18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 15701-15750 of 18466 CVEs Page 315 of 370
CVE-2025-14423
7.8
GIMP Multiple Products

GIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14422
7.8
GIMP Multiple Products

GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14420
7.8
Unknown Multiple Products

pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14419
7.8
Unknown Multiple Products

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14417
7.8
Unknown Multiple Products

pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14414
7.8
Soda Multiple Products

Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14413
7.8
Soda Multiple Products

Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14412
7.8
Soda Multiple Products

Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14409
7.8
Soda Multiple Products

Soda PDF Desktop PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14406
7.8
Soda Multiple Products

Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

2025-12-24
CVE-2025-14403
7.8
PDFsam Multiple Products

PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14401
7.8
PDFsam Multiple Products

PDFsam Enhanced App Out-Of-Bounds Read Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14397
Analyzed
8.8
WordPress Multiple Products

The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to a missing capability check on...

2025-12-14
CVE-2025-14390
Analyzed
8.8
WordPress Multiple Products

The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5

2025-12-11
CVE-2025-14388
Analyzed
9.8
HP Multiple Products

The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including,...

2025-12-24
CVE-2025-14386
Analyzed
8.8
WordPress Multiple Products

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authenticatio...

2026-01-29
CVE-2025-14383
Analyzed
7.5
WordPress Multiple Products

The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, an...

2025-12-16
CVE-2025-14364
Analyzed
8.8
WordPress Multiple Products

The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missin...

2025-12-19
CVE-2025-14360
Analyzed
9.8
Unknown Multiple Products

Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bloc...

2026-01-09
CVE-2025-14359
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in brandexponents Oshine oshin a...

2026-01-09
CVE-2025-14358
Analyzed
9.8
Unknown Multiple Products

Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issu...

2026-01-09
CVE-2025-14353
7.5
WordPress is vulnerable

The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1

2026-03-08
CVE-2025-14349
Analyzed
8.8
Universal Software Multiple Products

Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc

2026-02-14
CVE-2025-14346
Analyzed
9.8
WHILL Model Multiple Products

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pai...

2026-01-06
CVE-2025-14344
Analyzed
9.8
WordPress Multiple Products

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'pl...

2025-12-13
CVE-2025-14343
7.6
Dokuzsoft Technology Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd

2026-02-27
CVE-2025-14341
8.3
DivvyDrive Multiple Products

Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in...

2026-05-08
CVE-2025-14333
8.1
Firefox Multiple Products

Memory safety bugs present in Firefox ESR 140

2025-12-10
CVE-2025-14329
8.8
Privilege Multiple Products

Privilege escalation in the Netmonitor component

2025-12-10
CVE-2025-14328
8.8
Privilege Multiple Products

Privilege escalation in the Netmonitor component

2025-12-10
CVE-2025-14327
7.5
Spoofing Multiple Products

Spoofing issue in the Downloads Panel component

2025-12-11
CVE-2025-14323
8.8
Privilege Multiple Products

Privilege escalation in the DOM: Notifications component

2025-12-10
CVE-2025-14322
8
Sandbox Multiple Products

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component

2025-12-10
CVE-2025-14320
Analyzed
9.8
Infor Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trad...

2026-05-05
CVE-2025-14316
Analyzed
7.1
WordPress Multiple Products

The AhaChat Messenger Marketing WordPress plugin through 1

2026-01-27
CVE-2025-14314
8.5
Roxnor PopupKit Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roxnor PopupKit popup-builder-block allows Blind...

2025-12-19
CVE-2025-14309
7.5
Unknown Multiple Products

NULL Pointer Dereference vulnerability in ravynsoft ravynos

2025-12-11
CVE-2025-14305
7.8
Unknown Multiple Products

ListCheck

2025-12-17
CVE-2025-14301
Analyzed
9.8
HP Multiple Products

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is du...

2026-01-14
CVE-2025-14287
7.5
Unknown Multiple Products

A command injection vulnerability exists in mlflow/mlflow versions before v3

2026-03-17
CVE-2025-14279
Analyzed
8.1
Intel Multiple Products

MLFlow versions up to and including 3

2026-01-12
CVE-2025-14273
7.2
Mattermost Multiple Products

Mattermost versions 11

2025-12-23
CVE-2025-14265
Analyzed
9.1
Unknown Multiple Products

In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation a...

2025-12-12
CVE-2025-14261
Analyzed
7.1
Intel Multiple Products

The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only 6 bytes long at its core, whi...

2025-12-09
CVE-2025-14258
7.3
Unknown Multiple Products

A vulnerability has been found in itsourcecode Student Management System 1

2025-12-09
CVE-2025-14257
7.3
Unknown Multiple Products

A flaw has been found in itsourcecode Student Management System 1

2025-12-09
CVE-2025-14256
7.3
Unknown Multiple Products

A vulnerability was detected in itsourcecode Student Management System 1

2025-12-09
CVE-2025-14252
7.8
Advantech SUSI driver Multiple Products

An Improper Access Control vulnerability in Advantech SUSI driver (susi

2025-12-16
CVE-2025-14251
7.3
Unknown Multiple Products

A security vulnerability has been detected in code-projects Online Ordering System 1

2025-12-09
CVE-2025-14250
7.3
Unknown Multiple Products

A weakness has been identified in code-projects Online Ordering System 1

2025-12-09