24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 21601-21650 of 24021 CVEs Page 433 of 481
CVE-2025-12934
Analyzed
8.1
beaverbuilder

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capabi...

2025-12-24
CVE-2025-12929
Analyzed
7.3
SourceCodester Survey Application System

A flaw has been found in SourceCodester Survey Application System 1

2025-11-11
CVE-2025-12928
Analyzed
7.3
code-projects Online Job Search Engine

A vulnerability was detected in code-projects Online Job Search Engine 1

2025-11-11
CVE-2025-12925
Analyzed
7.3
rymcu forest

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224

2025-11-11
CVE-2025-12904
Analyzed
7.2
otacke SNORDIAN's H5PxAPIkatchu

The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up...

2025-11-15
CVE-2025-12903
Analyzed
7.5
paymentplugins Payment Plugins Braintree For WooCommerce

The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-b...

2025-11-14
CVE-2025-12886
Analyzed
7.2
Laborator Oxygen - WooCommerce WordPress Theme

The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6

2026-03-29
CVE-2025-12882
Analyzed
9.8
SmartDataSoft Clasifico Listing

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated users to register themselves with the 'admi...

2026-02-20
CVE-2025-12879
Analyzed
8.8
vinoth06 User Generator and Importer

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1

2025-12-06
CVE-2025-12871
Analyzed
9.8
aEnrich a+HRD

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access toke...

2025-11-13
CVE-2025-12870
Analyzed
9.8
aEnrich a+HRD

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain...

2025-11-13
CVE-2025-12868
Analyzed
9.8
CyberTutor New Site Server

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the...

2025-11-11
CVE-2025-12867
Analyzed
7.2
Hundred Plus EIP Plus

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell ba...

2025-11-11
CVE-2025-12866
Analyzed
9.8
Hundred Plus EIP Plus

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-...

2025-11-11
CVE-2025-12865
Analyzed
8.8
e-Excellence U-Office Force

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to...

2025-11-11
CVE-2025-12864
Analyzed
8.8
e-Excellence U-Office Force

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to...

2025-11-11
CVE-2025-12863
Analyzed
7.5
Unknown

A flaw was found in the xmlSetTreeDoc() function of the libxml2 XML parsing library

2025-11-08
CVE-2025-12851
Analyzed
8.1
wphocus My auctions allegro

The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3

2025-12-06
CVE-2025-12850
Analyzed
7.5
wphocus My auctions allegro

The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3

2025-12-06
CVE-2025-12846
Analyzed
8.8
creativethemeshq Blocksy Companion

The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2

2025-11-13
CVE-2025-12845
Analyzed
8.8
Essekia

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data th...

2026-02-20
CVE-2025-12844
Analyzed
7.1
tigroumeow

The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3

2025-11-14
CVE-2025-12840
Analyzed
7.8
Academy Software Foundation OpenEXR

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-12839
Analyzed
7.8
Academy Software Foundation OpenEXR

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

2025-12-24
CVE-2025-12835
Analyzed
7.3
WordPress WooMulti

The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any authenticated users, such as su...

2025-12-14
CVE-2025-12824
Analyzed
8.8
tharkun69 Player Leaderboard

The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2025-12-13
CVE-2025-12821
Analyzed
8.8
spicethemes NewsBlogger

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0

2026-02-20
CVE-2025-12819
Analyzed
7.5
PgBouncer PgBouncer

Untrusted search path in auth_query connection handler in PgBouncer before 1

2025-12-03
CVE-2025-12816
Analyzed
8.6
Digital Bazaar node-forge

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1

2025-11-26
CVE-2025-12805
Analyzed
8.1
Red Hat Red Hat OpenShift AI 2.25

A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator

2026-03-28
CVE-2025-12790
Analyzed
7.4
Nicholas J Humfrey ruby-mqtt

A flaw was found in Rubygem MQTT

2025-11-06
CVE-2025-12779
Analyzed
8.8
Amazon Amazon WorkSpaces

Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023

2025-11-06
CVE-2025-12775
Analyzed
8.8
nazsabuz WP Dropzone

The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 1

2025-11-19
CVE-2025-12771
Analyzed
7.8
IBM Concert

IBM Concert 1

2025-12-27
CVE-2025-12768
Analyzed
8.6
Rockwell Automation FactoryTalk® Historian Machine Edition

A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to a...

2026-09-02
CVE-2025-12765
Analyzed
7.5
pgadmin.org pgAdmin 4

pgAdmin <= 9

2025-11-14
CVE-2025-12764
Analyzed
7.5
pgadmin.org pgAdmin 4

pgAdmin <= 9

2025-11-14
CVE-2025-12762
Analyzed
9.1
pgadmin.org pgAdmin 4

pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores...

2025-11-14
CVE-2025-12758
Analyzed
7.5
Unknown validator

Versions of the package validator before 13

2025-11-28
CVE-2025-12744
Analyzed
8.8
Red Hat Red Hat Enterprise Linux 6

A flaw was found in the ABRT daemon’s handling of user-supplied mount information

2025-12-03
CVE-2025-12737
Analyzed
8.4
WSO2 WSO2 Open Banking AM

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious act...

2026-09-04
CVE-2025-12733
Analyzed
8.8
wpallimport

The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...

2025-11-14
CVE-2025-12726
Analyzed
7.5
Google Chrome

Inappropriate implementation in Views in Google Chrome on Windows prior to 142

2025-11-11
CVE-2025-1272
Analyzed
7.7
Fedora Project Fedora Linux

The Linux Kernel lockdown mode for kernel versions starting on 6

2026-02-19
CVE-2025-12716
Analyzed
8.7
GitLab GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18

2025-12-12
CVE-2025-12707
Analyzed
7.5
owthub Library Management System

The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3

2026-02-20
CVE-2025-12686
Analyzed
9.8
Synology BeeStation OS

A classic buffer overflow in Synology BeeStation OS AdminCenter allows remote attackers to execute arbitrary code via unspecified vectors.

2026-05-28
CVE-2025-12684
Analyzed
7.1
WordPress URL Shortify

The URL Shortify WordPress plugin before 1

2025-12-16
CVE-2025-12682
Analyzed
9.8
fahadmahmood Easy Upload Files During Checkout

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in t...

2025-11-04
CVE-2025-12664
Analyzed
7.5
GitLab GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13

2026-04-10