8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1751-1800 of 8341 CVEs Page 36 of 167
CVE-2025-6758
Analyzed
9.8
WordPress Multiple Products

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' functio...

2025-08-19
CVE-2025-6754
Analyzed
8.8
WordPress Multiple Products

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_...

2025-08-04
CVE-2025-67511
Analyzed
9.6
Cybersecurity AI Multiple Products

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below...

2025-12-11
CVE-2025-67510
Analyzed
9.4
HP Multiple Products

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided b...

2025-12-11
CVE-2025-67509
Analyzed
8.2
HP Multiple Products

Neuron is a PHP framework for creating and orchestrating AI Agents

2025-12-11
CVE-2025-67508
8
Unknown Multiple Products

gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools

2025-12-13
CVE-2025-67507
8.1
Filament Multiple Products

Filament is a collection of full-stack components for accelerated Laravel development

2025-12-11
CVE-2025-67506
Analyzed
9.8
Microsoft Multiple Products

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/r...

2025-12-11
CVE-2025-67505
Analyzed
8.4
Okta Multiple Products

Okta Java Management SDK facilitates interactions with the Okta management API

2025-12-11
CVE-2025-67504
Analyzed
9.1
HP Multiple Products

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand()...

2025-12-10
CVE-2025-67495
8
ZITADEL Multiple Products

ZITADEL is an open-source identity infrastructure tool

2025-12-10
CVE-2025-67494
Analyzed
9.3
Unknown Multiple Products

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. T...

2025-12-10
CVE-2025-67493
7.5
Homarr Multiple Products

Homarr is an open-source dashboard

2025-12-18
CVE-2025-67489
Analyzed
9.8
Intel Multiple Products

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution...

2025-12-10
CVE-2025-67488
7.8
SiYuan Multiple Products

SiYuan is self-hosted, open source personal knowledge management software

2025-12-11
CVE-2025-67460
Analyzed
7.8
Microsoft Multiple Products

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6

2025-12-11
CVE-2025-6746
Analyzed
8.8
WordPress Multiple Products

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8

2025-07-08
CVE-2025-67450
Analyzed
7.8
Unknown Multiple Products

Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitr...

2025-12-26
CVE-2025-67442
7.6
Unknown Multiple Products

EVE-NG 6

2025-12-20
CVE-2025-6742
Analyzed
7.5
HP Multiple Products

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...

2025-07-11
CVE-2025-67419
7.5
Unknown Multiple Products

A Denial of Service (DoS) vulnerability in evershop 2

2026-01-06
CVE-2025-67418
Analyzed
9.8
ClipBucket Multiple Products

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative creden...

2025-12-23
CVE-2025-6741
7.7
Devolutions Multiple Products

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure me...

2025-07-23
CVE-2025-6737
Analyzed
7.2
Vendor Multiple Products

Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants

2025-08-25
CVE-2025-67366
7.5
Unknown Multiple Products

@sylphxltd/filesystem-mcp v0

2026-01-08
CVE-2025-67364
7.5
Unknown Multiple Products

fast-filesystem-mcp version 3

2026-01-08
CVE-2025-67325
9.8
Unknown Multiple Products

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote c...

2026-01-09
CVE-2025-67303
7.5
Unknown Multiple Products

An issue in ComfyUI-Manager prior to version 3

2026-01-06
CVE-2025-67289
Analyzed
9.6
HP Multiple Products

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading...

2025-12-23
CVE-2025-67288
Analyzed
10
Intel Multiple Products

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

2025-12-23
CVE-2025-67285
7.3
Unknown Multiple Products

A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1

2025-12-18
CVE-2025-67274
7.5
Unknown Multiple Products

An issue in continuous

2026-01-27
CVE-2025-6724
Analyzed
8.8
Unknown Multiple Products

In Progress Chef Automate, versions earlier than 4

2025-09-29
CVE-2025-67230
7.1
Unknown Multiple Products

Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0

2026-01-25
CVE-2025-67229
9.8
Unknown Multiple Products

An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to...

2026-01-24
CVE-2025-67221
7.5
Unknown Multiple Products

The orjson

2026-01-23
CVE-2025-67172
7.2
RiteCMS Multiple Products

RiteCMS v3

2025-12-18
CVE-2025-67171
7.5
Unknown Multiple Products

Incorrect access control in the /templates/ component of RiteCMS v3

2025-12-18
CVE-2025-67165
9.8
Unknown Multiple Products

An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.

2025-12-18
CVE-2025-67164
Analyzed
9.9
HP Multiple Products

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary co...

2025-12-18
CVE-2025-6715
Analyzed
9.8
HP Multiple Products

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to...

2025-08-13
CVE-2025-67147
Analyzed
9.8
HP Multiple Products

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1)...

2026-01-13
CVE-2025-67146
Analyzed
9.4
HP Multiple Products

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) traine...

2026-01-13
CVE-2025-67133
7.5
Unknown Multiple Products

An issue in Hero Motocorp Vida V1 Pro 2

2026-01-10
CVE-2025-6713
7.7
MongoDB Multiple Products

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the...

2025-07-07
CVE-2025-67109
Analyzed
10
Unknown Multiple Products

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands...

2025-12-24
CVE-2025-67108
Analyzed
10
Intel Multiple Products

eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.

2025-12-24
CVE-2025-67089
8.1
Unknown Multiple Products

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4

2026-01-09
CVE-2025-67079
9.8
Unknown Multiple Products

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via...

2026-01-16
CVE-2025-67077
8.8
Omnispace Agora Multiple Products

File upload vulnerability in Omnispace Agora Project before 25

2026-01-17