8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1401-1450 of 8341 CVEs Page 29 of 167
CVE-2025-71000
7.5
Unknown Multiple Products

An issue in the flow

2026-01-30
CVE-2025-70999
7.5
GPU Multiple Products

A GPU device-ID validation flaw in the flow

2026-01-30
CVE-2025-70986
7.5
Unknown Multiple Products

Incorrect access control in the selectDept function of RuoYi v4

2026-01-24
CVE-2025-70985
9.1
Unknown Multiple Products

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

2026-01-24
CVE-2025-70983
9.9
Unknown Multiple Products

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

2026-01-24
CVE-2025-70982
Analyzed
9.9
Intel Multiple Products

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive u...

2026-01-27
CVE-2025-70974
Analyzed
10
Fastjson before Multiple Products

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, th...

2026-01-09
CVE-2025-70968
Analyzed
9.8
FreeImage Multiple Products

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().

2026-01-15
CVE-2025-70893
Analyzed
8.8
HP Multiple Products

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1

2026-01-16
CVE-2025-70892
Analyzed
9.8
HP Multiple Products

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly v...

2026-01-16
CVE-2025-70841
Analyzed
10
Apache Multi-Tenancy Based eCommerce Platform SaaS

Dokans SaaS platform allows unauthenticated attackers to download the `.env` file, exposing encryption keys, database credentials, and API keys, leadi...

2026-02-04
CVE-2025-7077
8.8
Unknown Multiple Products

A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2

2025-07-06
CVE-2025-70747
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-16
CVE-2025-70746
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-18
CVE-2025-70744
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-16
CVE-2025-70656
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-16
CVE-2025-70651
7.5
Tenda Multiple Products

Tenda AX-1803 v1

2026-01-22
CVE-2025-70650
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-22
CVE-2025-70648
7.5
Tenda Multiple Products

Tenda AX1803 v1

2026-01-23
CVE-2025-70646
7.5
Tenda Multiple Products

Tenda AX1803 v1

2026-01-23
CVE-2025-70645
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-22
CVE-2025-70644
7.5
Tenda Multiple Products

Tenda AX-1806 v1

2026-01-23
CVE-2025-7052
Analyzed
8.8
WordPress Multiple Products

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5

2025-09-30
CVE-2025-7051
8.3
Unknown Multiple Products

On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server

2025-08-21
CVE-2025-7050
Analyzed
7.2
Google Multiple Products

The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in...

2025-08-05
CVE-2025-7049
Analyzed
8.8
WordPress Multiple Products

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67

2025-09-10
CVE-2025-7044
7.7
Unknown Multiple Products

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS

2025-12-03
CVE-2025-7042
7.8
SOLIDWORKS Multiple Products

Use After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025

2025-07-15
CVE-2025-7040
Analyzed
8.2
WordPress Multiple Products

The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_...

2025-09-07
CVE-2025-7038
Analyzed
8.2
WordPress Multiple Products

The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route...

2025-09-30
CVE-2025-7036
Analyzed
7.5
WordPress Multiple Products

The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1

2025-08-07
CVE-2025-70308
7.5
Unknown Multiple Products

An out-of-bounds read in the GSF demuxer filter component of GPAC v2

2026-01-16
CVE-2025-70307
7.5
Unknown Multiple Products

A stack overflow in the dump_ttxt_sample function of GPAC v2

2026-01-16
CVE-2025-70304
7.5
Unknown Multiple Products

A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2

2026-01-16
CVE-2025-70298
8.2
GPAC Multiple Products

GPAC v2

2026-01-16
CVE-2025-7016
8
Unknown Multiple Products

Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd

2026-01-30
CVE-2025-7007
Analyzed
7.5
Microsoft Multiple Products

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the anti...

2025-12-02
CVE-2025-6996
8.4
Endpoint Multiple Products

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated...

2025-07-10
CVE-2025-6995
8.4
Endpoint Multiple Products

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated...

2025-07-10
CVE-2025-6994
Analyzed
9.8
WordPress Multiple Products

The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to t...

2025-08-07
CVE-2025-6993
Analyzed
7.5
WordPress Multiple Products

The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX...

2025-07-16
CVE-2025-6991
7.5
WordPress Multiple Products

The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4

2025-07-28
CVE-2025-69908
Analyzed
7.5
Unknown Multiple Products

An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly acce...

2026-01-24
CVE-2025-69907
Analyzed
7.5
Unknown Multiple Products

An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/Ge...

2026-01-24
CVE-2025-6990
Analyzed
8.8
WordPress Multiple Products

The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4

2025-11-01
CVE-2025-6989
8.1
WordPress Multiple Products

The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in a...

2025-07-28
CVE-2025-6985
7.5
Unknown Multiple Products

The HTMLSectionSplitter class in langchain-text-splitters version 0

2025-10-06
CVE-2025-6984
Analyzed
7.5
Unknown Multiple Products

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML...

2025-09-04
CVE-2025-69828
10
Unknown Multiple Products

File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via...

2026-01-23
CVE-2025-69822
7.4
Unknown Multiple Products

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1

2026-01-24