18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 16101-16150 of 18466 CVEs Page 323 of 370
CVE-2025-12868
Analyzed
9.8
Unknown Multiple Products

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the...

2025-11-11
CVE-2025-12867
Analyzed
7.2
HP Multiple Products

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell ba...

2025-11-11
CVE-2025-12866
Analyzed
9.8
Unknown Multiple Products

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-...

2025-11-11
CVE-2025-12865
Analyzed
8.8
Microsoft Multiple Products

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to...

2025-11-11
CVE-2025-12864
Analyzed
8.8
Microsoft Multiple Products

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to...

2025-11-11
CVE-2025-12863
7.5
Unknown Multiple Products

A flaw was found in the xmlSetTreeDoc() function of the libxml2 XML parsing library

2025-11-08
CVE-2025-12851
Analyzed
8.1
WordPress Multiple Products

The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3

2025-12-06
CVE-2025-12850
Analyzed
7.5
WordPress Multiple Products

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3

2025-12-06
CVE-2025-12846
8.8
WordPress Multiple Products

The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2

2025-11-13
CVE-2025-12845
8.8
WordPress is vulnerable

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data th...

2026-02-20
CVE-2025-12844
Analyzed
7.1
HP Multiple Products

The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3

2025-11-14
CVE-2025-12840
7.8
Academy Multiple Products

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-12839
7.8
Academy Multiple Products

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-12835
Analyzed
7.3
WordPress Multiple Products

The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any authenticated users, such as su...

2025-12-14
CVE-2025-12824
Analyzed
8.8
WordPress Multiple Products

The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2025-12-13
CVE-2025-12821
8.8
WordPress is vulnerable

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0

2026-02-20
CVE-2025-12819
7.5
PgBouncer Multiple Products

Untrusted search path in auth_query connection handler in PgBouncer before 1

2025-12-03
CVE-2025-12816
Analyzed
8.6
Unknown Multiple Products

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1

2025-11-26
CVE-2025-12805
8.1
Red Hat OpenShift AI

A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator

2026-03-28
CVE-2025-12790
7.4
Unknown Multiple Products

A flaw was found in Rubygem MQTT

2025-11-06
CVE-2025-12779
Analyzed
8.8
Linux Multiple Products

Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023

2025-11-06
CVE-2025-12775
8.8
WordPress Multiple Products

The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 1

2025-11-19
CVE-2025-12771
Analyzed
7.8
IBM Multiple Products

IBM Concert 1

2025-12-27
CVE-2025-12765
7.5
Unknown Multiple Products

pgAdmin <= 9

2025-11-14
CVE-2025-12764
7.5
Unknown Multiple Products

pgAdmin <= 9

2025-11-14
CVE-2025-12762
Analyzed
9.1
Unknown Multiple Products

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores...

2025-11-14
CVE-2025-12758
Analyzed
7.5
Unknown Multiple Products

Versions of the package validator before 13

2025-11-28
CVE-2025-12744
Analyzed
8.8
Unknown Multiple Products

A flaw was found in the ABRT daemon’s handling of user-supplied mount information

2025-12-03
CVE-2025-12733
Analyzed
8.8
WordPress Multiple Products

The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...

2025-11-14
CVE-2025-12726
Analyzed
7.5
Microsoft Multiple Products

Inappropriate implementation in Views in Google Chrome on Windows prior to 142

2025-11-11
CVE-2025-1272
7.7
Linux Kernel lockdown

The Linux Kernel lockdown mode for kernel versions starting on 6

2026-02-19
CVE-2025-12716
8.7
GitLab Multiple Products

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18

2025-12-12
CVE-2025-12707
7.5
WordPress is vulnerable

The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3

2026-02-20
CVE-2025-12686
Analyzed
9.8
Synology BeeStation OS

A classic buffer overflow in Synology BeeStation OS AdminCenter allows remote attackers to execute arbitrary code via unspecified vectors.

2026-05-28
CVE-2025-12684
Analyzed
7.1
WordPress Multiple Products

The URL Shortify WordPress plugin before 1

2025-12-16
CVE-2025-12682
Analyzed
9.8
WordPress Multiple Products

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in t...

2025-11-04
CVE-2025-12664
7.5
GitLab has remediated

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13

2026-04-10
CVE-2025-12646
Analyzed
7.5
WordPress Multiple Products

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions up to, and including, 1

2025-11-20
CVE-2025-12638
Analyzed
8
Intel Multiple Products

Keras version 3

2025-11-29
CVE-2025-12637
Analyzed
8.8
WordPress Multiple Products

The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation feature in the process_theme fu...

2025-11-13
CVE-2025-12633
7.5
WordPress Multiple Products

The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...

2025-11-14
CVE-2025-12629
Analyzed
7.1
WordPress Multiple Products

The Broken Link Manager WordPress plugin through 0

2025-11-25
CVE-2025-12622
Analyzed
8.8
Tenda Multiple Products

A vulnerability was determined in Tenda AC10 16

2025-11-04
CVE-2025-12619
Analyzed
8.8
Tenda Multiple Products

A vulnerability was found in Tenda A15 15

2025-11-04
CVE-2025-12618
Analyzed
8.8
Tenda Multiple Products

A vulnerability has been found in Tenda AC8 16

2025-11-04
CVE-2025-12617
Analyzed
7.3
Billing Multiple Products

A flaw has been found in itsourcecode Billing System 1

2025-11-04
CVE-2025-12613
8.6
Unknown Multiple Products

Versions of the package cloudinary before 2

2025-11-11
CVE-2025-12611
Analyzed
8.8
Tenda Multiple Products

A vulnerability was identified in Tenda AC21 16

2025-11-04
CVE-2025-12608
Analyzed
7.3
Unknown Multiple Products

A security flaw has been discovered in itsourcecode Online Loan Management System 1

2025-11-04
CVE-2025-12607
Analyzed
7.3
Unknown Multiple Products

A vulnerability was identified in itsourcecode Online Loan Management System 1

2025-11-04