18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 16051-16100 of 18466 CVEs Page 322 of 370
CVE-2025-13069
8.8
WordPress Multiple Products

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1

2025-11-19
CVE-2025-13068
Analyzed
7.2
WordPress Multiple Products

The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username in all versions up to, and incl...

2025-11-26
CVE-2025-13067
8.8
WordPress is vulnerable

The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1

2026-03-11
CVE-2025-13066
Analyzed
8.8
WordPress Multiple Products

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2

2025-12-06
CVE-2025-13065
Analyzed
8.8
WordPress Multiple Products

The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4

2025-12-07
CVE-2025-13063
7.3
Dee Multiple Products

A flaw has been found in DinukaNavaratna Dee Store 1

2025-11-14
CVE-2025-13062
Analyzed
8.8
WordPress Multiple Products

The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2

2026-01-16
CVE-2025-13060
7.3
Unknown Multiple Products

A security vulnerability has been detected in SourceCodester Survey Application System 1

2025-11-14
CVE-2025-13047
7.5
Bacteriology Multiple Products

Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers...

2025-11-14
CVE-2025-13046
7.5
Bacteriology Multiple Products

Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers...

2025-11-14
CVE-2025-13042
8.8
Google Multiple Products

Inappropriate implementation in V8 in Google Chrome prior to 142

2025-11-13
CVE-2025-13035
Analyzed
8
HP Multiple Products

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3

2025-11-20
CVE-2025-13033
7.5
Unknown Multiple Products

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses

2025-11-15
CVE-2025-13030
7.1
All Multiple Products

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint

2026-05-01
CVE-2025-13027
8.1
Unknown Multiple Products

Memory safety bugs present in Firefox 144 and Thunderbird 144

2025-11-13
CVE-2025-13020
8.8
Unknown Multiple Products

Use-after-free in the WebRTC: Audio/Video component

2025-11-13
CVE-2025-13019
8.1
Unknown Multiple Products

Same-origin policy bypass in the DOM: Workers component

2025-11-13
CVE-2025-13018
8.1
Mitigation Multiple Products

Mitigation bypass in the DOM: Security component

2025-11-13
CVE-2025-13017
8.1
Unknown Multiple Products

Same-origin policy bypass in the DOM: Notifications component

2025-11-13
CVE-2025-13014
8.8
Unknown Multiple Products

Use-after-free in the Audio/Video component

2025-11-13
CVE-2025-13003
7.6
Aksis Computer Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc

2025-12-12
CVE-2025-13002
8.2
Farktor Software Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc

2026-02-13
CVE-2025-13000
Analyzed
7.7
WordPress Multiple Products

The db-access WordPress plugin through 0

2025-12-03
CVE-2025-12995
Analyzed
8.1
Unknown Multiple Products

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determin...

2025-12-05
CVE-2025-12985
8.4
IBM Multiple Products

IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running...

2026-01-21
CVE-2025-12981
Analyzed
9.8
WordPress is vulnerable

The Listee theme for WordPress allows unauthenticated registration as an Administrator due to a broken validation check in the listee-core plugin's re...

2026-02-27
CVE-2025-12980
Analyzed
7.5
WordPress Multiple Products

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access of data due to a m...

2025-12-21
CVE-2025-12977
Analyzed
9.1
Fluent Bit Multiple Products

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to w...

2025-11-25
CVE-2025-12974
8.1
WordPress Multiple Products

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechan...

2025-11-19
CVE-2025-12973
Analyzed
7.2
WordPress Multiple Products

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing...

2025-11-22
CVE-2025-12970
Analyzed
8.8
Docker Multiple Products

The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length

2025-11-25
CVE-2025-12968
Analyzed
8.8
WordPress Multiple Products

The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all vers...

2025-12-13
CVE-2025-12967
Analyzed
8
Unknown Multiple Products

An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role

2025-11-11
CVE-2025-12966
Analyzed
8.8
WordPress Multiple Products

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_di...

2025-12-07
CVE-2025-12963
Analyzed
9.8
WordPress Multiple Products

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via ac...

2025-12-13
CVE-2025-12957
Analyzed
8.8
WordPress Multiple Products

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4

2026-01-16
CVE-2025-12956
8.7
Unknown Multiple Products

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Releas...

2025-12-09
CVE-2025-12955
Analyzed
7.5
WordPress Multiple Products

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2

2025-11-19
CVE-2025-12938
7.3
Admission Multiple Products

A vulnerability was identified in projectworlds Online Admission System 1

2025-11-11
CVE-2025-12934
Analyzed
8.1
WordPress Multiple Products

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabi...

2025-12-24
CVE-2025-12929
7.3
Unknown Multiple Products

A flaw has been found in SourceCodester Survey Application System 1

2025-11-11
CVE-2025-12928
7.3
Search Multiple Products

A vulnerability was detected in code-projects Online Job Search Engine 1

2025-11-11
CVE-2025-12925
7.3
Unknown Multiple Products

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224

2025-11-11
CVE-2025-12904
Analyzed
7.2
WordPress Multiple Products

The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up...

2025-11-15
CVE-2025-12903
7.5
WordPress Multiple Products

The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-b...

2025-11-14
CVE-2025-12886
7.2
WordPress is vulnerable

The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6

2026-03-29
CVE-2025-12882
Analyzed
9.8
WordPress is vulnerable

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated users to register themselves with the 'admi...

2026-02-20
CVE-2025-12879
Analyzed
8.8
WordPress Multiple Products

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1

2025-12-06
CVE-2025-12871
Analyzed
9.8
Unknown Multiple Products

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access toke...

2025-11-13
CVE-2025-12870
Analyzed
9.8
Unknown Multiple Products

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain...

2025-11-13