18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 16251-16300 of 18466 CVEs Page 326 of 370
CVE-2025-12198
Analyzed
7.8
Unknown Multiple Products

A vulnerability has been found in dnsmasq up to 2

2025-10-27
CVE-2025-12197
Analyzed
7.5
WordPress Multiple Products

The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6

2025-11-06
CVE-2025-12181
Analyzed
8.8
WordPress Multiple Products

The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function...

2025-12-06
CVE-2025-12171
Analyzed
8.8
WordPress Multiple Products

The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ingest_image()...

2025-11-01
CVE-2025-12166
Analyzed
7.5
WordPress Multiple Products

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `orde...

2026-01-16
CVE-2025-12161
Analyzed
8.8
WordPress Multiple Products

The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creati...

2025-11-09
CVE-2025-12160
Analyzed
7.2
WordPress Multiple Products

The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' parameter in all versions up to...

2025-11-22
CVE-2025-12158
Analyzed
9.8
WordPress Multiple Products

The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabiliti...

2025-11-04
CVE-2025-12154
Analyzed
8.8
WordPress Multiple Products

The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function in...

2025-12-06
CVE-2025-12153
Analyzed
8.8
WordPress Multiple Products

The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions u...

2025-12-06
CVE-2025-12139
Analyzed
7.5
Google Multiple Products

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all...

2025-11-06
CVE-2025-12138
Analyzed
8.8
WordPress Multiple Products

The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, an...

2025-11-22
CVE-2025-12135
Analyzed
7.2
WordPress Multiple Products

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1

2025-11-22
CVE-2025-12121
7.3
Lite Multiple Products

Lite XL versions 2

2025-11-20
CVE-2025-12120
7.3
Lite Multiple Products

Lite XL versions 2

2025-11-20
CVE-2025-12115
Analyzed
7.5
WordPress Multiple Products

The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2

2025-10-31
CVE-2025-12107
Analyzed
10
Infor Multiple Products

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template...

2026-02-20
CVE-2025-12106
Analyzed
9.1
Unknown Multiple Products

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

2025-12-02
CVE-2025-12105
7.5
Unknown Multiple Products

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/...

2025-10-23
CVE-2025-12100
Analyzed
7.8
MongoDB BI Connector Multiple Products

Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation

2025-10-23
CVE-2025-12099
Analyzed
7.2
HP Multiple Products

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...

2025-11-09
CVE-2025-12097
Analyzed
7.5
Unknown Multiple Products

There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure

2025-12-05
CVE-2025-12082
7.5
Drupal Multiple Products

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing

2025-10-30
CVE-2025-12062
Analyzed
8.8
Google Maps

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in...

2026-02-17
CVE-2025-12061
Analyzed
8.6
WordPress Multiple Products

The TAX SERVICE Electronic HDM WordPress plugin before 1

2025-11-27
CVE-2025-12059
Analyzed
9.8
Intel Logo j-Platform

Logo j-Platform is vulnerable to the insertion of sensitive information into externally accessible files due to incorrectly configured access control...

2026-02-12
CVE-2025-12057
Analyzed
9.8
WordPress Multiple Products

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally,...

2025-11-21
CVE-2025-12055
Analyzed
7.5
Microsoft Multiple Products

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance...

2025-10-27
CVE-2025-12048
7.5
Pro Multiple Products

An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote co...

2025-11-14
CVE-2025-12046
7.8
DLL Multiple Products

A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to exec...

2025-12-11
CVE-2025-12044
7.5
Vault Multiple Products

Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads

2025-10-23
CVE-2025-12036
8.8
Google Multiple Products

Out of bounds memory access in V8 in Google Chrome prior to 141

2025-11-08
CVE-2025-12029
8
GitLab Multiple Products

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15

2025-12-12
CVE-2025-12028
Analyzed
8.8
WordPress Multiple Products

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4

2025-10-24
CVE-2025-12008
Analyzed
8.8
APPYAP Technology and Multiple Products

Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc

2026-05-15
CVE-2025-11995
Analyzed
7.2
WordPress Multiple Products

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and includin...

2025-11-01
CVE-2025-11994
7.2
WordPress Multiple Products

The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and incl...

2025-11-14
CVE-2025-11993
Analyzed
8.8
HP is vulnerable

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1

2026-05-29
CVE-2025-11985
Analyzed
8.8
WordPress Multiple Products

The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capab...

2025-11-22
CVE-2025-11967
Analyzed
7.2
WordPress Multiple Products

The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_contact_attribute_import...

2025-11-09
CVE-2025-11962
7.3
DivvyDrive Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc

2025-11-14
CVE-2025-11959
8.1
Premierturk Multiple Products

Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk In...

2025-11-13
CVE-2025-11957
8.4
Devolutions Multiple Products

Improper authorization in the temporary access workflow of Devolutions Server 2025

2025-10-22
CVE-2025-11956
Analyzed
8.9
Proliz Software Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd

2025-11-06
CVE-2025-11954
Analyzed
8
Unknown Multiple Products

Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd

2026-05-21
CVE-2025-11953
KEV Analyzed
9.8
Intel Multiple Products

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoi...

2025-11-04
CVE-2025-11949
7.5
EasyFlow Multiple Products

EasyFlow

2025-10-21
CVE-2025-11948
Analyzed
9.8
Unknown Multiple Products

Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upl...

2025-10-20
CVE-2025-11943
Analyzed
7.3
Unknown Multiple Products

A vulnerability has been found in 70mai X200 up to 20251010

2025-10-20
CVE-2025-11942
Analyzed
7.3
Unknown Multiple Products

A flaw has been found in 70mai X200 up to 20251010

2025-10-20