8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 2151-2200 of 8341 CVEs Page 44 of 167
CVE-2025-64266
8.8
Rental Multiple Products

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object...

2025-12-19
CVE-2025-64236
9.8
Unknown Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: fro...

2025-12-19
CVE-2025-64233
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2....

2025-12-19
CVE-2025-64232
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icopydoc Import from YML import-from-yml allows...

2025-11-06
CVE-2025-64231
Analyzed
9.8
Google Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpr...

2025-12-19
CVE-2025-64227
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue aff...

2025-12-19
CVE-2025-64224
7.1
ThemeGoods Grand Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Conference Theme Custom Post Ty...

2025-11-06
CVE-2025-64216
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeSphere SmartMag smart-ma...

2025-10-29
CVE-2025-64206
9.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.

2025-12-19
CVE-2025-64205
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows...

2025-12-19
CVE-2025-64198
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Easy Social Share Buttons easy-social-s...

2025-11-06
CVE-2025-64196
7.1
Pluggabl Booster Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster for WooCommerce woocommerce-jet...

2025-11-06
CVE-2025-64195
Analyzed
7.6
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Eduma eduma allows...

2025-10-29
CVE-2025-64188
9.8
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <...

2025-12-19
CVE-2025-64186
8.7
Evervault Multiple Products

Evervault is a payment security solution

2025-11-13
CVE-2025-64184
Analyzed
8.8
Dosage Multiple Products

Dosage is a comic strip downloader and archiver

2025-11-08
CVE-2025-64180
Analyzed
10
Intel Multiple Products

Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorize...

2025-11-08
CVE-2025-64173
7.5
Apollo Multiple Products

Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation 2

2025-11-06
CVE-2025-64168
7.1
Agno Multiple Products

Agno is a multi-agent framework, runtime and control plane

2025-10-31
CVE-2025-64167
7.1
Combodo Multiple Products

Combodo iTop is a web based IT service management tool

2025-11-11
CVE-2025-64155
9.8
Fortinet Multiple Products

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3...

2026-01-14
CVE-2025-64140
Analyzed
8.8
Microsoft Multiple Products

Jenkins Azure CLI Plugin 0

2025-10-29
CVE-2025-64134
Analyzed
7.1
Jenkins Multiple Products

Jenkins JDepend Plugin 1

2025-10-29
CVE-2025-64131
Analyzed
7.5
Jenkins Multiple Products

Jenkins SAML Plugin 4

2025-10-29
CVE-2025-64130
Analyzed
9.8
Zenitel Multiple Products

Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript...

2025-11-27
CVE-2025-64129
Analyzed
7.6
Zenitel Multiple Products

Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the device

2025-11-27
CVE-2025-64128
Analyzed
10
HP Multiple Products

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting...

2025-11-27
CVE-2025-64127
Analyzed
10
Unknown Multiple Products

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are la...

2025-11-27
CVE-2025-64126
Analyzed
10
Unknown Multiple Products

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without...

2025-11-27
CVE-2025-64112
8
Statmatic Multiple Products

Statmatic is a Laravel and Git powered content management system (CMS)

2025-10-30
CVE-2025-64109
8.8
Cursor Multiple Products

Cursor is a code editor built for programming with AI

2025-11-06
CVE-2025-64104
Analyzed
7.3
LangGraph Multiple Products

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite)

2025-10-29
CVE-2025-64101
8.1
Zitadel Multiple Products

Zitadel is open-source identity infrastructure software

2025-10-29
CVE-2025-64096
Analyzed
8.8
CryptoLib Multiple Products

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications...

2025-10-30
CVE-2025-64095
Analyzed
10
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor...

2025-10-28
CVE-2025-64093
Analyzed
10
Unknown Multiple Products

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

2026-01-10
CVE-2025-64092
Analyzed
7.5
Unknown Multiple Products

This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database

2026-01-10
CVE-2025-64091
8.6
Unknown Multiple Products

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device

2026-01-10
CVE-2025-64090
Analyzed
10
Unknown Multiple Products

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

2026-01-10
CVE-2025-64081
Analyzed
9.8
HP Multiple Products

SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to ex...

2025-12-09
CVE-2025-64076
7.5
Unknown Multiple Products

Multiple vulnerabilities exist in cbor2 through version 5

2025-11-19
CVE-2025-64066
Analyzed
8.6
Primakon Multiple Products

Primakon Pi Portal 1

2025-11-26
CVE-2025-64065
Analyzed
8.8
Primakon Multiple Products

The Primakon Pi Portal 1

2025-11-27
CVE-2025-64064
Analyzed
8.8
Primakon Multiple Products

Primakon Pi Portal 1

2025-11-26
CVE-2025-64062
Analyzed
8.8
Primakon Multiple Products

The Primakon Pi Portal 1

2025-11-27
CVE-2025-64057
8.3
Unknown Multiple Products

Directory traversal vulnerability in Fanvil x210 V2 2

2025-12-06
CVE-2025-64053
8.2
Unknown Multiple Products

A Buffer overflow vulnerability on Fanvil x210 2

2025-12-06
CVE-2025-64050
Analyzed
7.2
HP Multiple Products

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5

2025-11-26
CVE-2025-6397
8.6
Ankara Hosting Multiple Products

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Hosting Website Design Website Sof...

2026-02-04
CVE-2025-63958
Analyzed
9.8
Unknown Multiple Products

MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication...

2025-11-25