18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 15851-15900 of 18466 CVEs Page 318 of 370
CVE-2025-13735
7.4
Linux Multiple Products

Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules)

2025-11-27
CVE-2025-13724
Analyzed
7.5
WordPress Multiple Products

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all vers...

2025-12-03
CVE-2025-13721
Analyzed
7.5
Google Multiple Products

Race in v8 in Google Chrome prior to 143

2025-12-03
CVE-2025-13720
Analyzed
8.8
Google Multiple Products

Bad cast in Loader in Google Chrome prior to 143

2025-12-03
CVE-2025-13716
7.8
Tencent Multiple Products

Tencent MimicMotion create_pipeline Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13715
7.8
Tencent Multiple Products

Tencent FaceDetection-DSFD resnet Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13714
7.8
Tencent Multiple Products

Tencent MedicalNet generate_model Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13713
7.8
Tencent Multiple Products

Tencent Hunyuan3D-1 load_pretrained Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13712
7.8
Tencent Multiple Products

Tencent HunyuanDiT merge Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13711
7.8
Tencent Multiple Products

Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13710
7.8
Tencent Multiple Products

Tencent HunyuanVideo load_vae Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13709
Analyzed
7.8
Tencent Multiple Products

Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13708
Analyzed
7.8
Intel Multiple Products

Tencent NeuralNLP-NeuralClassifier _load_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13707
7.8
Tencent Multiple Products

Tencent HunyuanDiT model_resume Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13706
Analyzed
7.8
Tencent Multiple Products

Tencent PatrickStar merge_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

2025-12-24
CVE-2025-13703
7.8
VIPRE Multiple Products

VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability

2025-12-24
CVE-2025-13692
Analyzed
7.2
WordPress Multiple Products

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and...

2025-11-28
CVE-2025-13691
Analyzed
8.1
IBM DataStage on

IBM DataStage on Cloud Pak for Data 5

2026-02-18
CVE-2025-13689
Analyzed
8.8
IBM DataStage on

IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to un...

2026-02-18
CVE-2025-13680
Analyzed
8.8
WordPress Multiple Products

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101

2025-11-28
CVE-2025-13675
Analyzed
9.8
HP Multiple Products

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.p...

2025-11-28
CVE-2025-13673
Analyzed
7.5
WordPress is vulnerable

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versio...

2026-02-28
CVE-2025-13662
7.8
Endpoint Multiple Products

Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a...

2025-12-10
CVE-2025-13659
8.8
Endpoint Multiple Products

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attac...

2025-12-10
CVE-2025-13654
7.5
Unknown Multiple Products

A stack buffer overflow vulnerability exists in the buffer_get function of duc, a disk management tool, where a condition can evaluate to true due to...

2025-12-06
CVE-2025-13646
Analyzed
7.5
WordPress Multiple Products

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' fun...

2025-12-03
CVE-2025-13645
Analyzed
7.2
WordPress Multiple Products

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_fil...

2025-12-03
CVE-2025-13641
Analyzed
8.8
WordPress Multiple Products

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...

2025-12-19
CVE-2025-13638
Analyzed
8.8
Google Multiple Products

Use after free in Media Stream in Google Chrome prior to 143

2025-12-03
CVE-2025-13633
Analyzed
8.8
Google Multiple Products

Use after free in Digital Credentials in Google Chrome prior to 143

2025-12-03
CVE-2025-13631
Analyzed
8.8
Google Multiple Products

Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143

2025-12-03
CVE-2025-13630
Analyzed
8.8
Google Multiple Products

Type Confusion in V8 in Google Chrome prior to 143

2025-12-03
CVE-2025-13619
Analyzed
9.8
WordPress Multiple Products

The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUse...

2025-12-20
CVE-2025-13618
Analyzed
9.8
WordPress is vulnerable

The Mentoring plugin for WordPress contains a privilege escalation vulnerability that allows unauthenticated attackers to register as administrators.

2026-05-05
CVE-2025-13615
Analyzed
9.8
WordPress Multiple Products

The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the pl...

2025-12-01
CVE-2025-13614
Analyzed
8.1
WordPress Multiple Products

The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to...

2025-12-06
CVE-2025-13613
Analyzed
9.8
WordPress Multiple Products

The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin...

2025-12-11
CVE-2025-13609
8.2
Unknown Multiple Products

A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform M...

2025-11-25
CVE-2025-13607
Analyzed
9.4
Unknown Multiple Products

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

2025-12-11
CVE-2025-13603
8.8
WordPress is vulnerable

The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and including, 2

2026-02-20
CVE-2025-13601
Analyzed
7.7
Unknown Multiple Products

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function

2025-11-27
CVE-2025-13597
Analyzed
9.8
HP Multiple Products

The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all ve...

2025-11-26
CVE-2025-13595
Analyzed
9.8
HP Multiple Products

The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all...

2025-11-26
CVE-2025-13592
Analyzed
7.2
WordPress Multiple Products

The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2

2025-12-30
CVE-2025-13590
Analyzed
9.1
Unknown System REST API

A critical flaw in a system REST API allows an authenticated administrator to upload arbitrary files to user-controlled locations, leading to remote c...

2026-02-20
CVE-2025-13585
7.3
Tracking Multiple Products

A vulnerability was detected in code-projects COVID Tracking System 1

2025-11-25
CVE-2025-13583
7.3
Paper Multiple Products

A weakness has been identified in code-projects Question Paper Generator 1

2025-11-25
CVE-2025-13582
7.3
Jonnys Multiple Products

A security flaw has been discovered in code-projects Jonnys Liquor 1

2025-11-25
CVE-2025-13578
7.3
Library Multiple Products

A vulnerability has been found in code-projects Library System 1

2025-11-25
CVE-2025-13572
7.3
Unknown Multiple Products

A vulnerability was identified in projectworlds Advanced Library Management System 1

2025-11-23