24021 Total CVEs
23926 AI Analyzed
338 CISA KEV
5516 Critical
All Vendors
Showing 21751-21800 of 24021 CVEs Page 436 of 481
CVE-2025-12235
Analyzed
8
Tenda CH22

A vulnerability was found in Tenda CH22 1

2025-10-27
CVE-2025-12234
Analyzed
8.8
Tenda CH22

A vulnerability has been found in Tenda CH22 1

2025-10-27
CVE-2025-12233
Analyzed
8.8
Tenda CH22

A flaw has been found in Tenda CH22 1

2025-10-27
CVE-2025-12232
Analyzed
8.8
Tenda CH22

A vulnerability was detected in Tenda CH22 1

2025-10-27
CVE-2025-12225
Analyzed
8.8
Tenda AC6

A vulnerability has been found in Tenda AC6 15

2025-10-27
CVE-2025-12215
Analyzed
7.3
projectworlds Online Shopping System

A flaw has been found in projectworlds Online Shopping System 1

2025-10-27
CVE-2025-12214
Analyzed
8.8
Tenda O3

A vulnerability was detected in Tenda O3 1

2025-10-27
CVE-2025-12213
Analyzed
8.8
Tenda O3

A security vulnerability has been detected in Tenda O3 1

2025-10-27
CVE-2025-12212
Analyzed
8.8
Tenda O3

A weakness has been identified in Tenda O3 1

2025-10-27
CVE-2025-12211
Analyzed
8.8
Tenda O3

A security flaw has been discovered in Tenda O3 1

2025-10-27
CVE-2025-12210
Analyzed
8.8
Tenda O3

A vulnerability was identified in Tenda O3 1

2025-10-27
CVE-2025-12209
Analyzed
8.8
Tenda O3

A vulnerability was determined in Tenda O3 1

2025-10-27
CVE-2025-12208
Analyzed
7.3
SourceCodester Best House Rental Management System

A vulnerability was found in SourceCodester Best House Rental Management System 1

2025-10-27
CVE-2025-12198
Analyzed
7.8
Unknown

A vulnerability has been found in dnsmasq up to 2

2025-10-27
CVE-2025-12197
Analyzed
7.5
stellarwp The Events Calendar

The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6

2025-11-06
CVE-2025-12181
Analyzed
8.8
contentstudio Contentstudio

The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function...

2025-12-06
CVE-2025-12171
Analyzed
8.8
anthonyeden RESTful Content Syndication

The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ingest_image()...

2025-11-01
CVE-2025-12166
Analyzed
7.5
croixhaug

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `orde...

2026-01-16
CVE-2025-12161
Analyzed
8.8
burhandodhy

The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creati...

2025-11-09
CVE-2025-12160
Analyzed
7.2
nmedia Simple User Registration

The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' parameter in all versions up to...

2025-11-22
CVE-2025-12158
Analyzed
9.8
tanvirahmed1984 Simple User Capabilities

The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabiliti...

2025-11-04
CVE-2025-12154
Analyzed
8.8
moderntribe Auto Thumbnailer

The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function in...

2025-12-06
CVE-2025-12153
Analyzed
8.8
tsaiid Featured Image via URL

The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions u...

2025-12-06
CVE-2025-12139
Analyzed
7.5
princeahmed

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all...

2025-11-06
CVE-2025-12138
Analyzed
8.8
bww URL Image Importer

The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, an...

2025-11-22
CVE-2025-12135
Analyzed
7.2
iqonicdesign WPBookit

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1

2025-11-22
CVE-2025-12121
Analyzed
7.3
Lite XL Lite XL

Lite XL versions 2

2025-11-20
CVE-2025-12120
Analyzed
7.3
Lite XL Lite XL

Lite XL versions 2

2025-11-20
CVE-2025-12115
Analyzed
7.5
WPClever WPC Name Your Price for WooCommerce

The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2

2025-10-31
CVE-2025-12107
Analyzed
10
WSO2 Identity Server

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template...

2026-02-20
CVE-2025-12106
Analyzed
9.1
OpenVPN OpenVPN

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

2025-12-02
CVE-2025-12105
Analyzed
7.5
GNOME libsoup

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/...

2025-10-23
CVE-2025-12100
Analyzed
7.8
MongoDB BI Connector ODBC Driver

Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation

2025-10-23
CVE-2025-12099
Analyzed
7.2
kodezen

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...

2025-11-09
CVE-2025-12097
Analyzed
7.5
NI LabVIEW

There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure

2025-12-05
CVE-2025-12082
Analyzed
7.5
Drupal CivicTheme Design System

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing

2025-10-30
CVE-2025-12062
Analyzed
8.8
flippercode Maps

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in...

2026-02-17
CVE-2025-12061
Analyzed
8.6
WordPress TAX SERVICE Electronic HDM

The TAX SERVICE Electronic HDM WordPress plugin before 1

2025-11-27
CVE-2025-12059
Analyzed
9.8
Logo Software Industry and Trade Logo j-Platform

Logo j-Platform is vulnerable to the insertion of sensitive information into externally accessible files due to incorrectly configured access control...

2026-02-12
CVE-2025-12057
Analyzed
9.8
WordPress WavePlayer

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally,...

2025-11-21
CVE-2025-12055
Analyzed
7.5
MPDV Mikrolab MIP 2

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance...

2025-10-27
CVE-2025-12048
Analyzed
7.5
Lenovo Scanner Pro

An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote co...

2025-11-14
CVE-2025-12046
Analyzed
7.8
Lenovo App Store

A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to exec...

2025-12-11
CVE-2025-12044
Analyzed
7.5
HashiCorp Vault

Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads

2025-10-23
CVE-2025-12036
Analyzed
8.8
Google Chrome

Out of bounds memory access in V8 in Google Chrome prior to 141

2025-11-08
CVE-2025-12029
Analyzed
8
GitLab GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15

2025-12-12
CVE-2025-12028
Analyzed
8.8
indieweb IndieAuth

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4

2025-10-24
CVE-2025-12008
Analyzed
8.8
APPYAP Technology and Information Yaay Social Media App

Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc

2026-05-15
CVE-2025-11995
Analyzed
7.2
jackdewey Community Events

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and includin...

2025-11-01
CVE-2025-11994
Analyzed
7.2
yudiz Easy Email Subscription

The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and incl...

2025-11-14