23871 Total CVEs
23776 AI Analyzed
336 CISA KEV
5459 Critical
All Vendors
Showing 21301-21350 of 23871 CVEs Page 427 of 478
CVE-2025-13446
Analyzed
8.8
Tenda AC21

A vulnerability has been found in Tenda AC21 16

2025-11-20
CVE-2025-13445
Analyzed
8.8
Tenda AC21

A flaw has been found in Tenda AC21 16

2025-11-20
CVE-2025-13444
Analyzed
8.4
Progress Software LoadMaster

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” per...

2026-01-14
CVE-2025-13442
Analyzed
7.3
UTT 进取 750W

A security vulnerability has been detected in UTT 进取 750W up to 3

2025-11-20
CVE-2025-13433
Analyzed
7
Muse Group MuseHub

A security flaw has been discovered in Muse Group MuseHub 2

2025-11-20
CVE-2025-13422
Analyzed
7.3
freeprojectscodes Sports Club Management System

A vulnerability was detected in freeprojectscodes Sports Club Management System 1

2025-11-20
CVE-2025-13421
Analyzed
7.3
itsourcecode Human Resource Management System

A security vulnerability has been detected in itsourcecode Human Resource Management System 1

2025-11-20
CVE-2025-13420
Analyzed
7.3
itsourcecode Human Resource Management System

A weakness has been identified in itsourcecode Human Resource Management System 1

2025-11-20
CVE-2025-13417
Analyzed
8.6
WordPress Plugin Organizer

The Plugin Organizer WordPress plugin before 10

2025-12-30
CVE-2025-13410
Analyzed
7.3
Campcodes Retro Basketball Shoes Online Store

A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1

2025-11-20
CVE-2025-13400
Analyzed
8.8
Tenda CH22

A vulnerability was detected in Tenda CH22 1

2025-11-20
CVE-2025-13395
Analyzed
7.3
codehub666 94list

A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8

2025-11-20
CVE-2025-13390
Analyzed
10
listingthemes WP Directory Kit

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implemen...

2025-12-03
CVE-2025-13387
Analyzed
7.2
stellarwp Kadence WooCommerce Email Designer

The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to,...

2025-12-03
CVE-2025-13384
Analyzed
7.5
codepeople CP Contact Form with Paypal

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1

2025-11-23
CVE-2025-13379
Analyzed
8.6
IBM Aspera Console

IBM Aspera Console 3

2026-02-06
CVE-2025-13376
Analyzed
7.2
ov3rkll ProjectList

The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including,...

2025-11-26
CVE-2025-13375
Analyzed
9.8
IBM Common Cryptographic Architecture

IBM Common Cryptographic Architecture (CCA) contains a flaw allowing unauthenticated users to execute arbitrary commands with elevated privileges. Pat...

2026-02-05
CVE-2025-13374
Analyzed
9.8
irisideatechsolutions Kalrav AI Agent

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX ac...

2026-01-24
CVE-2025-13373
Analyzed
7.5
Advantech iView

Advantech iView versions 5

2025-12-05
CVE-2025-13371
Analyzed
8.6
moneyspace Money Space

The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2

2026-01-08
CVE-2025-13357
Analyzed
7.4
HashiCorp Tooling

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in...

2025-11-22
CVE-2025-13355
Analyzed
7.1
WordPress URL Shortify

The URL Shortify WordPress plugin before 1

2025-12-16
CVE-2025-13344
Analyzed
7.3
SourceCodester Train Station Ticketing System

A weakness has been identified in SourceCodester Train Station Ticketing System 1

2025-11-19
CVE-2025-13342
Analyzed
9.8
shabti Frontend Admin by DynamiApps

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to,...

2025-12-03
CVE-2025-13339
Analyzed
7.5
hippooo Hippoo Mobile App for WooCommerce

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1

2025-12-12
CVE-2025-13334
Analyzed
8.1
blazethemes Blaze Demo Importer

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the...

2025-12-13
CVE-2025-13329
Analyzed
9.8
snowray File Uploader for WooCommerce

The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback fun...

2025-12-20
CVE-2025-13323
Analyzed
7.3
code-projects Simple Pizza Ordering System

A security flaw has been discovered in code-projects Simple Pizza Ordering System 1

2025-11-19
CVE-2025-13322
Analyzed
8.1
husainali52 WP AUDIO GALLERY

The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and...

2025-11-22
CVE-2025-13319
Analyzed
8.8
Nettec AS Digi On-Prem Manager

An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL vi...

2025-11-18
CVE-2025-13313
Analyzed
9.8
dripadmin CRM Memberships

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.5. This is d...

2025-12-06
CVE-2025-13307
Analyzed
7.2
WordPress Ocean Modal Window

The Ocean Modal Window WordPress plugin before 2

2025-12-20
CVE-2025-13305
Analyzed
8.8
D-Link DWR-M920

A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1

2025-11-18
CVE-2025-13304
Analyzed
8.8
D-Link DWR-M920

A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1

2025-11-18
CVE-2025-13301
Analyzed
7.3
itsourcecode Web-Based Internet Laboratory Management System

A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1

2025-11-18
CVE-2025-13300
Analyzed
7.3
itsourcecode Web-Based Internet Laboratory Management System

A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1

2025-11-18
CVE-2025-13299
Analyzed
7.3
itsourcecode Web-Based Internet Laboratory Management System

A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1

2025-11-18
CVE-2025-13298
Analyzed
7.3
itsourcecode Web-Based Internet Laboratory Management System

A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1

2025-11-18
CVE-2025-13297
Analyzed
7.3
itsourcecode Web-Based Internet Laboratory Management System

A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1

2025-11-18
CVE-2025-13295
Analyzed
7.5
Argus Technology BILGER

Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc

2025-12-03
CVE-2025-13294
Analyzed
9.3
TBEA TLogger (Communication Box 3rd Generation)

An unauthenticated SQL injection vulnerability in TBEA TLogger V2.1.0.0B0.0.0.0 allows remote attackers to read, modify, or delete data in the device...

2026-08-11
CVE-2025-13293
Analyzed
9.3
TBEA TLogger

TBEA TLogger contains a hard-coded root credential, allowing an unauthenticated remote attacker to gain administrative access via SSH.

2026-08-11
CVE-2025-13291
Analyzed
7.3
Campcodes Supplier Management System

A vulnerability was found in Campcodes Supplier Management System 1

2025-11-18
CVE-2025-13288
Analyzed
8.8
Tenda CH22

A security vulnerability has been detected in Tenda CH22 1

2025-11-18
CVE-2025-13285
Analyzed
7.3
itsourcecode Online Voting System

A vulnerability was identified in itsourcecode Online Voting System 1

2025-11-18
CVE-2025-13284
Analyzed
9.8
ThinPLUS ThinPLUS

ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands an...

2025-11-18
CVE-2025-13283
Analyzed
7.1
Chunghwa Telecom TenderDocTransfer

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability

2025-11-18
CVE-2025-13282
Analyzed
8.1
Chunghwa Telecom TenderDocTransfer

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability

2025-11-18
CVE-2025-13280
Analyzed
7.3
CodeAstro Simple Inventory System

A vulnerability was determined in CodeAstro Simple Inventory System 1

2025-11-18