24458 Total CVEs
24363 AI Analyzed
343 CISA KEV
5636 Critical
All Vendors
Showing 19551-19600 of 24458 CVEs Page 392 of 490
CVE-2025-49377
Analyzed
7.5
Themefic Hydra Booking

Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Access Control Security Levels

2025-10-22
CVE-2025-49376
Analyzed
7.5
DELUCKS DELUCKS SEO

Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-22
CVE-2025-49371
Analyzed
8.1
AncoraThemes Strux

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Strux strux allo...

2025-12-19
CVE-2025-49370
Analyzed
8.1
AncoraThemes Lymcoin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Lymcoin lymcoin...

2025-12-19
CVE-2025-49369
Analyzed
8.1
AncoraThemes Lettuce

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Lettuce lettuce...

2025-12-19
CVE-2025-49368
Analyzed
8.1
AncoraThemes Palladio

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Palladio palladi...

2025-12-19
CVE-2025-49367
Analyzed
8.1
AncoraThemes Monyxi

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Monyxi monyxi al...

2025-12-19
CVE-2025-49366
Analyzed
8.1
AncoraThemes Hanani

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hanani hanani al...

2025-12-19
CVE-2025-49365
Analyzed
8.1
AncoraThemes Jack Well

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Jack Well jack-w...

2025-12-19
CVE-2025-49364
Analyzed
8.1
AncoraThemes Ludos Paradise

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ludos Paradise l...

2025-12-19
CVE-2025-49363
Analyzed
8.1
AncoraThemes Kings & Queens

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Kings & Queens k...

2025-12-19
CVE-2025-49362
Analyzed
8.1
AncoraThemes Gracioza

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gracioza gracioz...

2025-12-19
CVE-2025-49361
Analyzed
8.1
AncoraThemes Mamita

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mamita mamita al...

2025-12-19
CVE-2025-49360
Analyzed
8.1
AncoraThemes Militarology

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Militarology mil...

2025-12-19
CVE-2025-49359
Analyzed
8.1
AncoraThemes ShieldGroup

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ShieldGroup shie...

2025-12-19
CVE-2025-49354
Analyzed
7.1
Mindstien Technologies Recent Posts From Each Category

Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category allows Stored XSS

2026-01-01
CVE-2025-49353
Analyzed
7.1
Marcin Kijak Noindex by Path

Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path allows Stored XSS

2026-01-01
CVE-2025-49346
Analyzed
7.1
peterwsterling Simple Archive Generator

Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Simple Archive Generator allows Stored XSS

2026-01-01
CVE-2025-49345
Analyzed
7.1
mg12 WP-EasyArchives

Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives allows Stored XSS

2026-01-01
CVE-2025-49344
Analyzed
7.1
reneade SensitiveTagCloud

Cross-Site Request Forgery (CSRF) vulnerability in Rene Ade SensitiveTagCloud allows Stored XSS

2026-01-01
CVE-2025-49343
Analyzed
7.1
socialprofilr Social Profilr

Cross-Site Request Forgery (CSRF) vulnerability in Socialprofilr Social Profilr allows Stored XSS

2026-01-01
CVE-2025-49342
Analyzed
7.1
merzedes Custom Style

Cross-Site Request Forgery (CSRF) vulnerability in Wolfgang Hรคfelinger Custom Style allows Stored XSS

2026-01-01
CVE-2025-49302
Analyzed
10
Scott Paterson Easy Stripe

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe allows Remote Code Inclusion. This issue affects...

2025-07-06
CVE-2025-49271
Analyzed
7.5
GravityWP GravityWP - Merge Tags

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge T...

2025-08-14
CVE-2025-49267
Analyzed
8.5
Shabti Kaplan Frontend Admin by DynamiApps

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps allow...

2025-08-14
CVE-2025-49264
Analyzed
7.5
Cloud Infrastructure Services

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cloud Infrastructure Services...

2025-08-14
CVE-2025-49201
Analyzed
8.1
Fortinet FortiPAM

A weak authentication in Fortinet FortiPAM 1

2025-10-14
CVE-2025-49145
Analyzed
8.7
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-49113
KEV Analyzed
9.5
Roundcube Webmail

RoundCube Webmail Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.

2026-02-21
CVE-2025-49090
Analyzed
7.1
Matrix Matrix specification

The Matrix specification before 1

2025-10-02
CVE-2025-49070
Analyzed
7.5
NasaTheme Elessi

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi allows PHP L...

2025-07-06
CVE-2025-49060
Analyzed
10
CMSSuperHeroes Wastia

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue aff...

2025-10-23
CVE-2025-49059
Analyzed
9.3
CleverReachยฎ CleverReachยฎ WP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReachยฎ CleverReachยฎ WP allows SQL Injectio...

2025-08-14
CVE-2025-49036
Analyzed
8.1
octagonwebstudio Premium Addons for KingComposer

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addo...

2025-08-14
CVE-2025-49034
Analyzed
7.6
Aman Funnel Builder by FunnelKit

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows SQL...

2025-07-16
CVE-2025-49033
Analyzed
8.5
Metagauss ProfileGrid

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows Blind SQL Injectio...

2025-08-14
CVE-2025-49031
Analyzed
7.1
Stefan M SMu Manual DoFollow

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefan M

2025-07-16
CVE-2025-49029
9.1
bitto.kazi Custom Login And Signup Widget

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.Kazi Custom Login And Signup Widget allows Code Injection.This issue...

2025-07-06
CVE-2025-49028
Analyzed
7.1
Zoho Mail Zoho ZeptoMail

Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail allows Stored XSS

2026-01-01
CVE-2025-48989
Analyzed
7.5
Apache Apache Tomcat

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack

2025-08-14
CVE-2025-48986
Analyzed
8.8
Revive Revive Adserver

Authorization bypass in Revive Adserver 5

2025-11-20
CVE-2025-48984
Analyzed
8.8
Veeam Backup and Replication

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

2025-10-31
CVE-2025-48983
Analyzed
9.9
Veeam Backup and Replication

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by...

2025-10-31
CVE-2025-48982
Analyzed
7.3
Veeam Agent for Microsoft Windows

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a ma...

2025-10-31
CVE-2025-48981
Analyzed
8.6
CompuGroup Medical CGM MEDICO

An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate dat...

2025-10-08
CVE-2025-48978
Analyzed
7.5
Ubiquiti EdgeMAX EdgeSwitch

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1

2025-08-21
CVE-2025-48963
Analyzed
7.3
Acronis Acronis Cyber Protect Cloud Agent

Local privilege escalation due to improper soft link handling

2025-08-28
CVE-2025-48956
Analyzed
7.5

vLLM is an inference and serving engine for large language models (LLMs)

2025-08-21
CVE-2025-48952
9.4
jokob-sk NetAlertX

NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to by...

2025-07-06
CVE-2025-48928
KEV Analyzed
9.5
TeleMessage service

TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability - Recently added to CISA KEV.

2025-07-05