23554 Total CVEs
23459 AI Analyzed
328 CISA KEV
5363 Critical
All Vendors
Showing 18851-18900 of 23554 CVEs Page 378 of 472
CVE-2025-48160
Analyzed
8.1
CocoBasic Caliris

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris allows PHP...

2025-08-20
CVE-2025-48159
Analyzed
7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtube Vimeo Video Player and Slid...

2025-08-20
CVE-2025-48158
Analyzed
8.6
Alex Githatu BuddyPress XProfile Custom Image Field

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field al...

2025-08-20
CVE-2025-48157
Analyzed
8.1
Michele Giorgi Formality

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality allo...

2025-08-20
CVE-2025-48154
Analyzed
7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon fo...

2025-08-20
CVE-2025-48153
Analyzed
7.1
Atakan Au Import CDN-Remote Images

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images allows Stored XSS

2025-07-16
CVE-2025-48152
Analyzed
7.1
dimafreund Rentsyst

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dimafreund Rentsyst allows Reflected XSS

2025-08-20
CVE-2025-48151
Analyzed
7.1
creativemindssolutions CM Map Locations

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows R...

2025-08-20
CVE-2025-48149
Analyzed
8.1
dedalx Cook&Meal

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Cook&Meal allows PHP L...

2025-08-20
CVE-2025-48148
Analyzed
10
StoreKeeper StoreKeeper for WooCommerce

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce allows Using Malicious Files. This issue...

2025-08-20
CVE-2025-48142
Analyzed
8.8
Saad Iqbal Bookify

Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify allows Privilege Escalation

2025-08-20
CVE-2025-48109
Analyzed
7.1
Xavier Media XM-Backup

Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup allows Stored XSS

2025-08-28
CVE-2025-48107
Analyzed
7.1
undsgn Uncode

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode allows Reflected XSS

2025-09-26
CVE-2025-48106
Analyzed
10
CMSSuperHeroes Clanora

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious Files.This issue affects Clanor...

2025-10-23
CVE-2025-48101
Analyzed
8.8
webdevstudios Constant Contact for WordPress

Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection

2025-09-09
CVE-2025-48100
Analyzed
9.1
extremeidea bidorbuy Store Integrator

Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator allows Remote Code Inclusion. This is...

2025-08-28
CVE-2025-48091
Analyzed
8.5
Alexander AnyComment

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injec...

2025-10-23
CVE-2025-48090
Analyzed
8.2
CocoBasic Blanka - One Page WordPress Theme

Path Traversal: '

2025-11-06
CVE-2025-48082
Analyzed
7.5
Progress Planner Progress Planner

Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation

2025-10-22
CVE-2025-48065
Analyzed
8.8
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-48055
Analyzed
8.5
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-48008
Analyzed
7.5
F5 BIG-IP

When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker...

2025-10-16
CVE-2025-48006
Analyzed
8.2
Saison Technology Co.,Ltd DataSpider Servista

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4

2025-09-29
CVE-2025-48005
Analyzed
9.8
The Biosig Project libbiosig

A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819...

2025-08-25
CVE-2025-47998
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-47987
Analyzed
7.8
Microsoft Windows 10 Version 1507

Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47986
Analyzed
8.8
Microsoft Windows 10 Version 1507

Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally

2025-07-08
CVE-2025-47985
Analyzed
7.8
Microsoft Windows 10 Version 1507

Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47982
Analyzed
7.8
Microsoft Windows 10 Version 1607

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47981
Analyzed
9.8
Microsoft Windows 10 Version 1507

Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

2025-07-08
CVE-2025-47976
Analyzed
7.8
Microsoft Windows 10 Version 1507

Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47973
Analyzed
7.8
Microsoft Windows 10 Version 1507

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47972
Analyzed
8
Microsoft Windows 10 Version 1507

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorize...

2025-07-10
CVE-2025-47971
Analyzed
7.8
Microsoft Windows 10 Version 1507

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally

2025-07-10
CVE-2025-4796
Analyzed
8.8
Arraytics

The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4

2025-08-08
CVE-2025-47954
Analyzed
8.8
Microsoft Microsoft SQL Server 2022 (CU 20)

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12
CVE-2025-47932
Analyzed
8.8
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-47917
Analyzed
8.9
Mbed mbedtls

Mbed TLS before 3

2025-07-21
CVE-2025-47913
Analyzed
7.5
golang.org/x/crypto golang.org/x/crypto/ssh/agent

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process

2025-11-14
CVE-2025-47909
Analyzed
7.3
github.com/gorilla/csrf github.com/gorilla/csrf

Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks

2025-08-29
CVE-2025-47908
Analyzed
7.5
github.com/rs/cors github.com/rs/cors

Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers...

2025-08-07
CVE-2025-47907
Analyzed
7
Go standard library database/sql

Cancelling a query (e

2025-08-07
CVE-2025-47855
Analyzed
9.8
Fortinet FortiFone

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 thro...

2026-01-14
CVE-2025-4784
Analyzed
9.8
Moderec Tourtella

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This issu...

2025-07-25
CVE-2025-47827
KEV Analyzed
9.5
IGEL IGEL OS

IGEL OS Use of a Key Past its Expiration Date Vulnerability - Active in CISA KEV catalog.

2025-10-14
CVE-2025-47813
KEV Analyzed
9.5
wftpserver Wing FTP Server

Wing FTP Server Information Disclosure Vulnerability - Active in CISA KEV catalog.

2026-03-17
CVE-2025-47812
KEV Analyzed
10
wftpserver Wing FTP Server

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user...

2025-07-11
CVE-2025-4779
Analyzed
9.1
lunary-ai lunary-ai/lunary

lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attacker can inject malicious JavaSc...

2025-07-07
CVE-2025-47773
Analyzed
8.8
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-47761
Analyzed
7.8
Fortinet FortiClientWindows

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] in Fortinet FortiClientWindows 7

2025-11-19