18466 Total CVEs
9986 AI Analyzed
280 CISA KEV
3815 Critical
All Vendors
Showing 16301-16350 of 18466 CVEs Page 327 of 370
CVE-2025-11940
Analyzed
7
Unknown Multiple Products

A security vulnerability has been detected in LibreWolf up to 143

2025-10-20
CVE-2025-11924
Analyzed
7.5
WordPress Multiple Products

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up t...

2025-12-17
CVE-2025-11923
Analyzed
8.8
WordPress Multiple Products

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation

2025-11-14
CVE-2025-11920
Analyzed
8.8
WordPress Multiple Products

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2025-11-01
CVE-2025-11919
Analyzed
9.6
Wolfram Research Cloud

A local file inclusion vulnerability in the Wolfram Cloud JVM initialization allows attackers to execute arbitrary code by manipulating shared tempora...

2026-06-27
CVE-2025-11900
Analyzed
9.8
Unknown Multiple Products

The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands...

2025-10-17
CVE-2025-11899
Analyzed
8.1
Agentflow Multiple Products

Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fix...

2025-10-17
CVE-2025-11898
Analyzed
7.5
Intel Multiple Products

Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traver...

2025-10-17
CVE-2025-11890
Analyzed
7.5
WordPress Multiple Products

The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1

2025-11-04
CVE-2025-11889
Analyzed
7.2
WordPress Multiple Products

The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the imp...

2025-10-24
CVE-2025-11877
7.5
Unknown Multiple Products

The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2

2026-01-08
CVE-2025-11864
7.3
Unknown Multiple Products

A vulnerability was identified in NucleoidAI Nucleoid up to 0

2025-10-16
CVE-2025-11849
Analyzed
9.3
Unknown Multiple Products

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package...

2025-10-17
CVE-2025-11833
Analyzed
9.8
WordPress Multiple Products

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data d...

2025-11-01
CVE-2025-11797
7.8
Unknown Multiple Products

A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability

2025-11-13
CVE-2025-11795
7.8
Unknown Multiple Products

A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability

2025-11-13
CVE-2025-11789
7.5
Circutor Multiple Products

Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9

2025-12-03
CVE-2025-11788
Analyzed
9.8
Unknown Multiple Products

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited...

2025-12-04
CVE-2025-11787
8.8
Unknown Multiple Products

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9

2025-12-03
CVE-2025-11786
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter i...

2025-12-04
CVE-2025-11785
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user...

2025-12-04
CVE-2025-11784
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user...

2025-12-04
CVE-2025-11783
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copyi...

2025-12-04
CVE-2025-11782
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string...

2025-12-04
CVE-2025-11781
7.8
Unknown Multiple Products

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9

2025-12-03
CVE-2025-11780
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user in...

2025-12-04
CVE-2025-11779
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applie...

2025-12-04
CVE-2025-11778
Analyzed
9.8
Unknown Multiple Products

Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption thro...

2025-12-04
CVE-2025-11774
8.2
Unknown Multiple Products

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafte...

2025-12-19
CVE-2025-11756
8.8
Google Multiple Products

Use after free in Safe Browsing in Google Chrome prior to 141

2025-11-08
CVE-2025-11755
Analyzed
8.8
WordPress Multiple Products

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when impo...

2025-11-01
CVE-2025-11754
7.5
WordPress is vulnerable

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings'...

2026-02-20
CVE-2025-11746
Analyzed
8.8
WordPress Multiple Products

The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9

2025-10-15
CVE-2025-11735
Analyzed
7.5
WordPress Multiple Products

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the `phrase` parameter in all v...

2025-10-28
CVE-2025-11733
Analyzed
7.2
WordPress Multiple Products

The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3

2025-11-04
CVE-2025-11730
7.2
Zyxel ATP series

A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from V...

2026-02-06
CVE-2025-11727
Analyzed
7.2
Google Multiple Products

The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Si...

2025-12-05
CVE-2025-11724
Analyzed
8.8
WordPress Multiple Products

The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all versions up to, and including,...

2025-11-04
CVE-2025-11722
Analyzed
7.5
WordPress Multiple Products

The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,...

2025-10-16
CVE-2025-11721
Analyzed
9.8
Mozilla Multiple Products

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort thi...

2025-10-15
CVE-2025-11720
8.1
Google Multiple Products

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname

2025-10-15
CVE-2025-11719
Analyzed
9.8
Microsoft Multiple Products

Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corrup...

2025-10-15
CVE-2025-11717
Analyzed
9.1
Google Multiple Products

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last...

2025-10-15
CVE-2025-11715
8.8
Firefox Multiple Products

Memory safety bugs present in Firefox ESR 140

2025-10-15
CVE-2025-11714
8.8
Firefox Multiple Products

Memory safety bugs present in Firefox ESR 115

2025-10-15
CVE-2025-11713
Analyzed
8.1
Microsoft Multiple Products

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows

2025-10-15
CVE-2025-11710
Analyzed
9.8
Mozilla Multiple Products

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromi...

2025-10-15
CVE-2025-11709
Analyzed
9.8
Intel Multiple Products

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulne...

2025-10-15
CVE-2025-11708
Analyzed
9.8
Unknown Multiple Products

Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird...

2025-10-15
CVE-2025-11704
Analyzed
7.5
WordPress Multiple Products

The Elegance Menu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2025-11-04