23871 Total CVEs
23776 AI Analyzed
336 CISA KEV
5459 Critical
All Vendors
Showing 21651-21700 of 23871 CVEs Page 434 of 478
CVE-2025-11993
Analyzed
8.8
sbthemes WooCommerce Infinite Scroll and Ajax Pagination

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1

2026-05-29
CVE-2025-11985
Analyzed
8.8
NooTheme Realty Portal

The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capab...

2025-11-22
CVE-2025-11967
Analyzed
7.2
getwpfunnels

The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_contact_attribute_import...

2025-11-09
CVE-2025-11962
Analyzed
7.3
DivvyDrive Information Technologies Digital Corporate Warehouse

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc

2025-11-14
CVE-2025-11959
Analyzed
8.1
Premierturk Information Technologies Excavation Management Information System

Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk In...

2025-11-13
CVE-2025-11957
Analyzed
8.4
Devolutions Server

Improper authorization in the temporary access workflow of Devolutions Server 2025

2025-10-22
CVE-2025-11956
Analyzed
8.9
Proliz Software OBS (Student Affairs Information System)

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd

2025-11-06
CVE-2025-11954
Analyzed
8
Sitemio Information Technologies Trade WISECP

Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd

2026-05-21
CVE-2025-11953
KEV Analyzed
9.8
Unknown

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoi...

2025-11-04
CVE-2025-11949
Analyzed
7.5
Digiwin EasyFlow .NET

EasyFlow

2025-10-21
CVE-2025-11948
Analyzed
9.8
Excellent Infotek Document Management System

Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upl...

2025-10-20
CVE-2025-11943
Analyzed
7.3
70mai X200

A vulnerability has been found in 70mai X200 up to 20251010

2025-10-20
CVE-2025-11942
Analyzed
7.3
70mai X200

A flaw has been found in 70mai X200 up to 20251010

2025-10-20
CVE-2025-11940
Analyzed
7
Unknown LibreWolf

A security vulnerability has been detected in LibreWolf up to 143

2025-10-20
CVE-2025-11924
Analyzed
7.5
kstover

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up t...

2025-12-17
CVE-2025-11923
Analyzed
8.8
chrisbadgett

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation

2025-11-14
CVE-2025-11920
Analyzed
8.8
whyun WPCOM Member

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1

2025-11-01
CVE-2025-11919
Analyzed
9.6
Wolfram Research Cloud

A local file inclusion vulnerability in the Wolfram Cloud JVM initialization allows attackers to execute arbitrary code by manipulating shared tempora...

2026-06-27
CVE-2025-11900
Analyzed
9.8
HGiga iSherlock 4.5

The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands...

2025-10-17
CVE-2025-11899
Analyzed
8.1
Flowring Technology Agentflow

Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fix...

2025-10-17
CVE-2025-11898
Analyzed
7.5
Flowring Technology Agentflow

Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traver...

2025-10-17
CVE-2025-11890
Analyzed
7.5
beycanpress

The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1

2025-11-04
CVE-2025-11889
Analyzed
7.2
edgarrojas

The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the imp...

2025-10-24
CVE-2025-11877
Analyzed
7.5
solwininfotech User Activity Log

The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2

2026-01-08
CVE-2025-11864
Analyzed
7.3
NucleoidAI Nucleoid

A vulnerability was identified in NucleoidAI Nucleoid up to 0

2025-10-16
CVE-2025-11849
Analyzed
9.3
Unknown mammoth

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package...

2025-10-17
CVE-2025-11833
Analyzed
9.8
saadiqbal

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data d...

2025-11-01
CVE-2025-11797
Analyzed
7.8
Autodesk 3ds Max

A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability

2025-11-13
CVE-2025-11795
Analyzed
7.8
Autodesk 3ds Max

A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability

2025-11-13
CVE-2025-11789
Analyzed
7.5
SGE-PLC1000 SGE-PLC50 Circutor

Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9

2025-12-03
CVE-2025-11788
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited...

2025-12-04
CVE-2025-11787
Analyzed
8.8
SGE-PLC1000 SGE-PLC50 Circutor

Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9

2025-12-03
CVE-2025-11786
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter i...

2025-12-04
CVE-2025-11785
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user...

2025-12-04
CVE-2025-11784
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user...

2025-12-04
CVE-2025-11783
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copyi...

2025-12-04
CVE-2025-11782
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string...

2025-12-04
CVE-2025-11781
Analyzed
7.8
SGE-PLC1000 SGE-PLC50 Circutor

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9

2025-12-03
CVE-2025-11780
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user in...

2025-12-04
CVE-2025-11779
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applie...

2025-12-04
CVE-2025-11778
Analyzed
9.8
SGE-PLC1000 SGE-PLC50 Circutor

Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption thro...

2025-12-04
CVE-2025-11774
Analyzed
8.2
Mitsubishi Electric GENESIS64

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafte...

2025-12-19
CVE-2025-11756
Analyzed
8.8
Google Chrome

Use after free in Safe Browsing in Google Chrome prior to 141

2025-11-08
CVE-2025-11755
Analyzed
8.8
wpdelicious

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when impo...

2025-11-01
CVE-2025-11754
Analyzed
7.5
wplegalpages

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings'...

2026-02-20
CVE-2025-11746
Analyzed
8.8
8Theme Xstore

The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9

2025-10-15
CVE-2025-11735
Analyzed
7.5
RealMag777

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the `phrase` parameter in all v...

2025-10-28
CVE-2025-11733
Analyzed
7.2
lumiblog Footnotes Made Easy

The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3

2025-11-04
CVE-2025-11730
Analyzed
7.2
Zyxel ATP series firmware

A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from V...

2026-02-06
CVE-2025-11727
Analyzed
7.2
codisto

The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Si...

2025-12-05