8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1601-1650 of 8341 CVEs Page 33 of 167
CVE-2025-68577
8.8
Virusdie Virusdie Multiple Products

Missing Authorization vulnerability in Virusdie Virusdie virusdie allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68576
7.5
Virusdie Virusdie Multiple Products

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Virusdie Virusdie virusdie allows Retrieve Embedded Sensit...

2025-12-26
CVE-2025-68575
8.8
Wappointment team Multiple Products

Missing Authorization vulnerability in Wappointment team Wappointment wappointment allows Exploiting Incorrectly Configured Access Control Security Le...

2025-12-25
CVE-2025-68573
8.8
Alessandro Piconi Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery

2025-12-25
CVE-2025-68572
Analyzed
8.8
Spider Multiple Products

Missing Authorization vulnerability in Spider Themes BBP Core bbp-core allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68571
8.8
SALESmanago Multiple Products

Missing Authorization vulnerability in SALESmanago SALESmanago salesmanago allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68570
Analyzed
9.8
Intel Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trad...

2025-12-25
CVE-2025-68569
8.8
Unknown Multiple Products

Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Acces...

2025-12-25
CVE-2025-68568
7.5
Unknown Multiple Products

Missing Authorization vulnerability in integrationclaspo Popup Builder: Exit-Intent pop-up, Spin the Wheel, Newsletter signup, Email Capture & Lea...

2025-12-26
CVE-2025-68567
Analyzed
8.8
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Cross Site Request Forgery

2025-12-25
CVE-2025-68565
9.8
Unknown Multiple Products

Missing Authorization vulnerability in JayBee Twitch Player ttv-easy-embed-player allows Exploiting Incorrectly Configured Access Control Security Lev...

2025-12-25
CVE-2025-68563
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Unloc...

2025-12-25
CVE-2025-68562
Analyzed
9.9
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG:...

2025-12-30
CVE-2025-68561
7.6
Ruben Garcia Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP allows SQL Injection

2025-12-24
CVE-2025-68560
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elem...

2025-12-24
CVE-2025-68550
7.6
VillaTheme WPBulky Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme WPBulky allows Blind SQL Injection

2025-12-24
CVE-2025-68547
7.5
WPweb Follow My Blog Multiple Products

Missing Authorization vulnerability in WPweb Follow My Blog Post allows Exploiting Incorrectly Configured Access Control Security Levels

2026-01-06
CVE-2025-68546
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Thembay Nika allows PHP Local...

2025-12-24
CVE-2025-68544
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Thembay Diza allows PHP Local...

2025-12-24
CVE-2025-68540
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP...

2025-12-25
CVE-2025-68537
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP...

2025-12-25
CVE-2025-68535
9.1
Unknown Multiple Products

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Contr...

2025-12-25
CVE-2025-68530
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Bookory bookory al...

2025-12-25
CVE-2025-68529
Analyzed
8.8
Rhys Wynne WP Email Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery

2025-12-25
CVE-2025-68523
8.1
Spiffy Multiple Products

Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security...

2025-12-25
CVE-2025-68522
Analyzed
8.8
Unknown Multiple Products

Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68521
Analyzed
8.8
Unknown Multiple Products

Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68519
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-wooco...

2025-12-25
CVE-2025-68517
8.1
Essekia Tablesome Multiple Products

Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68516
7.5
Essekia Tablesome Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in Essekia Tablesome tablesome allows Retrieve Embedded Sensitive Data

2025-12-26
CVE-2025-68511
9.1
Unknown Multiple Products

Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Leve...

2025-12-25
CVE-2025-68508
9.1
Unknown Multiple Products

Missing Authorization vulnerability in Brave Brave brave-popup-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This is...

2025-12-25
CVE-2025-68506
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache do...

2025-12-25
CVE-2025-68505
Analyzed
8.8
Unknown Multiple Products

Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security Levels

2025-12-25
CVE-2025-68500
Analyzed
9.1
WordPress Multiple Products

Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Server Side Request...

2025-12-25
CVE-2025-68496
Analyzed
9.8
WordPress Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allo...

2025-12-25
CVE-2025-68494
Analyzed
7.5
Intel Multiple Products

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-ele...

2025-12-26
CVE-2025-68493
Analyzed
8.1
Apache Multiple Products

Missing XML Validation vulnerability in Apache Struts, Apache Struts

2026-01-13
CVE-2025-68479
7.1
Discourse Multiple Products

Discourse is an open source discussion platform

2026-01-29
CVE-2025-68478
7.1
Langflow Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2025-12-20
CVE-2025-68477
7.7
Langflow Multiple Products

Langflow is a tool for building and deploying AI-powered agents and workflows

2025-12-20
CVE-2025-68475
7.5
Unknown Multiple Products

Fedify is a TypeScript library for building federated server apps powered by ActivityPub

2025-12-23
CVE-2025-68472
8.1
Intel Multiple Products

MindsDB is a platform for building artificial intelligence from enterprise data

2026-01-13
CVE-2025-68461
7.2
Webmail Multiple Products

Roundcube Webmail before 1

2025-12-18
CVE-2025-68460
7.2
Webmail Multiple Products

Roundcube Webmail before 1

2025-12-18
CVE-2025-68459
7.2
Ruijie Multiple Products

RG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co

2025-12-18
CVE-2025-68438
Analyzed
7.5
Apache Multiple Products

In Apache Airflow versions before 3

2026-01-18
CVE-2025-68435
9.1
Unknown Multiple Products

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication...

2025-12-18
CVE-2025-68434
Analyzed
8.8
HP Multiple Products

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework

2025-12-18
CVE-2025-68433
7.7
Unknown Multiple Products

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0

2025-12-18