24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 21551-21600 of 24021 CVEs Page 432 of 481
CVE-2025-13124
Analyzed
7.6
Netiket Information Technologies ApplyLogic

Authorization Bypass Through User-Controlled Key vulnerability in Netiket Information Technologies Ltd

2025-12-12
CVE-2025-13122
Analyzed
7.3
SourceCodester Patients Waiting Area Queue Management System

A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1

2025-11-14
CVE-2025-13121
Analyzed
7.3
cameasy Liketea

A security vulnerability has been detected in cameasy Liketea 1

2025-11-14
CVE-2025-13096
Analyzed
7.1
IBM Business Automation Workflow containers

IBM Business Automation Workflow containers V25

2026-02-03
CVE-2025-13094
Analyzed
8.8
wp3d WP3D Model Import Viewer

The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_fil...

2025-12-14
CVE-2025-13089
Analyzed
7.5
wpdirectorykit WP Directory Kit

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' parameter in all versions up to,...

2025-12-14
CVE-2025-13088
Analyzed
8.8
ikhodal Category and Product Woocommerce Tabs

The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2025-11-19
CVE-2025-13084
Analyzed
7.6
Opto 22 groov View Server

The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys

2025-11-27
CVE-2025-13077
Analyzed
7.5
payamito

The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'col...

2025-12-14
CVE-2025-13073
Analyzed
7.1
WordPress HandL UTM Grabber / Tracker

The HandL UTM Grabber / Tracker WordPress plugin before 2

2025-12-12
CVE-2025-13072
Analyzed
7.1
WordPress HandL UTM Grabber / Tracker

The HandL UTM Grabber / Tracker WordPress plugin before 2

2025-12-12
CVE-2025-13069
Analyzed
8.8
ideastocode Enable SVG, WebP, and ICO Upload

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1

2025-11-19
CVE-2025-13068
Analyzed
7.2
milmor Telegram Bot & Channel

The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username in all versions up to, and incl...

2025-11-26
CVE-2025-13067
Analyzed
8.8
wproyal

The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1

2026-03-11
CVE-2025-13066
Analyzed
8.8
kraftplugins Demo Importer Plus

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2

2025-12-06
CVE-2025-13065
Analyzed
8.8
brainstormforce

The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4

2025-12-07
CVE-2025-13063
Analyzed
7.3
DinukaNavaratna Dee Store

A flaw has been found in DinukaNavaratna Dee Store 1

2025-11-14
CVE-2025-13062
Analyzed
8.8
divisupreme

The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2

2026-01-16
CVE-2025-13060
Analyzed
7.3
SourceCodester Survey Application System

A security vulnerability has been detected in SourceCodester Survey Application System 1

2025-11-14
CVE-2025-13047
Analyzed
7.5
Bacteriology

Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers...

2025-11-14
CVE-2025-13046
Analyzed
7.5
Bacteriology

Bacteriology Laboratory Reporting System developed by ViewLead Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers...

2025-11-14
CVE-2025-13042
Analyzed
8.8
Google Chrome

Inappropriate implementation in V8 in Google Chrome prior to 142

2025-11-13
CVE-2025-13035
Analyzed
8
codesnippetspro Code Snippets

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3

2025-11-20
CVE-2025-13033
Analyzed
7.5
nodemailer nodemailer

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses

2025-11-15
CVE-2025-13030
Analyzed
7.1
All django-mdeditor

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint

2026-05-01
CVE-2025-13027
Analyzed
8.1
Mozilla Firefox

Memory safety bugs present in Firefox 144 and Thunderbird 144

2025-11-13
CVE-2025-13020
Analyzed
8.8
Mozilla Firefox

Use-after-free in the WebRTC: Audio/Video component

2025-11-13
CVE-2025-13019
Analyzed
8.1
Mozilla Firefox

Same-origin policy bypass in the DOM: Workers component

2025-11-13
CVE-2025-13018
Analyzed
8.1
Mozilla Firefox

Mitigation bypass in the DOM: Security component

2025-11-13
CVE-2025-13017
Analyzed
8.1
Mozilla Firefox

Same-origin policy bypass in the DOM: Notifications component

2025-11-13
CVE-2025-13014
Analyzed
8.8
Mozilla Firefox

Use-after-free in the Audio/Video component

2025-11-13
CVE-2025-13003
Analyzed
7.6
Aksis Computer Services and Consulting AxOnboard

Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc

2025-12-12
CVE-2025-13002
Analyzed
8.2
Farktor Software E-Commerce Services E-Commerce Package

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc

2026-02-13
CVE-2025-13000
Analyzed
7.7
WordPress db-access

The db-access WordPress plugin through 0

2025-12-03
CVE-2025-12995
Analyzed
8.1
Medtronic CareLink Network

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determin...

2025-12-05
CVE-2025-12985
Analyzed
8.4
IBM IBM Licensing Operator

IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running...

2026-01-21
CVE-2025-12981
Analyzed
9.8
dreamstechnologies Listee

The Listee theme for WordPress allows unauthenticated registration as an Administrator due to a broken validation check in the listee-core plugin's re...

2026-02-27
CVE-2025-12980
Analyzed
7.5
wpxpo

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthorized access of data due to a m...

2025-12-21
CVE-2025-12977
Analyzed
9.1
FluentBit Fluent Bit

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to w...

2025-11-25
CVE-2025-12974
Analyzed
8.1
Gravity Forms Gravity Forms

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechan...

2025-11-19
CVE-2025-12973
Analyzed
7.2
oc3dots

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing...

2025-11-22
CVE-2025-12970
Analyzed
8.8
FluentBit Fluent Bit

The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length

2025-11-25
CVE-2025-12968
Analyzed
8.8
infility Infility Global

The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all vers...

2025-12-13
CVE-2025-12967
Analyzed
8
AWS JDBC Wrapper

An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role

2025-11-11
CVE-2025-12966
Analyzed
8.8
plugins360 All-in-One Video Gallery

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_di...

2025-12-07
CVE-2025-12963
Analyzed
9.8
lazycoders

The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via ac...

2025-12-13
CVE-2025-12957
Analyzed
8.8
plugins360 All-in-One Video Gallery

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4

2026-01-16
CVE-2025-12956
Analyzed
8.7
Dassault Systèmes ENOVIA Collaborative Industry Innovator

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Releas...

2025-12-09
CVE-2025-12955
Analyzed
7.5
rajeshsingh520 PiWeb Live sales notification for WooCommerce

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2

2025-11-19
CVE-2025-12938
Analyzed
7.3
projectworlds Online Admission System

A vulnerability was identified in projectworlds Online Admission System 1

2025-11-11