8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1701-1750 of 8341 CVEs Page 35 of 167
CVE-2025-67928
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows...

2026-01-09
CVE-2025-67926
8.8
Shahjahan Jewel Multiple Products

Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security...

2026-01-09
CVE-2025-67925
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zozothemes Corpkit corpkit al...

2026-01-09
CVE-2025-67924
9.8
Unknown Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affec...

2026-01-09
CVE-2025-67921
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.T...

2026-01-09
CVE-2025-67920
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Neo Ocular neoo...

2026-01-09
CVE-2025-67919
Analyzed
8.1
WofficeIO Woffice Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access...

2026-01-09
CVE-2025-67917
8.1
Unknown Multiple Products

Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels

2026-01-09
CVE-2025-67915
9.8
Unknown Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects T...

2026-01-09
CVE-2025-67914
7.5
Path Multiple Products

Path Traversal: '

2026-01-09
CVE-2025-67913
9.8
Unknown Multiple Products

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by...

2026-01-09
CVE-2025-67911
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newslett...

2026-01-09
CVE-2025-67910
9.8
Unknown Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.T...

2026-01-09
CVE-2025-6791
8.8
Unknown Multiple Products

On the monitoring event logs page, it is possible to alter the http request to insert a payload in the DB

2025-08-23
CVE-2025-67909
Analyzed
8.1
WP Swings Membership Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting In...

2025-12-25
CVE-2025-67900
Analyzed
8.1
Agent Multiple Products

NXLog Agent before 6

2025-12-15
CVE-2025-67895
Analyzed
9.8
Apache Multiple Products

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on A...

2025-12-18
CVE-2025-67877
8.8
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-19
CVE-2025-67853
7.5
Unknown Multiple Products

A flaw was found in Moodle

2026-02-04
CVE-2025-67850
7.3
Unknown Multiple Products

A flaw was found in moodle

2026-02-04
CVE-2025-67849
7.3
Unknown Multiple Products

A flaw was found in Moodle

2026-02-04
CVE-2025-67848
8.1
Infor Multiple Products

A flaw was found in Moodle

2026-02-04
CVE-2025-67847
8.8
Unknown Multiple Products

A flaw was found in Moodle

2026-01-23
CVE-2025-67843
8.3
Rendering Multiple Products

A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to ex...

2025-12-19
CVE-2025-6783
Analyzed
7.5
WordPress Multiple Products

The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() function in all versions up to, and...

2025-07-05
CVE-2025-67826
7.7
Ultimate Multiple Products

An issue was discovered in K7 Ultimate Security 17

2025-12-23
CVE-2025-67823
8.2
Multimedia Email Multiple Products

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10

2026-01-17
CVE-2025-6782
Analyzed
7.5
WordPress Multiple Products

The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm() function in all versions up...

2025-07-05
CVE-2025-67818
7.2
OSS Multiple Products

An issue was discovered in Weaviate OSS before 1

2025-12-14
CVE-2025-67787
9.6
Unknown Multiple Products

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a...

2025-12-18
CVE-2025-67781
Analyzed
9.9
Microsoft Multiple Products

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privilege...

2025-12-18
CVE-2025-67779
7.5
React Multiple Products

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a spe...

2025-12-12
CVE-2025-67751
7.2
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2025-12-16
CVE-2025-67750
8.4
Salesforce Multiple Products

Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows

2025-12-13
CVE-2025-67745
7.1
MyHoard Multiple Products

MyHoard is a daemon for creating, managing and restoring MySQL backups

2025-12-20
CVE-2025-67744
Analyzed
9.6
Intel Multiple Products

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerabi...

2025-12-16
CVE-2025-67738
8.5
Unknown Multiple Products

squid/cachemgr

2025-12-12
CVE-2025-67729
Analyzed
8.8
LMDeploy Multiple Products

LMDeploy is a toolkit for compressing, deploying, and serving LLMs

2025-12-27
CVE-2025-67728
Analyzed
9.8
Fireshare facilitates Multiple Products

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public...

2025-12-13
CVE-2025-67726
7.5
Tornado Multiple Products

Tornado is a Python web framework and asynchronous networking library

2025-12-13
CVE-2025-67725
7.5
Tornado Multiple Products

Tornado is a Python web framework and asynchronous networking library

2025-12-13
CVE-2025-67648
7.1
Shopware Multiple Products

Shopware is an open commerce platform

2025-12-12
CVE-2025-67645
8.8
OpenEMR Multiple Products

OpenEMR is a free and open source electronic health records and medical practice management application

2026-01-28
CVE-2025-67644
Analyzed
7.3
LangGraph Multiple Products

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite)

2025-12-12
CVE-2025-67641
8
Jenkins Multiple Products

Jenkins Coverage Plugin 2

2025-12-11
CVE-2025-67635
7.5
Jenkins Multiple Products

Jenkins 2

2025-12-12
CVE-2025-67625
Analyzed
8.8
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forgery

2025-12-25
CVE-2025-67623
9.1
Unknown Multiple Products

Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6...

2025-12-25
CVE-2025-67622
Analyzed
8.8
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Stored XSS

2025-12-25
CVE-2025-67621
7.5
Unknown Multiple Products

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Workflow eight-day-week-print-wo...

2025-12-26