24905 Total CVEs
24810 AI Analyzed
349 CISA KEV
5784 Critical
All Vendors
Showing 20001-20050 of 24905 CVEs Page 401 of 499
CVE-2025-49365
Analyzed
8.1
AncoraThemes Jack Well

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Jack Well jack-w...

2025-12-19
CVE-2025-49364
Analyzed
8.1
AncoraThemes Ludos Paradise

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ludos Paradise l...

2025-12-19
CVE-2025-49363
Analyzed
8.1
AncoraThemes Kings & Queens

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Kings & Queens k...

2025-12-19
CVE-2025-49362
Analyzed
8.1
AncoraThemes Gracioza

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gracioza gracioz...

2025-12-19
CVE-2025-49361
Analyzed
8.1
AncoraThemes Mamita

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mamita mamita al...

2025-12-19
CVE-2025-49360
Analyzed
8.1
AncoraThemes Militarology

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Militarology mil...

2025-12-19
CVE-2025-49359
Analyzed
8.1
AncoraThemes ShieldGroup

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ShieldGroup shie...

2025-12-19
CVE-2025-49354
Analyzed
7.1
Mindstien Technologies Recent Posts From Each Category

Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category allows Stored XSS

2026-01-01
CVE-2025-49353
Analyzed
7.1
Marcin Kijak Noindex by Path

Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path allows Stored XSS

2026-01-01
CVE-2025-49346
Analyzed
7.1
peterwsterling Simple Archive Generator

Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Simple Archive Generator allows Stored XSS

2026-01-01
CVE-2025-49345
Analyzed
7.1
mg12 WP-EasyArchives

Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives allows Stored XSS

2026-01-01
CVE-2025-49344
Analyzed
7.1
reneade SensitiveTagCloud

Cross-Site Request Forgery (CSRF) vulnerability in Rene Ade SensitiveTagCloud allows Stored XSS

2026-01-01
CVE-2025-49343
Analyzed
7.1
socialprofilr Social Profilr

Cross-Site Request Forgery (CSRF) vulnerability in Socialprofilr Social Profilr allows Stored XSS

2026-01-01
CVE-2025-49342
Analyzed
7.1
merzedes Custom Style

Cross-Site Request Forgery (CSRF) vulnerability in Wolfgang Häfelinger Custom Style allows Stored XSS

2026-01-01
CVE-2025-49302
Analyzed
10
Scott Paterson Easy Stripe

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe allows Remote Code Inclusion. This issue affects...

2025-07-06
CVE-2025-49271
Analyzed
7.5
GravityWP GravityWP - Merge Tags

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge T...

2025-08-14
CVE-2025-49267
Analyzed
8.5
Shabti Kaplan Frontend Admin by DynamiApps

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps allow...

2025-08-14
CVE-2025-49264
Analyzed
7.5
Cloud Infrastructure Services

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cloud Infrastructure Services...

2025-08-14
CVE-2025-49201
Analyzed
8.1
Fortinet FortiPAM

A weak authentication in Fortinet FortiPAM 1

2025-10-14
CVE-2025-49145
Analyzed
8.7
Combodo iTop

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-49113
KEV Analyzed
9.5
Roundcube Webmail

RoundCube Webmail Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.

2026-02-21
CVE-2025-49090
Analyzed
7.1
Matrix Matrix specification

The Matrix specification before 1

2025-10-02
CVE-2025-49070
Analyzed
7.5
NasaTheme Elessi

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi allows PHP L...

2025-07-06
CVE-2025-49060
Analyzed
10
CMSSuperHeroes Wastia

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue aff...

2025-10-23
CVE-2025-49059
Analyzed
9.3
CleverReach® CleverReach® WP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP allows SQL Injectio...

2025-08-14
CVE-2025-49036
Analyzed
8.1
octagonwebstudio Premium Addons for KingComposer

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addo...

2025-08-14
CVE-2025-49034
Analyzed
7.6
Aman Funnel Builder by FunnelKit

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows SQL...

2025-07-16
CVE-2025-49033
Analyzed
8.5
Metagauss ProfileGrid

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows Blind SQL Injectio...

2025-08-14
CVE-2025-49031
Analyzed
7.1
Stefan M SMu Manual DoFollow

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefan M

2025-07-16
CVE-2025-49029
9.1
bitto.kazi Custom Login And Signup Widget

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.Kazi Custom Login And Signup Widget allows Code Injection.This issue...

2025-07-06
CVE-2025-49028
Analyzed
7.1
Zoho Mail Zoho ZeptoMail

Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail allows Stored XSS

2026-01-01
CVE-2025-48989
Analyzed
7.5
Apache Apache Tomcat

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack

2025-08-14
CVE-2025-48986
Analyzed
8.8
Revive Revive Adserver

Authorization bypass in Revive Adserver 5

2025-11-20
CVE-2025-48984
Analyzed
8.8
Veeam Backup and Replication

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

2025-10-31
CVE-2025-48983
Analyzed
9.9
Veeam Backup and Replication

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by...

2025-10-31
CVE-2025-48982
Analyzed
7.3
Veeam Agent for Microsoft Windows

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a ma...

2025-10-31
CVE-2025-48981
Analyzed
8.6
CompuGroup Medical CGM MEDICO

An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate dat...

2025-10-08
CVE-2025-48978
Analyzed
7.5
Ubiquiti EdgeMAX EdgeSwitch

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1

2025-08-21
CVE-2025-48963
Analyzed
7.3
Acronis Acronis Cyber Protect Cloud Agent

Local privilege escalation due to improper soft link handling

2025-08-28
CVE-2025-48956
Analyzed
7.5

vLLM is an inference and serving engine for large language models (LLMs)

2025-08-21
CVE-2025-48952
9.4
jokob-sk NetAlertX

NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to by...

2025-07-06
CVE-2025-48928
KEV Analyzed
9.5
TeleMessage service

TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability - Recently added to CISA KEV.

2025-07-05
CVE-2025-48927
KEV Analyzed
9.5
TeleMessage service

TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability - Recently added to CISA KEV.

2025-07-05
CVE-2025-48913
Analyzed
9.8
Apache Apache CXF

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capa...

2025-08-08
CVE-2025-48891
Analyzed
7.6
Advantech iView

A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils

2025-07-11
CVE-2025-48869
Analyzed
7.5
horilla-opensource horilla

Horilla is a free and open source Human Resource Management System (HRMS)

2025-09-24
CVE-2025-48868
Analyzed
7.2
horilla-opensource horilla

Horilla is a free and open source Human Resource Management System (HRMS)

2025-09-24
CVE-2025-48860
Analyzed
8
Bosch Rexroth ctrlX OS - Setup

A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to...

2025-08-14
CVE-2025-48826
Analyzed
8.8
Planet WGR-500

A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1

2025-10-07
CVE-2025-48824
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08