24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 20301-20350 of 24021 CVEs Page 407 of 481
CVE-2025-29846
Analyzed
7.2
Synology Synology Router Manager (SRM)

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages

2025-12-05
CVE-2025-29745
Analyzed
7.5
Unknown

A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024

2025-08-05
CVE-2025-29635
KEV Analyzed
9.5
D-Link DIR-823X

D-Link DIR-823X Command Injection Vulnerability - Active in CISA KEV catalog.

2026-04-25
CVE-2025-29556
Analyzed
7.3
ExaGrid

ExaGrid EX10 6

2025-07-31
CVE-2025-29534
Analyzed
8.8
Unknown

An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1

2025-07-28
CVE-2025-29523
Analyzed
7.2

D-Link DSL-7740C with firmware DSL7740C

2025-08-25
CVE-2025-29516
Analyzed
7.2

D-Link DSL-7740C with firmware DSL7740C

2025-08-25
CVE-2025-29515
Analyzed
9.8

Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitra...

2025-08-25
CVE-2025-29514
Analyzed
9.8

Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to download the conf...

2025-08-25
CVE-2025-29421
Analyzed
7.5
PerfreeBlog

PerfreeBlog v4

2025-08-26
CVE-2025-29420
Analyzed
7.5
PerfreeBlog

PerfreeBlog v4

2025-08-26
CVE-2025-29365
Analyzed
9.8
Unknown

spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.

2025-08-23
CVE-2025-2932
Analyzed
8.8
jkdevstudio JKDEVKIT

The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' funct...

2025-07-05
CVE-2025-29296
Analyzed
9.8
H3C

Multiple H3C network devices contain command injection vulnerabilities in the /api/esps request handler, allowing unauthenticated remote attackers to...

2026-08-05
CVE-2025-2928
Analyzed
7.2
Genetec Genetec Security Center

SQL Injection affecting the Archiver role

2025-07-29
CVE-2025-29270
Analyzed
10
Unknown

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the...

2025-10-31
CVE-2025-29229
Analyzed
9.8

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

2025-12-24
CVE-2025-29228
Analyzed
9.8

Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

2025-12-24
CVE-2025-29192
Analyzed
8.2
FlowiseAI Flowise

Flowise before 3

2025-10-06
CVE-2025-2902
Analyzed
8.3
Hitachi

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform

2026-06-29
CVE-2025-29009
Analyzed
10
Webkul Medical Prescription Attachment Plugin for WooCommerce

Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce allows Upload a Web She...

2025-07-16
CVE-2025-29004
Analyzed
8.8
AA-Team

Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing P...

2026-01-07
CVE-2025-29000
Analyzed
7.5
August Infotech Multi-language Responsive Contact Form

Missing Authorization vulnerability in August Infotech Multi-language Responsive Contact Form allows Accessing Functionality Not Properly Constrained...

2025-07-16
CVE-2025-28983
9.8
ClickandPledge Click & Pledge Connect

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Pri...

2025-07-06
CVE-2025-28982
Analyzed
9.3
ThimPress WP Pipes

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes allows SQL Injection. This is...

2025-07-16
CVE-2025-28980
7.7
machouinard Aviation Weather from NOAA

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Tra...

2025-07-06
CVE-2025-28979
Analyzed
8.1
ThimPress WP Pipes

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PHP...

2025-08-14
CVE-2025-28977
Analyzed
7.1
ThimPress WP Pipes

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes allows Reflected XSS

2025-08-20
CVE-2025-28969
Analyzed
8.5
cybio Gallery Widget

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widget allows SQL Injection

2025-07-06
CVE-2025-28967
Analyzed
8.5
Steve Truman

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LI...

2025-07-05
CVE-2025-28965
Analyzed
8.6
Md Yeasin Ul Haider URL Shortener

Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener allows Accessing Functionality Not Properly Constrained by ACLs

2025-07-16
CVE-2025-28961
Analyzed
9.8
Md Yeasin Ul Haider URL Shortener

Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener allows Object Injection. This issue affects URL Shortener: from n...

2025-07-16
CVE-2025-28959
Analyzed
9.3
Md Yeasin Ul Haider URL Shortener

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haider URL Shortener allows SQL Inj...

2025-07-16
CVE-2025-28955
Analyzed
7.5
FWDesign Easy Video Player Wordpress & WooCommerce

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Player Wordpress & WooCommerce all...

2025-07-16
CVE-2025-28951
9.1
CreedAlly Bulk Featured Image

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image allows Upload a Web Shell to a Web Server. This issue a...

2025-07-06
CVE-2025-28949
Analyzed
8.5
Codedraft Mediabay - WordPress Media Library Folders

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Fol...

2026-01-01
CVE-2025-2843
Analyzed
8.8
rhobs observability-operator

A flaw was found in the Observability Operator

2025-11-13
CVE-2025-28357
Analyzed
8.8
Unknown

A CRLF injection vulnerability in Neto CMS v6

2025-10-01
CVE-2025-2824
Analyzed
7.4
IBM Operational Decision Manager

IBM Operational Decision Manager 8

2025-08-01
CVE-2025-28170
Analyzed
7.6
Grandstream

Grandstream Networks GXP1628 <=1

2025-07-29
CVE-2025-2813
Analyzed
7.5
Phoenix Contact AXL F BK PN TPS

An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80

2025-07-31
CVE-2025-28041
Analyzed
8.6
Unknown

Incorrect access control in the doFilter function of itranswarp up to 2

2025-08-21
CVE-2025-2800
Analyzed
7.2
wpeventmanager

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting...

2025-07-16
CVE-2025-27919
Analyzed
8.2
AnyDesk

An issue was discovered in AnyDesk through 9

2025-11-08
CVE-2025-27917
Analyzed
7.5
AnyDesk

An issue was discovered in AnyDesk through 9

2025-11-08
CVE-2025-27916
Analyzed
7.5
AnyDesk

An issue was discovered in AnyDesk through 9

2025-11-08
CVE-2025-27915
KEV Analyzed
9.5
Synacor Zimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability - Active in CISA KEV catalog.

2025-10-07
CVE-2025-27845
Analyzed
9.8
Unknown

In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This all...

2025-08-15
CVE-2025-27821
Analyzed
7.3
Apache HDFS native client

Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client

2026-01-27
CVE-2025-27772
Analyzed
7.4
uptrain-ai uptrain

UpTrain is an open-source platform to evaluate and improve generative AI applications

2026-08-18