23828 Total CVEs
23733 AI Analyzed
332 CISA KEV
5447 Critical
All Vendors
Showing 19101-19150 of 23828 CVEs Page 383 of 477
CVE-2025-48306
Analyzed
7.1
developers savyour Savyour Affiliate Partner

Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner allows Stored XSS

2025-08-28
CVE-2025-48304
Analyzed
7.1
Gary Illyes Google XML News Sitemap plugin

Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin allows Stored XSS

2025-08-28
CVE-2025-48302
Analyzed
7.5
Roxnor FundEngine

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roxnor FundEngine allows PHP...

2025-08-20
CVE-2025-48301
Analyzed
7.6
YayCommerce SMTP for SendGrid – YaySMTP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid – YaySMTP allows S...

2025-07-16
CVE-2025-48300
Analyzed
9.1
Adrian Tobey Groundhogg

Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg allows Upload a Web Shell to a Web Server. This issue affects...

2025-07-16
CVE-2025-48299
Analyzed
7.6
YayCommerce YayExtra

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra allows SQL Injection

2025-07-16
CVE-2025-48298
Analyzed
7.5
Benjamin Denis SEOPress for MainWP

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for M...

2025-08-20
CVE-2025-48297
Analyzed
7.1
quantumcloud Simple Link Directory

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflec...

2025-08-20
CVE-2025-48296
Analyzed
7.1
skygroup UpStore

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup UpStore allows Reflected XSS

2025-08-20
CVE-2025-48293
Analyzed
9.8
Dylan Kuhn Geo Mashup

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dylan Kuhn Geo Mashup allows...

2025-08-14
CVE-2025-48291
Analyzed
7.1
Wasiliy Strecker / ContestGallery developer Contest Gallery

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Cont...

2025-07-16
CVE-2025-4828
Analyzed
9.8
Schiocco Support Board

The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete functio...

2025-07-10
CVE-2025-4822
Analyzed
9.8
Bayraktar Solar Energies ScadaWatt Otopilot

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allo...

2025-07-25
CVE-2025-48208
Analyzed
8.8
Apache Apache HertzBeat (incubating)

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat

2025-09-10
CVE-2025-48171
Analyzed
8.1
thembay Cena Store

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Cena Store allows PHP...

2025-08-20
CVE-2025-48170
Analyzed
7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for...

2025-08-20
CVE-2025-48169
Analyzed
9.9
Jordy Meow Code Engine

Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine allows Remote Code Inclusion. This issue affects Cod...

2025-08-20
CVE-2025-48168
Analyzed
7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Au...

2025-08-20
CVE-2025-48165
Analyzed
8.8
DELUCKS DELUCKS SEO

Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO allows Privilege Escalation

2025-08-20
CVE-2025-48164
Analyzed
8.8
Brainstorm Force SureDash

Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash allows Privilege Escalation

2025-08-20
CVE-2025-48163
Analyzed
7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT - HTML5 Radio Player With Ads...

2025-08-20
CVE-2025-48162
Analyzed
7.1
quantumcloud Simple Business Directory Pro

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro allow...

2025-08-20
CVE-2025-48161
Analyzed
7.6
YayCommerce YaySMTP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows SQL Injection

2025-07-16
CVE-2025-48160
Analyzed
8.1
CocoBasic Caliris

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris allows PHP...

2025-08-20
CVE-2025-48159
Analyzed
7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtube Vimeo Video Player and Slid...

2025-08-20
CVE-2025-48158
Analyzed
8.6
Alex Githatu BuddyPress XProfile Custom Image Field

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field al...

2025-08-20
CVE-2025-48157
Analyzed
8.1
Michele Giorgi Formality

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality allo...

2025-08-20
CVE-2025-48154
Analyzed
7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon fo...

2025-08-20
CVE-2025-48153
Analyzed
7.1
Atakan Au Import CDN-Remote Images

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images allows Stored XSS

2025-07-16
CVE-2025-48152
Analyzed
7.1
dimafreund Rentsyst

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dimafreund Rentsyst allows Reflected XSS

2025-08-20
CVE-2025-48151
Analyzed
7.1
creativemindssolutions CM Map Locations

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows R...

2025-08-20
CVE-2025-48149
Analyzed
8.1
dedalx Cook&Meal

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Cook&Meal allows PHP L...

2025-08-20
CVE-2025-48148
Analyzed
10
StoreKeeper StoreKeeper for WooCommerce

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce allows Using Malicious Files. This issue...

2025-08-20
CVE-2025-48142
Analyzed
8.8
Saad Iqbal Bookify

Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify allows Privilege Escalation

2025-08-20
CVE-2025-48109
Analyzed
7.1
Xavier Media XM-Backup

Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup allows Stored XSS

2025-08-28
CVE-2025-48107
Analyzed
7.1
undsgn Uncode

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode allows Reflected XSS

2025-09-26
CVE-2025-48106
Analyzed
10
CMSSuperHeroes Clanora

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious Files.This issue affects Clanor...

2025-10-23
CVE-2025-48101
Analyzed
8.8
webdevstudios Constant Contact for WordPress

Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection

2025-09-09
CVE-2025-48100
Analyzed
9.1
extremeidea bidorbuy Store Integrator

Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator allows Remote Code Inclusion. This is...

2025-08-28
CVE-2025-48091
Analyzed
8.5
Alexander AnyComment

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injec...

2025-10-23
CVE-2025-48090
Analyzed
8.2
CocoBasic Blanka - One Page WordPress Theme

Path Traversal: '

2025-11-06
CVE-2025-48082
Analyzed
7.5
Progress Planner Progress Planner

Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation

2025-10-22
CVE-2025-48065
Analyzed
8.8
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-48055
Analyzed
8.5
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-48008
Analyzed
7.5
F5 BIG-IP

When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker...

2025-10-16
CVE-2025-48006
Analyzed
8.2
Saison Technology Co.,Ltd DataSpider Servista

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4

2025-09-29
CVE-2025-48005
Analyzed
9.8
The Biosig Project libbiosig

A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819...

2025-08-25
CVE-2025-47998
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-47987
Analyzed
7.8
Microsoft Windows 10 Version 1507

Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47986
Analyzed
8.8
Microsoft Windows 10 Version 1507

Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally

2025-07-08