in ClasroomIO before v

2026-03-12
CVE-2025-67289
Analyzed
9.6
HP Multiple Products

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading...

2025-12-23
CVE-2025-67288
Analyzed
10
Intel Multiple Products

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

2025-12-23
CVE-2025-67285
7.3
Unknown Multiple Products

A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1

2025-12-18
CVE-2025-67274
7.5
Unknown Multiple Products

An issue in continuous

2026-01-27
CVE-2025-6724
Analyzed
8.8
Unknown Multiple Products

In Progress Chef Automate, versions earlier than 4

2025-09-29
CVE-2025-67230
7.1
Unknown Multiple Products

Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0

2026-01-25
CVE-2025-67229
Analyzed
9.8
Unknown Multiple Products

An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to...

2026-01-24
CVE-2025-67223
7.5
File Multiple Products

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8

2026-04-29
CVE-2025-67221
7.5
Unknown Multiple Products

The orjson

2026-01-23
CVE-2025-67172
7.2
RiteCMS Multiple Products

RiteCMS v3

2025-12-18
CVE-2025-67171
7.5
Unknown Multiple Products

Incorrect access control in the /templates/ component of RiteCMS v3

2025-12-18
CVE-2025-67165
Analyzed
9.8
Unknown Multiple Products

An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.

2025-12-18
CVE-2025-67164
Analyzed
9.9
HP Multiple Products

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary co...

2025-12-18
CVE-2025-6715
Analyzed
9.8
HP Multiple Products

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to...

2025-08-13
CVE-2025-67147
Analyzed
9.8
HP Multiple Products

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1)...

2026-01-13
CVE-2025-67146
Analyzed
9.4
HP Multiple Products

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) traine...

2026-01-13
CVE-2025-67133
7.5
Unknown Multiple Products

An issue in Hero Motocorp Vida V1 Pro 2

2026-01-10
CVE-2025-6713
Analyzed
7.7
MongoDB Multiple Products

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the...

2025-07-07
CVE-2025-67109
Analyzed
10
Unknown Multiple Products

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands...

2025-12-24
CVE-2025-67108
Analyzed
10
Intel Multiple Products

eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.

2025-12-24
CVE-2025-67089
8.1
Unknown Multiple Products

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4

2026-01-09
CVE-2025-67079
Analyzed
9.8
Unknown Multiple Products

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via...

2026-01-16
CVE-2025-67077
8.8
Omnispace Agora Multiple Products

File upload vulnerability in Omnispace Agora Project before 25

2026-01-17
CVE-2025-67076
7.5
Omnispace Agora Multiple Products

Directory traversal vulnerability in Omnispace Agora Project before 25

2026-01-16
CVE-2025-67073
Analyzed
9.8
Tenda Multiple Products

A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remote attackers to cause denial of...

2025-12-18
CVE-2025-67070
8.2
Intel Multiple Products

A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2

2026-01-10