20685 Total CVEs
11938 AI Analyzed
298 CISA KEV
4466 Critical
All Vendors
Showing 18001-18050 of 20685 CVEs Page 361 of 414
CVE-2025-14037
8.1
WordPress is vulnerable

The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1

2026-03-21
CVE-2025-14031
Analyzed
7.5
IBM Sterling B2B

IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6

2026-03-19
CVE-2025-14026
7.8
DLP Multiple Products

Forcepoint One DLP Client, version 23

2026-01-07
CVE-2025-14025
8.5
Ansible Multiple Products

A flaw was found in Ansible Automation Platform (AAP)

2026-01-09
CVE-2025-14022
Analyzed
7.7
Apple Multiple Products

LINE client for iOS prior to 15

2025-12-15
CVE-2025-14018
7.3
NetBT Consulting Multiple Products

Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc

2025-12-23
CVE-2025-14015
8.8
H3C Multiple Products

A weakness has been identified in H3C Magic B0 up to 100R002

2025-12-05
CVE-2025-14014
Analyzed
9.8
Infor Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd...

2026-02-13
CVE-2025-14009
Analyzed
10
NLTK Project NLTK (Natural Language Toolkit)

The NLTK downloader lacks path validation in its unzip function, allowing attackers to execute arbitrary code via malicious zip packages that overwrit...

2026-02-19
CVE-2025-14002
Analyzed
8.1
WordPress Multiple Products

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and including, 1

2025-12-17
CVE-2025-13999
Analyzed
7.2
WordPress Multiple Products

The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all ver...

2025-12-20
CVE-2025-13986
7.5
Drupal Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass

2026-01-30
CVE-2025-13982
8.1
Drupal Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery

2026-01-30
CVE-2025-13970
8
Unknown Multiple Products

OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation

2025-12-14
CVE-2025-1395
8.2
Codriapp Innovation Multiple Products

Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc

2026-01-30
CVE-2025-13947
7.4
Unknown Multiple Products

A flaw was found in WebKitGTK

2025-12-03
CVE-2025-13943
8.8
Zyxel EX3301

A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5

2026-02-24
CVE-2025-13942
Analyzed
9.8
Zyxel EX3510

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 router allows remote attackers to execute arbitrary OS commands via craf...

2026-02-24
CVE-2025-13941
Analyzed
8.8
Unknown Multiple Products

A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service

2025-12-19
CVE-2025-13928
7.5
GitLab Multiple Products

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17

2026-01-23
CVE-2025-13927
7.5
GitLab Multiple Products

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11

2026-01-23
CVE-2025-13926
Analyzed
9.8
Unknown Multiple Products

An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BA...

2026-04-10
CVE-2025-13917
7
Unknown Multiple Products

WSS Agent, prior to 9

2026-01-29
CVE-2025-13915
Analyzed
9.8
IBM Multiple Products

IBM API Connect 10.0.8.0 through 10.0.8.5, and 10.0.11.0 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized acces...

2025-12-27
CVE-2025-13914
8.7
Microsoft Networks Apstra

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attac...

2026-04-10
CVE-2025-13888
Analyzed
9.1
HP Multiple Products

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated perm...

2025-12-16
CVE-2025-13886
Analyzed
7.5
WordPress Multiple Products

The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2025-12-13
CVE-2025-13878
7.5
Malformed Multiple Products

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly

2026-01-22
CVE-2025-13855
7.6
IBM Storage Protect

IBM Storage Protect Server 8

2026-04-01
CVE-2025-13851
Analyzed
9.8
WordPress site

The Buyent Classified plugin for WordPress allows unauthenticated attackers to register as administrators due to a lack of role validation during REST...

2026-02-20
CVE-2025-1384
7
Least Multiple Products

Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the...

2025-07-14
CVE-2025-13814
7.3
Unknown Multiple Products

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5

2025-12-02
CVE-2025-13808
7.3
Unknown Multiple Products

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1

2025-12-02
CVE-2025-13806
7.3
Unknown Multiple Products

A security vulnerability has been detected in nutzam NutzBoot up to 2

2025-12-02
CVE-2025-13803
7.3
Unknown Multiple Products

A vulnerability was identified in MediaCrush 1

2025-12-02
CVE-2025-13801
Analyzed
7.5
WordPress Multiple Products

The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3

2026-01-08
CVE-2025-13792
Analyzed
7.3
Unknown Multiple Products

A security flaw has been discovered in Qualitor 8

2025-12-01
CVE-2025-13788
Analyzed
7.3
Unknown Multiple Products

A vulnerability has been found in Chanjet CRM up to 20251106

2025-12-01
CVE-2025-13786
Analyzed
7.3
HP Multiple Products

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665

2025-12-01
CVE-2025-13782
Analyzed
7.3
Unknown Multiple Products

A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665

2025-12-01
CVE-2025-13780
Analyzed
9.1
Unknown Multiple Products

pgAdmin versions up to 9.10 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restore...

2025-12-12
CVE-2025-13779
8.3
ABB AWIN AWIN GW100

Missing authentication for critical function vulnerability in ABB AWIN GW100 rev

2026-03-14
CVE-2025-13777
8.3
ABB AWIN AWIN GW100

Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev

2026-03-14
CVE-2025-13774
8.8
Unknown Multiple Products

A vulnerability exists in Progress Flowmon ADS versions prior to 12

2026-01-14
CVE-2025-13773
Analyzed
9.8
HP Multiple Products

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5...

2025-12-24
CVE-2025-13772
7.1
GitLab Multiple Products

GitLab has remediated an issue in GitLab EE affecting all versions from 18

2026-01-10
CVE-2025-13768
Analyzed
7.5
WebITR Multiple Products

WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by m...

2025-11-29
CVE-2025-13764
Analyzed
9.8
WordPress Multiple Products

The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16. This is due to the 'WP_CarDe...

2025-12-12
CVE-2025-13761
8
GitLab Multiple Products

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18

2026-01-10
CVE-2025-13735
7.4
Linux Multiple Products

Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules)

2025-11-27