18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 14051-14100 of 18466 CVEs Page 282 of 370
CVE-2025-4521
8.8
WordPress is vulnerable

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capabili...

2026-02-20
CVE-2025-4519
Analyzed
8.8
WordPress Multiple Products

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capabili...

2025-11-08
CVE-2025-45150
Analyzed
9.8
Intel Multiple Products

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted...

2025-08-01
CVE-2025-45146
Analyzed
9.8
Unknown Multiple Products

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerab...

2025-08-11
CVE-2025-45095
7.3
Lavasoft Multiple Products

Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8

2025-10-09
CVE-2025-45081
8.8
Unknown Multiple Products

Misconfigured settings in IITB SSO v1

2025-07-06
CVE-2025-45080
8.8
YONO Multiple Products

YONO SBI: Banking & Lifestyle v1

2025-07-06
CVE-2025-45065
Analyzed
9.8
HP Multiple Products

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

2025-07-08
CVE-2025-45058
7.5
D-Link DI

D-Link DI-8300 v16

2026-04-10
CVE-2025-45057
7.5
D-Link DI

D-Link DI-8300 v16

2026-04-10
CVE-2025-45006
Analyzed
9.1
F5 Multiple Products

Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential...

2025-07-06
CVE-2025-44963
Analyzed
9
RUCKUS Network Director Multiple Products

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

2025-08-05
CVE-2025-44961
Analyzed
9.9
Unknown Multiple Products

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

2025-08-05
CVE-2025-44960
8.5
RUCKUS Multiple Products

RUCKUS SmartZone (SZ) before 6

2025-08-05
CVE-2025-44957
8.5
Ruckus Multiple Products

Ruckus SmartZone (SZ) before 6

2025-08-05
CVE-2025-44955
Analyzed
8.8
RUCKUS Multiple Products

RUCKUS Network Director (RND) before 4

2025-08-05
CVE-2025-44954
Analyzed
9
RUCKUS SmartZone Multiple Products

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

2025-08-05
CVE-2025-44824
Analyzed
8.5
Log Multiple Products

Nagios Log Server before 2024R1

2025-10-07
CVE-2025-44823
Analyzed
9.9
HP Multiple Products

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/syst...

2025-10-07
CVE-2025-44643
8.6
DrayTek Multiple Products

Certain Draytek products are affected by Insecure Configuration

2025-08-05
CVE-2025-44594
Analyzed
9.1
Unknown Multiple Products

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.

2025-09-10
CVE-2025-4439
7.7
GitLab Multiple Products

An issue has been discovered in GitLab CE/EE affecting all versions from 15

2025-07-23
CVE-2025-4425
8.2
Unknown Multiple Products

The vulnerability was identified in the code developed specifically for Lenovo

2025-07-30
CVE-2025-4423
8.2
Unknown Multiple Products

The vulnerability was identified in the code developed specifically for Lenovo

2025-07-30
CVE-2025-4422
8.2
Unknown Multiple Products

The vulnerability was identified in the code developed specifically for Lenovo

2025-07-30
CVE-2025-4421
8.2
Unknown Multiple Products

The vulnerability was identified in the code developed specifically for Lenovo

2025-07-30
CVE-2025-44177
8.2
Protop Multiple Products

A directory traversal vulnerability was discovered in White Star Software Protop version 4

2025-07-10
CVE-2025-4414
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content...

2025-07-06
CVE-2025-44137
Analyzed
8.2
HP Multiple Products

MapTiler Tileserver-php v2

2025-07-29
CVE-2025-44136
Analyzed
9.8
HP Multiple Products

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html enco...

2025-07-29
CVE-2025-4410
7.5
Unknown Multiple Products

A buffer overflow vulnerability exists in the module SetupUtility

2025-08-14
CVE-2025-44034
8
Unknown Multiple Products

SQL injection vulnerability in oa_system oasys v

2025-09-16
CVE-2025-44033
Analyzed
9.8
Unknown Multiple Products

SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in sr...

2025-08-29
CVE-2025-44018
8.3
Unknown Multiple Products

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4

2025-11-25
CVE-2025-44016
8.8
DEX Multiple Products

A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch

2025-12-12
CVE-2025-44005
Analyzed
10
Unknown Multiple Products

An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol au...

2025-12-18
CVE-2025-44004
Analyzed
7.2
Intel Multiple Products

Mattermost Confluence Plugin version <1

2025-08-11
CVE-2025-43995
Analyzed
9.8
Dell Multiple Products

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with...

2025-10-24
CVE-2025-43994
Analyzed
8.6
Dell Multiple Products

Dell Storage Center - Dell Storage Manager, version(s) DSM 20

2025-10-24
CVE-2025-43993
Analyzed
7.8
Dell Multiple Products

Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3

2025-09-25
CVE-2025-43990
7.3
Dell Multiple Products

Dell Command Monitor (DCM), versions prior to 10

2025-11-06
CVE-2025-43988
7.5
KuWFi Multiple Products

KuWFi 5G01-X55 FL2020_V0

2025-08-14
CVE-2025-43986
Analyzed
9.8
Unknown Multiple Products

An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interfa...

2025-08-14
CVE-2025-43984
Analyzed
9.8
Unknown Multiple Products

An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable...

2025-08-15
CVE-2025-43983
Analyzed
9.1
KuWFi Multiple Products

KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and gof...

2025-08-15
CVE-2025-43982
Analyzed
9.8
Shenzhen Tuoshi Multiple Products

Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that c...

2025-08-14
CVE-2025-43979
7.4
Unknown Multiple Products

An issue was discovered on FIRSTNUM JC21A-04 devices through 2

2025-08-05
CVE-2025-43978
7.4
Intel Multiple Products

Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1

2025-08-05
CVE-2025-43960
8.6
Adminer Multiple Products

Adminer 4

2025-08-25