24780 Total CVEs
24685 AI Analyzed
346 CISA KEV
5750 Critical
All Vendors
Showing 19751-19800 of 24780 CVEs Page 396 of 496
CVE-2025-50162
Analyzed
8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-50160
Analyzed
8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-50155
Analyzed
7.8
Microsoft Windows 10 Version 1507

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-50153
Analyzed
7.8
Microsoft Windows 10 Version 1507

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-50152
Analyzed
7.8
Microsoft Windows 10 Version 1507

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-50151
Analyzed
8.8
Apache Apache Jena

File access paths in configuration files uploaded by users with administrator access are not validated

2025-07-22
CVE-2025-5014
Analyzed
8.8
Chimp Group

The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in...

2025-07-05
CVE-2025-50130
Analyzed
7.8
Unknown V-SFT-6

A heap-based buffer overflow vulnerability exists in VS6Sim

2025-07-10
CVE-2025-50129
Analyzed
8.8
SAIL Image Decoding Library SAIL Image Decoding Library

A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0

2025-08-25
CVE-2025-50128
Analyzed
9.6
WWBN AVideo

A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8...

2025-07-25
CVE-2025-50110
Analyzed
8.8
Unknown

An issue was discovered in the method push

2025-09-15
CVE-2025-50109
Analyzed
7.7
Emerson ValveLink SOLO

Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere

2025-07-11
CVE-2025-50106
Analyzed
8.1
Oracle Oracle Java SE

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D)

2025-07-15
CVE-2025-50105
Analyzed
8.1
Oracle Oracle Universal Work Queue

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration)

2025-07-15
CVE-2025-50069
Analyzed
7.7
Oracle Oracle Database Server

Vulnerability in the Java VM component of Oracle Database Server

2025-07-15
CVE-2025-50067
Analyzed
9
Oracle Oracle Application Express

Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5....

2025-07-15
CVE-2025-50063
Analyzed
7.3
Oracle Oracle Java SE

Vulnerability in Oracle Java SE (component: Install)

2025-07-15
CVE-2025-50062
Analyzed
8.1
Oracle PeopleSoft Enterprise HCM Global Payroll Core

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core)

2025-07-15
CVE-2025-50060
Analyzed
8.1
Oracle Oracle BI Publisher

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server)

2025-07-15
CVE-2025-50059
Analyzed
8.6
Oracle Oracle Java SE

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

2025-07-15
CVE-2025-50053
Analyzed
7.1
nebelhorn

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin & Your nati...

2026-01-01
CVE-2025-49950
Analyzed
7.3
billingo Official Integration for Billingo

Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation

2025-10-23
CVE-2025-49943
Analyzed
8.1
AncoraThemes Femme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Femme femme allo...

2025-12-19
CVE-2025-49942
Analyzed
8.1
AncoraThemes Gardis

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gardis gardis al...

2025-12-19
CVE-2025-49941
Analyzed
8.1
AncoraThemes GlamChic

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes GlamChic glamchi...

2025-12-19
CVE-2025-4994
Analyzed
8.7
SafeLine SafeLine SL6/SL6+

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass

2026-06-23
CVE-2025-49935
Analyzed
7.4
xTemos Woodmart

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allo...

2025-10-23
CVE-2025-49931
Analyzed
9.3
Crocoblock JetSearch

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrocoBlock JetSearch jet-search allows Blind SQL...

2025-10-23
CVE-2025-49926
Analyzed
7.3
Laborator Kalium

Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection

2025-10-23
CVE-2025-49925
Analyzed
7.3
VibeThemes WPLMS

Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-23
CVE-2025-49924
Analyzed
7.3
Josh Kohlbach Wholesale Suite

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation

2025-10-23
CVE-2025-49921
Analyzed
7.3
Crocoblock JetReviews

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CrocoBlock JetReviews jet-rev...

2025-10-23
CVE-2025-49916
Analyzed
8.6
MultiVendorX MultiVendorX

Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained b...

2025-10-23
CVE-2025-49915
Analyzed
9.3
Cozy Vision SMS Alert Order Notifications

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-al...

2025-10-23
CVE-2025-49910
Analyzed
8.2
AmentoTech Private WPGuppy

Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-23
CVE-2025-49907
Analyzed
8.2
RealMag777 MDTF

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control...

2025-10-22
CVE-2025-49901
Analyzed
9.8
quantumcloud Simple Link Directory

Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentic...

2025-10-23
CVE-2025-49897
8.5
gopiplus Vertical scroll slideshow gallery v2

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 al...

2025-08-15
CVE-2025-49895
Analyzed
8.8
iThemes ServerBuddy by PluginBuddy.com

Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy

2025-08-17
CVE-2025-49888
Analyzed
7.1
pimwick PW WooCommerce On Sale!

Missing Authorization vulnerability in pimwick PW WooCommerce On Sale! allows Exploiting Incorrectly Configured Access Control Security Levels

2025-07-16
CVE-2025-49887
Analyzed
9.9
WPFactory Product XML Feed Manager for WooCommerce

Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce allows Remote Code Inclu...

2025-08-14
CVE-2025-49876
Analyzed
8.5
Metagauss ProfileGrid

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows SQL Injection

2025-07-16
CVE-2025-49870
Analyzed
7.5
Cozmoslabs Paid Member Subscriptions

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions allows SQL...

2025-07-06
CVE-2025-49869
Analyzed
8.8
Arraytics Eventin

Deserialization of Untrusted Data vulnerability in Arraytics Eventin allows Object Injection

2025-08-14
CVE-2025-49867
9.8
InspiryThemes RealHomes

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege Escalation. This issue affects RealHomes: from n/a through 4....

2025-07-06
CVE-2025-49844
Analyzed
9.9
redis redis

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua...

2025-10-03
CVE-2025-49826
7.5
vercel next.js

Next

2025-07-06
CVE-2025-49809
7.8
mtr mtr

mtr through 0

2025-07-06
CVE-2025-49761
Analyzed
7.8
Microsoft Windows 10 Version 1507

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-49759
Analyzed
8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12