21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 14151-14200 of 21553 CVEs Page 284 of 432
CVE-2025-6388
Analyzed
9.8
WordPress Multiple Products

The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.2.14. This is due to the cust...

2025-10-03
CVE-2025-63823
Analyzed
9.8
Google My Safetipin Android Application

The My Safetipin Android application version 5.2.1 contains hardcoded credentials and predictable OTP values, allowing for unauthorized account access...

2026-08-06
CVE-2025-63822
Analyzed
8.1
Google Android Application

SirenGPS Android Application 2

2026-08-06
CVE-2025-63811
7.5
Unknown Multiple Products

An issue was discovered in dvsekhvalnov jose2go 1

2025-11-14
CVE-2025-63807
7.5
Unknown Multiple Products

An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13)

2025-11-20
CVE-2025-63800
7.5
Unknown Multiple Products

The password change endpoint in Open Source Point of Sale 3

2025-11-19
CVE-2025-6380
Analyzed
9.8
WordPress Multiple Products

The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in ve...

2025-07-25
CVE-2025-63757
7.5
Unknown Multiple Products

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output

2025-12-20
CVE-2025-63748
8.8
QaTraq Multiple Products

QaTraq 6

2025-11-18
CVE-2025-63747
Analyzed
9.8
QaTraq Multiple Products

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web applicati...

2025-11-18
CVE-2025-63729
Analyzed
9
Unknown Multiple Products

An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL...

2025-11-26
CVE-2025-63719
7.3
Unknown Multiple Products

Campcodes Online Hospital Management System 1

2025-11-20
CVE-2025-63711
Analyzed
7.1
SourceCodester Multiple Products

A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1

2025-11-11
CVE-2025-63705
8.8
Unknown Multiple Products

NPM package node-ts-ocr 1

2026-05-09
CVE-2025-63700
7.5
Unknown Multiple Products

An issue was discovered in Clerk-js 5

2025-11-20
CVE-2025-63691
Analyzed
9.6
Unknown Multiple Products

In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/a...

2025-11-08
CVE-2025-63690
Analyzed
9.1
Unknown Multiple Products

In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the system management module, it is...

2025-11-08
CVE-2025-63689
Analyzed
10
HP Multiple Products

Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remot...

2025-11-08
CVE-2025-63685
7.5
Quark Multiple Products

Quark Cloud Drive v3

2025-11-20
CVE-2025-63680
Analyzed
8.6
Microsoft Multiple Products

Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallb...

2025-11-15
CVE-2025-63667
7.5
Unknown Multiple Products

Incorrect access control in SIMICAM v1

2025-11-14
CVE-2025-63665
Analyzed
9.8
Unknown Multiple Products

An issue in GT Edge AI Platform Versions before v2.0.10-dev allows attackers to execute arbitrary code via injecting a crafted JSON payload into the P...

2025-12-20
CVE-2025-63664
Analyzed
7.5
Intel Multiple Products

Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2

2025-12-23
CVE-2025-63663
Analyzed
7.5
Intel Multiple Products

Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2

2025-12-23
CVE-2025-63662
Analyzed
7.5
Insecure Multiple Products

Insecure permissions in the /api/v1/agents API of GT Edge AI Platform before v2

2025-12-23
CVE-2025-6366
Analyzed
8.8
WordPress Multiple Products

The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2

2025-08-26
CVE-2025-63648
7.5
Unknown Multiple Products

A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp

2026-01-22
CVE-2025-63647
7.5
Unknown Multiple Products

A NULL pointer dereference in the parse_meta function (src/httpd_daap

2026-01-22
CVE-2025-63622
Analyzed
9.8
HP Multiple Products

A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/admin/subcategory.ph...

2025-10-30
CVE-2025-63611
Analyzed
8.7
HP Multiple Products

Cross-Site Scripting in phpgurukul Hostel Management System v2

2026-01-09
CVE-2025-63602
7.3
Miner Multiple Products

A vulnerability was discovered in Awesome Miner thru 11

2025-11-19
CVE-2025-63589
7.1
Unknown Multiple Products

A reflected XSS vulnerability exists in CMSimple_XH 1

2025-11-06
CVE-2025-63588
7.1
Unknown Multiple Products

An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbi...

2025-11-06
CVE-2025-63561
7.5
Unknown Multiple Products

Summer Pearl Group Vacation Rental Management Platform prior to 1

2025-10-31
CVE-2025-63551
7.5
Unknown Multiple Products

A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management Sy...

2025-11-08
CVE-2025-63548
7.5
Unknown Multiple Products

An issue in Eprosima Micro-XREC-DDS Agent v

2026-05-02
CVE-2025-63547
7.5
Unknown Multiple Products

An issue in Eprosima Micro-XREC-DDS Agent v

2026-05-02
CVE-2025-63535
Analyzed
9.6
HP Multiple Products

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize...

2025-12-02
CVE-2025-63534
8.5
Unknown Multiple Products

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1

2025-12-02
CVE-2025-63533
8.5
Unknown Multiple Products

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1

2025-12-02
CVE-2025-63532
Analyzed
9.6
HP Multiple Products

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly saniti...

2025-12-02
CVE-2025-63531
Analyzed
10
HP Multiple Products

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly...

2025-12-02
CVE-2025-63528
8.5
Unknown Multiple Products

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1

2025-12-02
CVE-2025-63527
8.5
Unknown Multiple Products

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1

2025-12-02
CVE-2025-63526
8.5
Unknown Multiple Products

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs

2025-12-02
CVE-2025-63525
Analyzed
9.6
HP Multiple Products

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted...

2025-12-02
CVE-2025-63469
7.5
TOTOLINK Multiple Products

Totolink LR350 v9

2025-10-31
CVE-2025-63468
7.5
TOTOLINK Multiple Products

Totolink LR350 v9

2025-10-31
CVE-2025-63465
7.5
TOTOLINK Multiple Products

Totolink LR350 v9

2025-10-31
CVE-2025-63464
7.5
TOTOLINK Multiple Products

Totolink LR350 v9

2025-10-31