21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 15201-15250 of 21553 CVEs Page 305 of 432
CVE-2025-58789
7.6
Themeisle WP Full Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free allows SQL Injecti...

2025-09-05
CVE-2025-58788
Analyzed
7.6
License Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce allow...

2025-09-05
CVE-2025-5878
7.3
SAP Multiple Products

A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic

2025-07-06
CVE-2025-58778
Analyzed
7.2
Ruijie Multiple Products

Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality

2025-10-16
CVE-2025-58777
7.8
Studio Multiple Products

VT Studio versions 8

2025-10-02
CVE-2025-58776
7.8
Studio Multiple Products

KV Studio versions 12

2025-10-02
CVE-2025-58775
Analyzed
7.8
STUDIO Multiple Products

KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability

2025-10-02
CVE-2025-58768
Analyzed
9.6
Intel Multiple Products

DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operati...

2025-09-09
CVE-2025-58766
Analyzed
9
Unknown Multiple Products

Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows atta...

2025-09-17
CVE-2025-58763
8
Media Multiple Products

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

2025-09-09
CVE-2025-58762
Analyzed
9.1
Unknown Multiple Products

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access...

2025-09-09
CVE-2025-58761
8.6
Media Multiple Products

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

2025-09-09
CVE-2025-58760
8.6
Media Multiple Products

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

2025-09-09
CVE-2025-58757
8.8
MONAI Multiple Products

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging

2025-09-09
CVE-2025-58756
8.8
MONAI Multiple Products

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging

2025-09-09
CVE-2025-58755
8.8
MONAI Multiple Products

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging

2025-09-09
CVE-2025-58754
Analyzed
7.5
HTTP Multiple Products

Axios is a promise based HTTP client for the browser and Node

2025-09-12
CVE-2025-58750
8.2
Unknown Multiple Products

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server

2025-09-09
CVE-2025-58746
Analyzed
9
Unknown Multiple Products

The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdo...

2025-09-08
CVE-2025-58745
Analyzed
9.9
HP Multiple Products

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. Th...

2025-09-08
CVE-2025-58728
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58724
7.8
Microsoft Multiple Products

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58722
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58720
7.8
Microsoft Multiple Products

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information l...

2025-10-14
CVE-2025-58718
8.8
Unknown Multiple Products

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2025-10-14
CVE-2025-58716
8.8
Microsoft Multiple Products

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58715
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58714
7.8
Microsoft Multiple Products

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58710
8.6
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation

2025-12-19
CVE-2025-58692
8.8
Fortinet Multiple Products

An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] in Fortinet FortiVoice 7

2025-11-19
CVE-2025-58690
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect allows Stored XSS

2025-09-22
CVE-2025-58688
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support allows Stored XSS

2025-09-22
CVE-2025-58687
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin allows Stored XSS

2025-09-22
CVE-2025-58686
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows...

2025-09-22
CVE-2025-58677
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews allows Stored XSS

2025-09-22
CVE-2025-58676
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER allows Stored XSS

2025-09-22
CVE-2025-58671
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auction Feed allows Stored XSS

2025-09-22
CVE-2025-58670
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection allows Stored XSS

2025-09-22
CVE-2025-58662
7.2
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object Injection

2025-09-22
CVE-2025-58657
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in EdwardBock Grid allows Stored XSS

2025-09-22
CVE-2025-58642
Analyzed
7.2
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition allows Object Injection

2025-09-04
CVE-2025-58637
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart all...

2025-09-03
CVE-2025-58628
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous allows Blind SQL Injecti...

2025-09-05
CVE-2025-58619
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection

2025-11-08
CVE-2025-58608
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuddyDev MediaPress allows PH...

2025-09-03
CVE-2025-58604
Analyzed
7.6
WPFunnels Mail Mint Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint allows SQL Injection

2025-09-03
CVE-2025-58592
8.1
Cozmoslabs Multiple Products

Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection

2025-11-08
CVE-2025-58482
7.3
Unknown Multiple Products

Improper access control in MPLocalService of MotionPhoto prior to version 4

2025-12-03
CVE-2025-58481
7.3
Unknown Multiple Products

Improper access control in MPRemoteService of MotionPhoto prior to version 4

2025-12-03
CVE-2025-58462
Analyzed
9.8
HP Multiple Products

OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacke...

2025-09-09