8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1651-1700 of 8341 CVEs Page 34 of 167
CVE-2025-68432
7.7
Unknown Multiple Products

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0

2025-12-18
CVE-2025-68429
7.3
Storybook Multiple Products

Storybook is a frontend workshop for building user interface components and pages in isolation

2025-12-18
CVE-2025-68400
8.8
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-19
CVE-2025-68398
Analyzed
9.1
Unknown Multiple Products

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of it...

2025-12-19
CVE-2025-68385
7.2
Unknown Multiple Products

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script...

2025-12-20
CVE-2025-68279
7.7
Weblate Multiple Products

Weblate is a web based localization tool

2025-12-20
CVE-2025-68272
Analyzed
7.5
Signal Multiple Products

Signal K Server is a server application that runs on a central hub in a boat

2026-01-02
CVE-2025-68271
10
Unknown Multiple Products

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 C...

2026-01-14
CVE-2025-68270
Analyzed
9.9
Intel Multiple Products

The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are ab...

2025-12-17
CVE-2025-68156
7.5
Expr Multiple Products

Expr is an expression language and expression evaluation for Go

2025-12-17
CVE-2025-68155
7.5
React Multiple Products

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite

2025-12-17
CVE-2025-68154
8.1
Unknown Multiple Products

systeminformation is a System and OS information library for node

2025-12-17
CVE-2025-68147
Analyzed
8.1
HP Multiple Products

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework

2025-12-18
CVE-2025-68141
7.4
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-22
CVE-2025-6814
7.5
WordPress Multiple Products

The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_now() function in vers...

2025-07-06
CVE-2025-68137
8.3
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-22
CVE-2025-68136
7.4
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-22
CVE-2025-68134
7.4
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-22
CVE-2025-68133
7.4
EVerest Multiple Products

EVerest is an EV charging software stack

2026-01-21
CVE-2025-68119
7
Downloading Multiple Products

Downloading and building modules with malicious version strings can cause local code execution

2026-01-30
CVE-2025-68116
8.9
Unknown Multiple Products

FileRise is a self-hosted web file manager / WebDAV server

2025-12-17
CVE-2025-68112
Analyzed
9.6
Tenda Multiple Products

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor a...

2025-12-18
CVE-2025-68111
7.2
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-18
CVE-2025-68110
Analyzed
9.9
Unknown Multiple Products

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host...

2025-12-18
CVE-2025-6811
9.8
Mescius Multiple Products

Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot...

2025-07-07
CVE-2025-68109
Analyzed
9.1
HP Multiple Products

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or...

2025-12-18
CVE-2025-6810
9.8
Mescius Multiple Products

Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers...

2025-07-07
CVE-2025-68068
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm stock...

2025-12-17
CVE-2025-68067
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm Core...

2025-12-17
CVE-2025-68066
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad a...

2025-12-17
CVE-2025-68065
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LiquidThemes Hub Core hub-cor...

2025-12-17
CVE-2025-68062
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog a...

2025-12-17
CVE-2025-68061
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall all...

2025-12-17
CVE-2025-68056
8.5
Zoom Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutsl...

2025-12-17
CVE-2025-68055
8.5
Themefic Hydra Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL...

2025-12-17
CVE-2025-68054
Analyzed
8.5
Intel Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Backg...

2025-12-17
CVE-2025-68053
Analyzed
8.5
Intel Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows B...

2025-12-17
CVE-2025-68044
8.6
Rustaurius Five Star Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configure...

2026-01-06
CVE-2025-68038
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Ic...

2025-12-25
CVE-2025-68036
7.5
Emraan Cheema CubeWP Multiple Products

Missing Authorization vulnerability in Emraan Cheema CubeWP allows Accessing Functionality Not Properly Constrained by ACLs

2025-12-30
CVE-2025-68033
7.5
Brecht Custom Related Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts allows Retrieve Embedded Sensitive Data

2026-01-06
CVE-2025-6802
Analyzed
9.8
Unknown Multiple Products

Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex...

2025-07-07
CVE-2025-67962
Analyzed
7.6
AIOSEO Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AIOSEO Plugin Team Broken Link Checker broken-li...

2025-12-17
CVE-2025-67950
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-p...

2025-12-17
CVE-2025-6794
Analyzed
9.8
Unknown Multiple Products

Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb...

2025-07-07
CVE-2025-67937
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon a...

2026-01-09
CVE-2025-67936
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly all...

2026-01-09
CVE-2025-67935
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimi...

2026-01-09
CVE-2025-67934
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring well...

2026-01-09
CVE-2025-67931
7.5
AITpro BulletProof Multiple Products

Insertion of Sensitive Information Into Sent Data vulnerability in AITpro BulletProof Security bulletproof-security allows Retrieve Embedded Sensitive...

2026-01-09