8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1501-1550 of 8341 CVEs Page 31 of 167
CVE-2025-69039
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allo...

2026-01-24
CVE-2025-6901
7.3
Unknown Multiple Products

A vulnerability was found in code-projects Inventory Management System 1

2025-07-06
CVE-2025-68996
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Pos...

2025-12-31
CVE-2025-68990
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-...

2025-12-31
CVE-2025-68989
7.5
Renzo Johnson Contact Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp contact-form-7-mailchimp-exten...

2025-12-31
CVE-2025-68988
7.5
Unknown Multiple Products

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia einvoiceapp-malaysia allows Re...

2025-12-31
CVE-2025-68987
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama - A Word...

2025-12-31
CVE-2025-68985
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP...

2025-12-31
CVE-2025-68984
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Puca puca allows PHP...

2025-12-31
CVE-2025-68983
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart a...

2025-12-31
CVE-2025-68982
8.1
Unknown Multiple Products

Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Cont...

2025-12-31
CVE-2025-68981
8.8
Unknown Multiple Products

Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting Incorrectly Configured Access...

2025-12-31
CVE-2025-68980
8.1
Unknown Multiple Products

Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Incorrectly Configured Access Cont...

2025-12-31
CVE-2025-68979
Analyzed
8.1
Google Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Incor...

2025-12-31
CVE-2025-68976
8.8
Unknown Multiple Products

Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Level...

2025-12-31
CVE-2025-68975
8.1
Authorization Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Ac...

2025-12-31
CVE-2025-68974
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social L...

2025-12-31
CVE-2025-68973
Analyzed
7.8
Linux Multiple Products

In GnuPG through 2

2025-12-29
CVE-2025-68960
8.4
Unknown Multiple Products

Multi-thread race condition vulnerability in the video framework module

2026-01-14
CVE-2025-68958
8
Unknown Multiple Products

Multi-thread race condition vulnerability in the card framework module

2026-01-14
CVE-2025-68957
8.4
Unknown Multiple Products

Multi-thread race condition vulnerability in the card framework module

2026-01-14
CVE-2025-68956
8
Unknown Multiple Products

Multi-thread race condition vulnerability in the card framework module

2026-01-14
CVE-2025-68955
8
Unknown Multiple Products

Multi-thread race condition vulnerability in the card framework module

2026-01-14
CVE-2025-68953
Analyzed
7.5
Frappe Multiple Products

Frappe is a full-stack web application framework

2026-01-06
CVE-2025-6895
9.8
WordPress Multiple Products

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_...

2025-07-28
CVE-2025-68939
Analyzed
8.2
Gitea Multiple Products

Gitea before 1

2025-12-26
CVE-2025-68929
Analyzed
9
Unknown Multiple Products

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tric...

2025-12-30
CVE-2025-68926
9.8
Unknown Multiple Products

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.77, RustFS implements gRPC authentication using a hardco...

2025-12-31
CVE-2025-68924
7.5
UmbracoForms Multiple Products

In Umbraco UmbracoForms through 8

2026-01-18
CVE-2025-68922
7.4
OpenOps Multiple Products

OpenOps before 0

2025-12-26
CVE-2025-68921
7.8
SteelSeries Multiple Products

SteelSeries Nahimic 3 1

2026-01-17
CVE-2025-68920
Analyzed
8.9
Unknown Multiple Products

C-Kermit (aka ckermit) through 10

2025-12-25
CVE-2025-68916
9.1
Riello UPS NetMan Multiple Products

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

2025-12-25
CVE-2025-6891
7.3
Unknown Multiple Products

A vulnerability classified as critical has been found in code-projects Inventory Management System 1

2025-07-06
CVE-2025-68897
Analyzed
9.9
HP Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode allows Code Injection.This issue affects...

2025-12-30
CVE-2025-6889
7.3
Unknown Multiple Products

A vulnerability was found in code-projects Movie Ticketing System 1

2025-07-06
CVE-2025-68889
7.1
Pinpoll Pinpoll Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pinpoll Pinpoll pinpoll allows Reflected XSS

2026-01-10
CVE-2025-68887
7.1
WordPress Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins...

2026-01-10
CVE-2025-68885
7.1
Page Carbajal Custom Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Page Carbajal Custom Post Status allows Stored XSS

2026-01-01
CVE-2025-6888
7.3
HP Multiple Products

A vulnerability was found in PHPGurukul Teachers Record Management System 2

2025-07-06
CVE-2025-68879
7.1
Councilsoft Content Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Councilsoft Content Grid Slider allows Reflected...

2025-12-30
CVE-2025-68878
7.1
Prasadkirpekar Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasadkirpekar Advanced Custom CSS allows Reflec...

2025-12-30
CVE-2025-68877
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CedCommerce CedCommerce Integ...

2025-12-30
CVE-2025-68876
7.1
INVELITY Invelity SPS Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity SPS connect allows Reflected X...

2025-12-30
CVE-2025-68874
7.1
Shahjada Visitor Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Visitor Stats Widget visitor-stats-widg...

2026-01-10
CVE-2025-68873
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chloédigital PRIMER by chloédigital primer-by-ch...

2026-01-10
CVE-2025-68870
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in reDim GmbH CookieHint WP allo...

2025-12-30
CVE-2025-6887
8.8
Tenda Multiple Products

A vulnerability was found in Tenda AC5 15

2025-07-06
CVE-2025-68865
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global allows SQL Injection.Th...

2026-01-06
CVE-2025-68861
7.1
Unknown Multiple Products

Missing Authorization vulnerability in Plugin Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-30