24780 Total CVEs
24685 AI Analyzed
346 CISA KEV
5750 Critical
All Vendors
Showing 19851-19900 of 24780 CVEs Page 398 of 496
CVE-2025-49520
8.8

A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command

2025-07-06
CVE-2025-49506
Analyzed
7.5
Apache Apache Portable Runtime Utility

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentia...

2026-08-27
CVE-2025-49495
Analyzed
8.4
Processor

An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580

2026-01-06
CVE-2025-49492
7.4
ASR Falcon Linux、Kestrel、Lapwing Linux

Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun

2025-07-06
CVE-2025-49480
7.4
ASR Falcon Linux、Kestrel、Lapwing Linux

Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lzma/src/LzmaEnc

2025-07-06
CVE-2025-4946
Analyzed
8.1
Odin Design Vikinger

The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the vikinger_delete_activity_med...

2025-07-05
CVE-2025-49459
Analyzed
7.8
Zoom Communications Zoom Workplace for Windows on ARM

Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6

2025-09-09
CVE-2025-49457
Analyzed
9.6
Zoom Communications Zoom Clients for Windows

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

2025-08-12
CVE-2025-49438
Analyzed
7.2
Max Chirkov Simple Login Log

Deserialization of Untrusted Data vulnerability in Max Chirkov Simple Login Log allows Object Injection

2025-08-20
CVE-2025-49417
Analyzed
9.8
BestWpDeveloper WooCommerce Product Multi-Action

Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action allows Object Injection. This issue affects WooCom...

2025-07-06
CVE-2025-49414
Analyzed
10
Fastw3b FW Gallery

Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery allows Using Malicious Files. This issue affects FW Gallery: f...

2025-07-06
CVE-2025-49407
Analyzed
7.1
favethemes Houzez

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez allows Reflected XSS

2025-08-28
CVE-2025-49405
Analyzed
8.1
favethemes Houzez

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP...

2025-08-28
CVE-2025-49404
Analyzed
8.5
purethemes Listeo Core

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in purethemes Listeo-Core allows SQL Injection

2025-08-28
CVE-2025-49401
Analyzed
9.8
axiomthemes smart SEO

Deserialization of Untrusted Data vulnerability in ExpressTech Systems Quiz And Survey Master allows Object Injection. This issue affects Quiz And Sur...

2025-09-05
CVE-2025-49399
Analyzed
8.8
Basix NEX-Forms

Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms allows Cross Site Request Forgery

2025-08-20
CVE-2025-49388
Analyzed
9.8
kamleshyadav Miraculous Core Plugin

Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin allows Privilege Escalation. This issue affects Miraculous Core Pl...

2025-08-28
CVE-2025-49387
Analyzed
10
add-ons.org

Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms allows Upload a Web Shell t...

2025-08-28
CVE-2025-49383
Analyzed
8.1
CocoBasic Neresa

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Neresa allows PHP L...

2025-08-28
CVE-2025-49382
Analyzed
8.8
DexignZone JobZilla - Job Board WordPress Theme

Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme allows Privilege Escalation

2025-08-20
CVE-2025-49381
Analyzed
9.6
ads.txt Guru ads.txt Guru Connect

Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect allows Cross Site Request Forgery. This issue affects ads.txt Gur...

2025-08-20
CVE-2025-49378
Analyzed
8.5
Themefic Hydra Booking

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL...

2025-10-23
CVE-2025-49377
Analyzed
7.5
Themefic Hydra Booking

Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Access Control Security Levels

2025-10-22
CVE-2025-49376
Analyzed
7.5
DELUCKS DELUCKS SEO

Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-22
CVE-2025-49371
Analyzed
8.1
AncoraThemes Strux

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Strux strux allo...

2025-12-19
CVE-2025-49370
Analyzed
8.1
AncoraThemes Lymcoin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Lymcoin lymcoin...

2025-12-19
CVE-2025-49369
Analyzed
8.1
AncoraThemes Lettuce

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Lettuce lettuce...

2025-12-19
CVE-2025-49368
Analyzed
8.1
AncoraThemes Palladio

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Palladio palladi...

2025-12-19
CVE-2025-49367
Analyzed
8.1
AncoraThemes Monyxi

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Monyxi monyxi al...

2025-12-19
CVE-2025-49366
Analyzed
8.1
AncoraThemes Hanani

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hanani hanani al...

2025-12-19
CVE-2025-49365
Analyzed
8.1
AncoraThemes Jack Well

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Jack Well jack-w...

2025-12-19
CVE-2025-49364
Analyzed
8.1
AncoraThemes Ludos Paradise

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ludos Paradise l...

2025-12-19
CVE-2025-49363
Analyzed
8.1
AncoraThemes Kings & Queens

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Kings & Queens k...

2025-12-19
CVE-2025-49362
Analyzed
8.1
AncoraThemes Gracioza

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gracioza gracioz...

2025-12-19
CVE-2025-49361
Analyzed
8.1
AncoraThemes Mamita

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mamita mamita al...

2025-12-19
CVE-2025-49360
Analyzed
8.1
AncoraThemes Militarology

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Militarology mil...

2025-12-19
CVE-2025-49359
Analyzed
8.1
AncoraThemes ShieldGroup

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ShieldGroup shie...

2025-12-19
CVE-2025-49354
Analyzed
7.1
Mindstien Technologies Recent Posts From Each Category

Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category allows Stored XSS

2026-01-01
CVE-2025-49353
Analyzed
7.1
Marcin Kijak Noindex by Path

Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path allows Stored XSS

2026-01-01
CVE-2025-49346
Analyzed
7.1
peterwsterling Simple Archive Generator

Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Simple Archive Generator allows Stored XSS

2026-01-01
CVE-2025-49345
Analyzed
7.1
mg12 WP-EasyArchives

Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives allows Stored XSS

2026-01-01
CVE-2025-49344
Analyzed
7.1
reneade SensitiveTagCloud

Cross-Site Request Forgery (CSRF) vulnerability in Rene Ade SensitiveTagCloud allows Stored XSS

2026-01-01
CVE-2025-49343
Analyzed
7.1
socialprofilr Social Profilr

Cross-Site Request Forgery (CSRF) vulnerability in Socialprofilr Social Profilr allows Stored XSS

2026-01-01
CVE-2025-49342
Analyzed
7.1
merzedes Custom Style

Cross-Site Request Forgery (CSRF) vulnerability in Wolfgang Häfelinger Custom Style allows Stored XSS

2026-01-01
CVE-2025-49302
Analyzed
10
Scott Paterson Easy Stripe

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe allows Remote Code Inclusion. This issue affects...

2025-07-06
CVE-2025-49271
Analyzed
7.5
GravityWP GravityWP - Merge Tags

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge T...

2025-08-14
CVE-2025-49267
Analyzed
8.5
Shabti Kaplan Frontend Admin by DynamiApps

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps allow...

2025-08-14
CVE-2025-49264
Analyzed
7.5
Cloud Infrastructure Services

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cloud Infrastructure Services...

2025-08-14
CVE-2025-49201
Analyzed
8.1
Fortinet FortiPAM

A weak authentication in Fortinet FortiPAM 1

2025-10-14
CVE-2025-49145
Analyzed
8.7
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11