24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 19251-19300 of 24021 CVEs Page 386 of 481
CVE-2025-48552
Analyzed
7.8
Google Android

In saveGlobalProxyLocked of DevicePolicyManagerService

2025-09-05
CVE-2025-4855
Analyzed
9.8
Schiocco Support Board

The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in t...

2025-07-10
CVE-2025-48549
Analyzed
7.8
Google Android

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check

2025-09-04
CVE-2025-48548
Analyzed
7.3
Google Android

In multiple functions of AppOpsControllerImpl

2025-09-04
CVE-2025-48546
Analyzed
7.8
Google Android

In checkPermissions of SafeActivityOptions

2025-09-05
CVE-2025-48544
Analyzed
7.8
Google Android

In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection

2025-09-05
CVE-2025-48543
KEV Analyzed
8.8
Google Android

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free

2025-09-04
CVE-2025-48541
Analyzed
7.8
Google Android

In onCreate of FaceSettings

2025-09-04
CVE-2025-48540
Analyzed
7.8
Google Android

In processTransactInternal of RpcState

2025-09-04
CVE-2025-48539
Analyzed
8
Google Android

In SendPacketToPeer of acl_arbiter

2025-09-04
CVE-2025-48536
Analyzed
7.8
Google Android

In grantAllowlistedPackagePermissions of SettingsSliceProvider

2025-12-09
CVE-2025-48535
Analyzed
7.8
Google Android

In assertSafeToStartCustomActivity of AppRestrictionsFragment

2025-09-04
CVE-2025-48534
Analyzed
8.8
Google Android

In getDefaultCBRPackageName of CellBroadcastHandler

2025-09-05
CVE-2025-48532
Analyzed
7.3
Google Android

In markMediaAsFavorite of MediaProvider

2025-09-04
CVE-2025-48531
Analyzed
7.8
Google Android

In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code

2025-09-05
CVE-2025-48530
Analyzed
8.1
Google Android

In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check

2025-09-05
CVE-2025-48525
Analyzed
7.8
Google Android

In disassociate of DisassociationProcessor

2025-12-09
CVE-2025-48523
Analyzed
7.8
Google Android

In onCreate of SelectAccountActivity

2025-09-05
CVE-2025-48522
Analyzed
7.8
Google Android

In setDisplayName of AssociationRequest

2025-09-05
CVE-2025-48510
Analyzed
7.1
AMD AMD μProf

Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability

2025-11-25
CVE-2025-48503
Analyzed
7.8
AMD Software Installer

A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary...

2026-02-13
CVE-2025-48498
Analyzed
7.5
Bloomberg Comdb2

A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8

2025-07-23
CVE-2025-48431
Analyzed
7.5
Apache Apache Thrift

Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings

2026-04-29
CVE-2025-48429
Analyzed
7.4
Grassroot DICOM Grassroot DICOM

An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3

2025-12-17
CVE-2025-48397
Analyzed
7.1
Eaton Eaton Brightlayer Software Suite (BLSS)

The privileged user could log in without sufficient credentials after enabling an application protocol

2025-11-04
CVE-2025-48396
Analyzed
8.3
Eaton Eaton Brightlayer Software Suite (BLSS)

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS

2025-11-04
CVE-2025-48392
Analyzed
7.5
Apache Apache IoTDB

A vulnerability in Apache IoTDB

2025-09-24
CVE-2025-48384
KEV Analyzed
8
git git

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acce...

2025-07-10
CVE-2025-48359
Analyzed
7.1
thaihavnn07 ATT YouTube Widget

Cross-Site Request Forgery (CSRF) vulnerability in thaihavnn07 ATT YouTube Widget allows Stored XSS

2025-08-28
CVE-2025-48353
Analyzed
7.1
dactum Clickbank WordPress Plugin (Niche Storefront)

Cross-Site Request Forgery (CSRF) vulnerability in dactum Clickbank WordPress Plugin (Niche Storefront) allows Stored XSS

2025-08-28
CVE-2025-48351
Analyzed
7.1
PluginsPoint Kento Splash Screen

Cross-Site Request Forgery (CSRF) vulnerability in PluginsPoint Kento Splash Screen allows Stored XSS

2025-08-28
CVE-2025-48345
Analyzed
7.1
arisoft Contact Form 7 Editor Button

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft Contact Form 7 Editor Button allows Refl...

2025-07-16
CVE-2025-48343
Analyzed
7.1
Aaron Axelsen WPMU Ldap Authentication

Cross-Site Request Forgery (CSRF) vulnerability in Aaron Axelsen WPMU Ldap Authentication allows Stored XSS

2025-08-28
CVE-2025-48338
Analyzed
7.5
Kevon Adonis WP Abstracts

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-...

2025-10-23
CVE-2025-48332
Analyzed
7.5
PublishPress Gutenberg Blocks

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks...

2025-08-14
CVE-2025-48325
Analyzed
7.1
shmish111 WP Admin Theme

Cross-Site Request Forgery (CSRF) vulnerability in shmish111 WP Admin Theme allows Stored XSS

2025-08-28
CVE-2025-48321
Analyzed
7.1
dyiosah Ultimate twitter profile widget

Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget allows Stored XSS

2025-08-28
CVE-2025-48320
Analyzed
7.1
cuckoohello 百度分享按钮

Cross-Site Request Forgery (CSRF) vulnerability in cuckoohello 百度分享按钮 allows Stored XSS

2025-08-28
CVE-2025-48317
Analyzed
7.5
Stefan Keller WooCommerce Payment Gateway for Saferpay

Path Traversal vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay allows Path Traversal

2025-09-05
CVE-2025-48311
Analyzed
7.1
OffClicks Invisible Optin

Cross-Site Request Forgery (CSRF) vulnerability in OffClicks Invisible Optin allows Stored XSS

2025-08-28
CVE-2025-48309
Analyzed
7.1
web-able BetPress

Cross-Site Request Forgery (CSRF) vulnerability in web-able BetPress allows Stored XSS

2025-08-28
CVE-2025-48308
Analyzed
7.1
nonletter Newsletter subscription optin module

Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module allows Stored XSS

2025-08-28
CVE-2025-48307
Analyzed
7.1
kasonzhao SEO For Images

Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao SEO For Images allows Stored XSS

2025-08-28
CVE-2025-48306
Analyzed
7.1
developers savyour Savyour Affiliate Partner

Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner allows Stored XSS

2025-08-28
CVE-2025-48304
Analyzed
7.1
Gary Illyes Google XML News Sitemap plugin

Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin allows Stored XSS

2025-08-28
CVE-2025-48302
Analyzed
7.5
Roxnor FundEngine

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roxnor FundEngine allows PHP...

2025-08-20
CVE-2025-48301
Analyzed
7.6
YayCommerce SMTP for SendGrid – YaySMTP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid – YaySMTP allows S...

2025-07-16
CVE-2025-48300
Analyzed
9.1
Adrian Tobey Groundhogg

Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg allows Upload a Web Shell to a Web Server. This issue affects...

2025-07-16
CVE-2025-48299
Analyzed
7.6
YayCommerce YayExtra

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra allows SQL Injection

2025-07-16
CVE-2025-48298
Analyzed
7.5
Benjamin Denis SEOPress for MainWP

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for M...

2025-08-20