24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 21201-21250 of 24021 CVEs Page 425 of 481
CVE-2025-14443
Analyzed
8.5
Red Hat Red Hat OpenShift Container Platform 4

A flaw was found in ose-openshift-apiserver

2025-12-17
CVE-2025-14440
Analyzed
9.8
jayarsiech JAY Login & Register

The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrec...

2025-12-14
CVE-2025-14437
Analyzed
7.5
wpmudev

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3

2025-12-20
CVE-2025-14436
Analyzed
7.2
neeraj slit Brevo for WooCommerce

The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’ parameter in all versions up...

2026-01-09
CVE-2025-14431
Analyzed
9.8
THEMELOGI Navian

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in THEMELOGI Navian navian allow...

2026-01-09
CVE-2025-14430
Analyzed
9.8
ThemeMove Brook

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook - Agency Busi...

2026-01-09
CVE-2025-14429
Analyzed
9.8
ThemeMove AeroLand

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove AeroLand aeroland a...

2026-01-09
CVE-2025-14425
Analyzed
7.8
GIMP GIMP

GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14424
Analyzed
7.8
GIMP GIMP

GIMP XCF File Parsing Use-After-Free Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14423
Analyzed
7.8
GIMP GIMP

GIMP LBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14422
Analyzed
7.8
GIMP GIMP

GIMP PNM File Parsing Integer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14420
Analyzed
7.8
pdfforge PDF Architect

pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14419
Analyzed
7.8
pdfforge PDF Architect

pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14417
Analyzed
7.8
pdfforge PDF Architect

pdfforge PDF Architect Launch Insufficient UI Warning Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14414
Analyzed
7.8
Soda PDF Desktop

Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14413
Analyzed
7.8
Soda PDF Desktop

Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14412
Analyzed
7.8
Soda PDF Desktop

Soda PDF Desktop XLS File Insufficient UI Warning Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14409
Analyzed
7.8
Soda PDF Desktop

Soda PDF Desktop PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14406
Analyzed
7.8
Soda PDF Desktop

Soda PDF Desktop Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

2025-12-24
CVE-2025-14403
Analyzed
7.8
PDFsam Enhanced

PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14401
Analyzed
7.8
PDFsam Enhanced

PDFsam Enhanced App Out-Of-Bounds Read Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14397
Analyzed
8.8
franciscopalacios Postem Ipsum

The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to a missing capability check on...

2025-12-14
CVE-2025-14390
Analyzed
8.8
videomerchant Video Merchant

The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5

2025-12-11
CVE-2025-14388
Analyzed
9.8
kiboit PhastPress

The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including,...

2025-12-24
CVE-2025-14386
Analyzed
8.8
shahrukhlinkgraph

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authenticatio...

2026-01-29
CVE-2025-14383
Analyzed
7.5
wpdevelop Booking Calendar

The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, an...

2025-12-16
CVE-2025-14364
Analyzed
8.8
kraftplugins Demo Importer Plus

The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missin...

2025-12-19
CVE-2025-14360
Analyzed
9.8
Kaira Blockons

Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bloc...

2026-01-09
CVE-2025-14359
Analyzed
9.8
Brandexponents Oshine

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in brandexponents Oshine oshin a...

2026-01-09
CVE-2025-14358
Analyzed
9.8
sizam REHub Framework

Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issu...

2026-01-09
CVE-2025-14353
Analyzed
7.5
PressTigers ZIP Code Based Content Protection

The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1

2026-03-08
CVE-2025-14349
Analyzed
8.8
Universal Software FlexCity/Kiosk

Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc

2026-02-14
CVE-2025-14346
Analyzed
9.8
WHILL Model C2 Electric Wheelchair

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pai...

2026-01-06
CVE-2025-14344
Analyzed
9.8
sh1zen Multi Uploader for Gravity Forms

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'pl...

2025-12-13
CVE-2025-14343
Analyzed
7.6
Dokuzsoft Technology E-Commerce Product

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd

2026-02-27
CVE-2025-14341
Analyzed
8.3
DivvyDrive Information Technologies DivvyDrive

Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in...

2026-05-08
CVE-2025-14333
Analyzed
8.1
Mozilla Firefox

Memory safety bugs present in Firefox ESR 140

2025-12-10
CVE-2025-14329
Analyzed
8.8
Mozilla Firefox

Privilege escalation in the Netmonitor component

2025-12-10
CVE-2025-14328
Analyzed
8.8
Mozilla Firefox

Privilege escalation in the Netmonitor component

2025-12-10
CVE-2025-14327
Analyzed
7.5
Mozilla Firefox

Spoofing issue in the Downloads Panel component

2025-12-11
CVE-2025-14323
Analyzed
8.8
Mozilla Firefox

Privilege escalation in the DOM: Notifications component

2025-12-10
CVE-2025-14322
Analyzed
8
Mozilla Firefox

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component

2025-12-10
CVE-2025-14320
Analyzed
9.8
Infor Online Support Application

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trad...

2026-05-05
CVE-2025-14316
Analyzed
7.1
WordPress AhaChat Messenger Marketing

The AhaChat Messenger Marketing WordPress plugin through 1

2026-01-27
CVE-2025-14314
Analyzed
8.5
Roxnor PopupKit

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roxnor PopupKit popup-builder-block allows Blind...

2025-12-19
CVE-2025-14309
Analyzed
7.5
ravynsoft ravynos

NULL Pointer Dereference vulnerability in ravynsoft ravynos

2025-12-11
CVE-2025-14305
Analyzed
7.8
Acer ListCheck.exe

ListCheck

2025-12-17
CVE-2025-14301
Analyzed
9.8
woosaai Integration Opvius AI for WooCommerce

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is du...

2026-01-14
CVE-2025-14287
Analyzed
7.5
mlflow mlflow/mlflow

A command injection vulnerability exists in mlflow/mlflow versions before v3

2026-03-17
CVE-2025-14279
Analyzed
8.1
mlflow mlflow/mlflow

MLFlow versions up to and including 3

2026-01-12