25368 Total CVEs
25273 AI Analyzed
354 CISA KEV
5897 Critical
All Vendors
Showing 20351-20400 of 25368 CVEs Page 408 of 508
CVE-2025-50053
Analyzed
7.1
nebelhorn

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin & Your nati...

2026-01-01
CVE-2025-49950
Analyzed
7.3
billingo Official Integration for Billingo

Missing Authorization vulnerability in billingo Official Integration for Billingo billingo allows Privilege Escalation

2025-10-23
CVE-2025-49943
Analyzed
8.1
AncoraThemes Femme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Femme femme allo...

2025-12-19
CVE-2025-49942
Analyzed
8.1
AncoraThemes Gardis

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gardis gardis al...

2025-12-19
CVE-2025-49941
Analyzed
8.1
AncoraThemes GlamChic

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes GlamChic glamchi...

2025-12-19
CVE-2025-4994
Analyzed
8.7
SafeLine SafeLine SL6/SL6+

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass

2026-06-23
CVE-2025-49935
Analyzed
7.4
xTemos Woodmart

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allo...

2025-10-23
CVE-2025-49931
Analyzed
9.3
Crocoblock JetSearch

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CrocoBlock JetSearch jet-search allows Blind SQL...

2025-10-23
CVE-2025-49926
Analyzed
7.3
Laborator Kalium

Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection

2025-10-23
CVE-2025-49925
Analyzed
7.3
VibeThemes WPLMS

Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-23
CVE-2025-49924
Analyzed
7.3
Josh Kohlbach Wholesale Suite

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation

2025-10-23
CVE-2025-49921
Analyzed
7.3
Crocoblock JetReviews

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CrocoBlock JetReviews jet-rev...

2025-10-23
CVE-2025-49916
Analyzed
8.6
MultiVendorX MultiVendorX

Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained b...

2025-10-23
CVE-2025-49915
Analyzed
9.3
Cozy Vision SMS Alert Order Notifications

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-al...

2025-10-23
CVE-2025-49910
Analyzed
8.2
AmentoTech Private WPGuppy

Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs

2025-10-23
CVE-2025-49907
Analyzed
8.2
RealMag777 MDTF

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control...

2025-10-22
CVE-2025-49901
Analyzed
9.8
quantumcloud Simple Link Directory

Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentic...

2025-10-23
CVE-2025-49897
8.5
gopiplus Vertical scroll slideshow gallery v2

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 al...

2025-08-15
CVE-2025-49895
Analyzed
8.8
iThemes ServerBuddy by PluginBuddy.com

Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy

2025-08-17
CVE-2025-49888
Analyzed
7.1
pimwick PW WooCommerce On Sale!

Missing Authorization vulnerability in pimwick PW WooCommerce On Sale! allows Exploiting Incorrectly Configured Access Control Security Levels

2025-07-16
CVE-2025-49887
Analyzed
9.9
WPFactory Product XML Feed Manager for WooCommerce

Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce allows Remote Code Inclu...

2025-08-14
CVE-2025-49876
Analyzed
8.5
Metagauss ProfileGrid

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows SQL Injection

2025-07-16
CVE-2025-49870
Analyzed
7.5
Cozmoslabs Paid Member Subscriptions

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions allows SQL...

2025-07-06
CVE-2025-49869
Analyzed
8.8
Arraytics Eventin

Deserialization of Untrusted Data vulnerability in Arraytics Eventin allows Object Injection

2025-08-14
CVE-2025-49867
9.8
InspiryThemes RealHomes

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege Escalation. This issue affects RealHomes: from n/a through 4....

2025-07-06
CVE-2025-49844
Analyzed
9.9
redis redis

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua...

2025-10-03
CVE-2025-49826
7.5
vercel next.js

Next

2025-07-06
CVE-2025-49809
7.8
mtr mtr

mtr through 0

2025-07-06
CVE-2025-49761
Analyzed
7.8
Microsoft Windows 10 Version 1507

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-49759
Analyzed
8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12
CVE-2025-49758
Analyzed
8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges...

2025-08-12
CVE-2025-49757
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-08-12
CVE-2025-49753
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49752
Analyzed
10
Microsoft Azure Bastion Developer

Azure Bastion Elevation of Privilege Vulnerability

2025-11-20
CVE-2025-49741
7.4
Microsoft Microsoft Edge (Chromium-based)

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network

2025-07-06
CVE-2025-49740
Analyzed
8.8
Microsoft Windows 10 Version 1507

Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network

2025-07-08
CVE-2025-49739
Analyzed
8.8
Microsoft Microsoft Visual Studio 2015 Update 3

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network

2025-07-10
CVE-2025-49735
Analyzed
8.1
Microsoft Windows Server 2012

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network

2025-07-10
CVE-2025-49729
Analyzed
8.8

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49724
Analyzed
8.8
Microsoft Windows 10 Version 1809

Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49723
Analyzed
8.8
Microsoft Windows 10 Version 1809

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally

2025-07-08
CVE-2025-49717
Analyzed
8.5
Microsoft Microsoft SQL Server 2019 (CU 32)

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network

2025-07-10
CVE-2025-49713
Analyzed
8.8
Microsoft Microsoft Edge (Chromium-based)

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over...

2025-07-05
CVE-2025-49712
Analyzed
8.8
Microsoft Microsoft SharePoint Enterprise Server 2016

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-49708
Analyzed
9.9
Microsoft Windows 10 Version 1809

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

2025-10-14
CVE-2025-49707
Analyzed
7.9
Microsoft DCadsv5-series Azure VM

Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally

2025-08-12
CVE-2025-49704
Analyzed
8.8
Microsoft Microsoft SharePoint Enterprise Server 2016

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-07-08
CVE-2025-49701
Analyzed
8.8
Microsoft Microsoft SharePoint Enterprise Server 2016

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-07-08
CVE-2025-49697
Analyzed
8.4
Microsoft Microsoft 365 Apps for Enterprise

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally

2025-07-08
CVE-2025-49696
Analyzed
8.4
Microsoft Microsoft 365 Apps for Enterprise

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally

2025-07-08