24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 21401-21450 of 24021 CVEs Page 429 of 481
CVE-2025-13597
Analyzed
9.8
soportecibeles AI Feeds

The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all ve...

2025-11-26
CVE-2025-13595
Analyzed
9.8
soportecibeles CIBELES AI

The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all...

2025-11-26
CVE-2025-13592
Analyzed
7.2
monetizemore

The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2

2025-12-30
CVE-2025-13590
Analyzed
9.1
WSO2 WSO2 API Manager

A critical flaw in a system REST API allows an authenticated administrator to upload arbitrary files to user-controlled locations, leading to remote c...

2026-02-20
CVE-2025-13585
Analyzed
7.3
itsourcecode COVID Tracking System

A vulnerability was detected in code-projects COVID Tracking System 1

2025-11-25
CVE-2025-13583
Analyzed
7.3
code-projects Question Paper Generator

A weakness has been identified in code-projects Question Paper Generator 1

2025-11-25
CVE-2025-13582
Analyzed
7.3
code-projects Jonnys Liquor

A security flaw has been discovered in code-projects Jonnys Liquor 1

2025-11-25
CVE-2025-13578
Analyzed
7.3
code-projects Library System

A vulnerability has been found in code-projects Library System 1

2025-11-25
CVE-2025-13572
Analyzed
7.3
projectworlds Advanced Library Management System

A vulnerability was identified in projectworlds Advanced Library Management System 1

2025-11-23
CVE-2025-13563
Analyzed
9.8
BuddhaThemes Lizza LMS Pro

The Lizza LMS Pro plugin for WordPress is vulnerable to privilege escalation, enabling unauthenticated attackers to register as administrators and tak...

2026-02-20
CVE-2025-13562
Analyzed
7.3
D-Link DIR-852

A vulnerability was identified in D-Link DIR-852 1

2025-11-23
CVE-2025-13561
Analyzed
7.3
SourceCodester Company Website CMS

A vulnerability was determined in SourceCodester Company Website CMS 1

2025-11-23
CVE-2025-13560
Analyzed
7.3
SourceCodester Company Website CMS

A vulnerability was found in SourceCodester Company Website CMS 1

2025-11-23
CVE-2025-13559
Analyzed
9.8
venusweb EduKart Pro

The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'edukart_pr...

2025-11-26
CVE-2025-13557
Analyzed
7.3
Campcodes Online Polling System

A vulnerability has been found in Campcodes Online Polling System 1

2025-11-23
CVE-2025-13556
Analyzed
7.3
Campcodes Online Polling System

A flaw has been found in Campcodes Online Polling System 1

2025-11-23
CVE-2025-13555
Analyzed
7.3
Campcodes School File Management System

A vulnerability was detected in Campcodes School File Management System 1

2025-11-23
CVE-2025-13554
Analyzed
7.3
Campcodes Supplier Management System

A security vulnerability has been detected in Campcodes Supplier Management System 1

2025-11-23
CVE-2025-13553
Analyzed
8.8
D-Link DWR-M920

A weakness has been identified in D-Link DWR-M920 1

2025-11-23
CVE-2025-13552
Analyzed
8.8
D-Link DIR-822K

A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1

2025-11-23
CVE-2025-13551
Analyzed
8.8
D-Link DIR-822K

A vulnerability was identified in D-Link DIR-822K and DWR-M920 1

2025-11-23
CVE-2025-13550
Analyzed
8.8
D-Link DIR-822K

A vulnerability was determined in D-Link DIR-822K and DWR-M920 1

2025-11-23
CVE-2025-13549
Analyzed
8.8
D-Link DIR-822K

A vulnerability was found in D-Link DIR-822K 1

2025-11-23
CVE-2025-13548
Analyzed
8.8
D-Link DIR-822K

A vulnerability has been found in D-Link DIR-822K and DWR-M920 1

2025-11-23
CVE-2025-13547
Analyzed
8.8
D-Link DIR-822K

A flaw has been found in D-Link DIR-822K and DWR-M920 1

2025-11-23
CVE-2025-13543
Analyzed
8.8
rtowebsites PostGallery

The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class...

2025-12-05
CVE-2025-13542
Analyzed
9.8
designthemes DesignThemes LMS

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms...

2025-12-04
CVE-2025-13540
Analyzed
9.8
Qode Interactive Tiare Membership

The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_m...

2025-11-28
CVE-2025-13539
Analyzed
9.8
Elated Themes FindAll Membership

The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plu...

2025-11-28
CVE-2025-13538
Analyzed
9.8
Elated Themes FindAll Listing

The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'findal...

2025-11-28
CVE-2025-13536
Analyzed
8.8
Blubrry PowerPress Podcasting plugin by Blubrry

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, an...

2025-11-28
CVE-2025-13526
Analyzed
7.5
walterpinem OneClick Chat to Order

The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1

2025-11-23
CVE-2025-13523
Analyzed
7.7
Mattermost Mattermost Confluence Plugin

Mattermost Confluence plugin version <1

2026-02-07
CVE-2025-13516
Analyzed
8.1
brainstormforce

The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and includi...

2025-12-03
CVE-2025-13506
Analyzed
8.8
Nebim Neyir Computer Industry and Services Nebim V3 ERP

Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc

2025-12-13
CVE-2025-13502
Analyzed
7.5
The WebKitGTK Team webkitgtk

A flaw was found in WebKitGTK and WPE WebKit

2025-11-26
CVE-2025-13499
Analyzed
7.8
Wireshark Foundation Wireshark

Kafka dissector crash in Wireshark 4

2025-11-22
CVE-2025-13493
Analyzed
7.5
webrndexperts Latest Registered Users

The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, and including, 1

2026-01-08
CVE-2025-13486
Analyzed
9.8
hwk-fr Advanced Custom Fields: Extended

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_f...

2025-12-03
CVE-2025-13485
Analyzed
7.3
itsourcecode Online File Management System

A security flaw has been discovered in itsourcecode Online File Management System 1

2025-11-22
CVE-2025-13481
Analyzed
8.8
IBM Aspera Orchestrator

IBM Aspera Orchestrator 4

2025-12-12
CVE-2025-13479
Analyzed
7.5
PosCube Hardware Software and Consulting QR Menu

Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd

2026-05-22
CVE-2025-13477
Analyzed
7.1
Digital Operations Services WifiBurada

Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services I...

2026-05-22
CVE-2025-13474
Analyzed
7.5
Menulux Software Mobile App

Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc

2025-12-17
CVE-2025-13470
Analyzed
7.5
Ribose RNP

In RNP version 0

2025-11-22
CVE-2025-13457
Analyzed
7.5
WooCommerce WooCommerce Square

The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5

2026-01-10
CVE-2025-13455
Analyzed
7.8
Lenovo ThinkPlus FU100

A vulnerability was reported in ThinkPlus configuration software that could allow a local authenticated user to bypass ThinkPlus device authentication...

2026-01-16
CVE-2025-13451
Analyzed
7.3
SourceCodester Online Shop Project

A vulnerability was identified in SourceCodester Online Shop Project 1

2025-11-20
CVE-2025-13449
Analyzed
7.3
code-projects Online Shop Project

A vulnerability was found in code-projects Online Shop Project 1

2025-11-20
CVE-2025-13447
Analyzed
8.4
Progress Software LoadMaster

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” per...

2026-01-14