17874 Total CVEs
9409 AI Analyzed
270 CISA KEV
3637 Critical
All Vendors
Showing 14951-15000 of 17874 CVEs Page 300 of 358
CVE-2025-14975
Analyzed
8.1
WordPress Multiple Products

The Custom Login Page Customizer WordPress plugin before 2

2026-01-30
CVE-2025-14968
7.3
Stock Multiple Products

A security flaw has been discovered in code-projects Simple Stock System 1

2025-12-20
CVE-2025-14967
7.3
Unknown Multiple Products

A vulnerability was identified in itsourcecode Student Management System 1

2025-12-20
CVE-2025-14964
Analyzed
9.8
TOTOLINK Multiple Products

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipu...

2025-12-20
CVE-2025-14961
7.3
Unknown Multiple Products

A vulnerability was detected in code-projects Simple Blood Donor Management System 1

2025-12-20
CVE-2025-14960
7.3
Unknown Multiple Products

A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1

2025-12-20
CVE-2025-14959
7.3
Stock Multiple Products

A weakness has been identified in code-projects Simple Stock System 1

2025-12-20
CVE-2025-14952
7.3
Unknown Multiple Products

A vulnerability was detected in Campcodes Supplier Management System 1

2025-12-20
CVE-2025-14951
7.3
Tracking Multiple Products

A security vulnerability has been detected in code-projects Scholars Tracking System 1

2025-12-20
CVE-2025-14950
7.3
Tracking Multiple Products

A weakness has been identified in code-projects Scholars Tracking System 1

2025-12-20
CVE-2025-14940
7.3
Tracking Multiple Products

A vulnerability was determined in code-projects Scholars Tracking System 1

2025-12-20
CVE-2025-14937
7.2
WordPress Multiple Products

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/for...

2026-01-10
CVE-2025-14936
7.8
NSF Multiple Products

NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14935
7.8
NSF Multiple Products

NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14934
7.8
NSF Multiple Products

NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14933
7.8
NSF Multiple Products

NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14932
7.8
NSF Multiple Products

NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14931
Analyzed
10
Unknown Multiple Products

Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote...

2025-12-24
CVE-2025-14930
7.8
Hugging Multiple Products

Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14929
Analyzed
7.8
Intel Multiple Products

Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14928
Analyzed
7.8
Hugging Multiple Products

Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14927
Analyzed
7.8
Intel Multiple Products

Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14926
Analyzed
7.8
HP Multiple Products

Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14925
Analyzed
7.8
Hugging Multiple Products

Hugging Face Accelerate Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14924
Analyzed
7.8
Intel Multiple Products

Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14922
Analyzed
7.8
Intel Multiple Products

Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14921
Analyzed
7.8
Intel Multiple Products

Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14920
Analyzed
7.8
Hugging Multiple Products

Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14914
Analyzed
7.6
IBM Multiple Products

IBM WebSphere Application Server Liberty 17

2026-02-03
CVE-2025-14905
7.2
Unknown Multiple Products

A flaw was found in the 389-ds-base server

2026-02-24
CVE-2025-14896
7.5
Unknown Multiple Products

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array

2025-12-20
CVE-2025-14894
7.5
Livewire Multiple Products

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent

2026-01-18
CVE-2025-14892
Analyzed
9.8
WordPress plugin through

The Prime Listing Manager plugin for WordPress contains a hardcoded secret that allows unauthenticated attackers to gain administrative access to the...

2026-02-13
CVE-2025-14884
7.2
D-Link Multiple Products

A vulnerability was detected in D-Link DIR-605 202WWB03

2025-12-20
CVE-2025-14879
Analyzed
9.8
Tenda Multiple Products

A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request...

2025-12-19
CVE-2025-14878
Analyzed
9.8
Tenda Multiple Products

A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HTT...

2025-12-19
CVE-2025-14877
7.3
Unknown Multiple Products

A vulnerability was identified in Campcodes Supplier Management System 1

2025-12-20
CVE-2025-14868
8.8
WordPress is vulnerable

The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versi...

2026-04-16
CVE-2025-14866
Analyzed
8.8
WordPress Multiple Products

The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-01-24
CVE-2025-14861
Analyzed
8.8
Unknown Multiple Products

Memory safety bugs present in Firefox 146

2025-12-19
CVE-2025-14855
Analyzed
7.2
WordPress Multiple Products

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2

2025-12-21
CVE-2025-14850
8.1
Advantech Multiple Products

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files

2025-12-20
CVE-2025-14849
8.8
Advantech Multiple Products

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code

2025-12-19
CVE-2025-14847
KEV
7.5
Unknown Multiple Products

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client

2025-12-20
CVE-2025-14844
Analyzed
8.2
WordPress Multiple Products

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3

2026-01-17
CVE-2025-14840
7.5
Drupal Multiple Products

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing

2026-01-30
CVE-2025-14835
7.1
WordPress Multiple Products

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and...

2026-01-08
CVE-2025-14833
7.3
Unknown Multiple Products

A security flaw has been discovered in code-projects Online Appointment Booking System 1

2025-12-18
CVE-2025-14832
7.3
Unknown Multiple Products

A vulnerability was identified in itsourcecode Online Cake Ordering System 1

2025-12-18
CVE-2025-14829
Analyzed
9.1
WordPress Multiple Products

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This mak...

2026-01-14