8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 2251-2300 of 8341 CVEs Page 46 of 167
CVE-2025-63526
8.5
Unknown Multiple Products

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs

2025-12-02
CVE-2025-63525
Analyzed
9.6
HP Multiple Products

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted...

2025-12-02
CVE-2025-63469
7.5
TOTOLINK Multiple Products

Totolink LR350 v9

2025-10-31
CVE-2025-63468
7.5
TOTOLINK Multiple Products

Totolink LR350 v9

2025-10-31
CVE-2025-63465
7.5
TOTOLINK Multiple Products

Totolink LR350 v9

2025-10-31
CVE-2025-63464
7.5
TOTOLINK Multiple Products

Totolink LR350 v9

2025-10-31
CVE-2025-63455
7.5
Tenda Multiple Products

Tenda AX-3 v16

2025-11-11
CVE-2025-63453
Analyzed
9.8
HP Multiple Products

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.

2025-11-04
CVE-2025-63452
Analyzed
9.4
HP Multiple Products

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.

2025-11-04
CVE-2025-63451
Analyzed
9.8
HP Multiple Products

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.

2025-11-04
CVE-2025-63441
7.3
Open Multiple Products

Open Source Social Network (OSSN) 8

2025-11-04
CVE-2025-63434
Analyzed
8.8
Google Multiple Products

The update mechanism in Xtooltech Xtool AnyScan Android Application 4

2025-11-25
CVE-2025-63423
7.5
Each Multiple Products

Each Italy Wireless Mini Router WIRELESS-N 300M v28K

2025-10-30
CVE-2025-63422
7.5
Unknown Multiple Products

Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K

2025-10-30
CVE-2025-63417
7.2
Unknown Multiple Products

A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023

2025-11-06
CVE-2025-63414
Analyzed
10
HP Multiple Products

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execu...

2025-12-17
CVE-2025-63406
Analyzed
8.8
Microsoft Multiple Products

An issue in Intermesh BV GroupOffice vulnerable before v

2025-11-15
CVE-2025-63391
7.5
Unknown Multiple Products

An authentication bypass vulnerability exists in Open-WebUI <=0

2025-12-20
CVE-2025-63387
7.5
Dify Multiple Products

Dify v1

2025-12-20
CVE-2025-63371
7.5
Paripovic Multiple Products

Milos Paripovic OneCommander 3

2025-11-20
CVE-2025-63365
Analyzed
7.1
File Multiple Products

SoftSea EPUB File Reader 1

2025-12-02
CVE-2025-63363
7.5
Unknown Multiple Products

A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3

2025-12-06
CVE-2025-63314
Analyzed
10
Unknown Multiple Products

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user pass...

2026-01-13
CVE-2025-63307
8.1
Unknown Multiple Products

alexusmai laravel-file-manager 3

2025-11-06
CVE-2025-63298
8.2
Unknown Multiple Products

A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1

2025-10-30
CVE-2025-6327
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons allows Upload a Web Shell to a W...

2025-11-06
CVE-2025-6325
Analyzed
9.8
WordPress Multiple Products

Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Escalation.This issue affects Ki...

2025-11-06
CVE-2025-63248
7.5
DWSurvey Multiple Products

DWSurvey 6

2025-11-06
CVE-2025-63224
Analyzed
10
Unknown Multiple Products

The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a...

2025-11-21
CVE-2025-63223
9.8
Unknown Multiple Products

The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication...

2025-11-21
CVE-2025-63220
Analyzed
7.2
Unknown Multiple Products

The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package

2025-11-20
CVE-2025-63219
7.5
ITEL Multiple Products

The ITEL ISO FM SFN Adapter (firmware ISO2 2

2025-11-20
CVE-2025-63218
Analyzed
9.8
Unknown Multiple Products

The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticati...

2025-11-21
CVE-2025-63210
Analyzed
9.8
Unknown Multiple Products

The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can...

2025-11-21
CVE-2025-63209
Analyzed
7.5
Control Multiple Products

The ELCA Star Transmitter Remote Control firmware 1

2025-11-20
CVE-2025-63208
7.5
Unknown Multiple Products

An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5

2025-11-20
CVE-2025-63207
9.8
Unknown Multiple Products

The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication ch...

2025-11-21
CVE-2025-63206
9.8
Unknown Multiple Products

An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to...

2025-11-21
CVE-2025-63205
7.5
Unknown Multiple Products

An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production...

2025-11-20
CVE-2025-63076
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 Elements dt-...

2025-12-11
CVE-2025-63074
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 dt-the7 allo...

2025-12-11
CVE-2025-63062
Analyzed
7.6
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AndonDesign UDesign Core u-de...

2025-12-11
CVE-2025-63057
8.2
Roxnor Wp Ultimate Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review all...

2025-12-10
CVE-2025-63036
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DFDevelopment Ronneby Theme C...

2025-12-11
CVE-2025-63003
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required P...

2025-12-11
CVE-2025-62986
7.1
FanBridge FanBridge Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in FanBridge FanBridge signup fanbridge-signup allows Stored XSS

2025-10-27
CVE-2025-62980
Analyzed
8.8
MDZ Persian Admnin Multiple Products

Missing Authorization vulnerability in MDZ Persian Admnin Fonts persian-admin-fonts allows Exploiting Incorrectly Configured Access Control Security L...

2025-10-27
CVE-2025-6297
8.2
Unknown Multiple Products

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is...

2025-07-06
CVE-2025-62965
7.2
Unknown Multiple Products

Missing Authorization vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Exploiting Incorrectly Configured Access Contr...

2025-10-27
CVE-2025-62964
8.1
Unknown Multiple Products

Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control...

2025-10-27