23871 Total CVEs
23776 AI Analyzed
336 CISA KEV
5459 Critical
All Vendors
Showing 20851-20900 of 23871 CVEs Page 418 of 478
CVE-2025-15057
Analyzed
7.2
veronalabs SlimStat Analytics

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) parameter in all versions up to, a...

2026-01-09
CVE-2025-15055
Analyzed
7.2
veronalabs SlimStat Analytics

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' parameters in all versions up...

2026-01-09
CVE-2025-15047
Analyzed
9.8
Tenda WH450

A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Hand...

2025-12-24
CVE-2025-15046
Analyzed
9.8
Tenda WH450

A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HT...

2025-12-24
CVE-2025-15045
Analyzed
9.8
Tenda WH450

A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit of the component HTTP Request...

2025-12-24
CVE-2025-15044
Analyzed
9.8
Tenda WH450

A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetting. The manipulation of the ar...

2025-12-24
CVE-2025-15036
Analyzed
9.6
mlflow mlflow/mlflow

A path traversal vulnerability in MLflow's archive extraction function allows attackers to overwrite arbitrary files and escape sandboxed directories...

2026-03-30
CVE-2025-15034
Analyzed
7.3
itsourcecode Student Management System

A security flaw has been discovered in itsourcecode Student Management System 1

2025-12-23
CVE-2025-15032
Analyzed
7.4
The Browser Company of New York Dia

Missing about:blank indicator in custom-sized new windows in Dia before 1

2026-01-18
CVE-2025-15031
Analyzed
8.1
mlflow mlflow/mlflow

A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries

2026-03-19
CVE-2025-15030
Analyzed
9.8
WordPress User Profile Builder

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to res...

2026-02-03
CVE-2025-15029
Analyzed
9.8
Centreon Infra Monitoring

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules)...

2026-01-06
CVE-2025-15027
Analyzed
9.8
jayarsiech JAY Login & Register

The JAY Login & Register plugin for WordPress allows unauthenticated privilege escalation to administrator by exploiting the 'jay_login_register_ajax_...

2026-02-08
CVE-2025-15026
Analyzed
9.8
Centreon Infra Monitoring

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functional...

2026-01-06
CVE-2025-15025
Analyzed
8.8
Unknown Library Automation System

Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry a...

2026-05-15
CVE-2025-15024
Analyzed
8.8
Unknown Library Automation System

Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems I...

2026-05-15
CVE-2025-15023
Analyzed
8.8
Unknown Library Automation System

Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc

2026-05-15
CVE-2025-15018
Analyzed
9.8
djanym Optional Email

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This...

2026-01-08
CVE-2025-15016
Analyzed
9.8
Ragic Enterprise Cloud Database

Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit th...

2025-12-22
CVE-2025-15015
Analyzed
7.5
Ragic Enterprise Cloud Database

Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Pa...

2025-12-22
CVE-2025-15012
Analyzed
7.3
code-projects Refugee Food Management System

A vulnerability was determined in code-projects Refugee Food Management System 1

2025-12-22
CVE-2025-15011
Analyzed
7.3
code-projects Simple Stock System

A vulnerability was found in code-projects Simple Stock System 1

2025-12-22
CVE-2025-15010
Analyzed
9.8
Tenda WH450

A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulation...

2025-12-22
CVE-2025-15008
Analyzed
7.3
Tenda WH450

A vulnerability was detected in Tenda WH450 1

2025-12-22
CVE-2025-15007
Analyzed
9.8
Tenda WH450

A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of t...

2025-12-22
CVE-2025-15006
Analyzed
9.8
Tenda WH450

A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of t...

2025-12-22
CVE-2025-15002
Analyzed
7.3
Unknown SeaCMS

A vulnerability has been found in SeaCMS up to 13

2025-12-22
CVE-2025-15001
Analyzed
9.8
fsylum FS Registration Password

The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0...

2026-01-06
CVE-2025-14998
Analyzed
9.8
wpmudev

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due t...

2026-01-02
CVE-2025-14997
Analyzed
7.2
BuddyDev BuddyPress Xprofile Custom Field Types

The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t...

2026-01-06
CVE-2025-14996
Analyzed
9.8
aksharsoftsolutions

The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up...

2026-01-06
CVE-2025-14995
Analyzed
8.8
Tenda FH1201

A vulnerability has been found in Tenda FH1201 1

2025-12-21
CVE-2025-14994
Analyzed
8.8
Tenda FH1201

A flaw has been found in Tenda FH1201 and FH1206 1

2025-12-21
CVE-2025-14993
Analyzed
8.8
Tenda AC18

A vulnerability was detected in Tenda AC18 15

2025-12-21
CVE-2025-14992
Analyzed
8.8
Tenda AC18

A security vulnerability has been detected in Tenda AC18 15

2025-12-21
CVE-2025-14990
Analyzed
7.3
Campcodes Complete Online Beauty Parlor Management System

A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1

2025-12-21
CVE-2025-14989
Analyzed
7.3
Campcodes Complete Online Beauty Parlor Management System

A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1

2025-12-21
CVE-2025-14977
Analyzed
8.1
dokaninc

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution โ€“ Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure...

2026-01-20
CVE-2025-14975
Analyzed
8.1
WordPress Custom Login Page Customizer

The Custom Login Page Customizer WordPress plugin before 2

2026-01-30
CVE-2025-14968
Analyzed
7.3
code-projects Simple Stock System

A security flaw has been discovered in code-projects Simple Stock System 1

2025-12-20
CVE-2025-14967
Analyzed
7.3
itsourcecode Student Management System

A vulnerability was identified in itsourcecode Student Management System 1

2025-12-20
CVE-2025-14964
Analyzed
9.8
TOTOLINK T10

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5083_B20200521. This affects the function sprintf of the file /cgi-bin/cstecgi.cgi. Such manipu...

2025-12-20
CVE-2025-14961
Analyzed
7.3
code-projects Simple Blood Donor Management System

A vulnerability was detected in code-projects Simple Blood Donor Management System 1

2025-12-20
CVE-2025-14960
Analyzed
7.3
code-projects Simple Blood Donor Management System

A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1

2025-12-20
CVE-2025-14959
Analyzed
7.3
code-projects Simple Stock System

A weakness has been identified in code-projects Simple Stock System 1

2025-12-20
CVE-2025-14952
Analyzed
7.3
Campcodes Supplier Management System

A vulnerability was detected in Campcodes Supplier Management System 1

2025-12-20
CVE-2025-14951
Analyzed
7.3
code-projects Scholars Tracking System

A security vulnerability has been detected in code-projects Scholars Tracking System 1

2025-12-20
CVE-2025-14950
Analyzed
7.3
code-projects Scholars Tracking System

A weakness has been identified in code-projects Scholars Tracking System 1

2025-12-20
CVE-2025-14940
Analyzed
7.3
code-projects Scholars Tracking System

A vulnerability was determined in code-projects Scholars Tracking System 1

2025-12-20
CVE-2025-14937
Analyzed
7.2
shabti Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parameter in the 'frontend_admin/for...

2026-01-10