8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 3151-3200 of 8341 CVEs Page 64 of 167
CVE-2025-58894
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Good Mood good-mo...

2025-12-19
CVE-2025-58893
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Alright alright a...

2025-12-19
CVE-2025-58892
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Tourimo tourimo...

2025-12-19
CVE-2025-58891
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Sanger sanger al...

2025-12-19
CVE-2025-58890
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Playful playful...

2025-12-19
CVE-2025-58889
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Towny towny allow...

2025-12-19
CVE-2025-58888
Analyzed
8.2
Adobe Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes The Flash thefla...

2025-12-19
CVE-2025-58885
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pathfinder pathf...

2025-12-19
CVE-2025-58881
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery allows Blind SQL Inj...

2025-09-05
CVE-2025-58879
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Festy festy allo...

2025-12-19
CVE-2025-58833
8.8
INVELITY Invelity Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in INVELITY Invelity MyGLS connect allows Object Injection

2025-09-05
CVE-2025-58819
Analyzed
9.1
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image allows Upload a Web Shell to a Web Server. This issue a...

2025-09-05
CVE-2025-58803
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Algenix algenix a...

2025-12-19
CVE-2025-58789
7.6
Themeisle WP Full Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free allows SQL Injecti...

2025-09-05
CVE-2025-58788
Analyzed
7.6
License Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce allow...

2025-09-05
CVE-2025-5878
7.3
SAP Multiple Products

A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic

2025-07-06
CVE-2025-58778
Analyzed
7.2
Ruijie Multiple Products

Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality

2025-10-16
CVE-2025-58777
7.8
Studio Multiple Products

VT Studio versions 8

2025-10-02
CVE-2025-58776
7.8
Studio Multiple Products

KV Studio versions 12

2025-10-02
CVE-2025-58775
Analyzed
7.8
STUDIO Multiple Products

KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability

2025-10-02
CVE-2025-58768
9.6
Intel Multiple Products

DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operati...

2025-09-09
CVE-2025-58766
9
Unknown Multiple Products

Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows atta...

2025-09-17
CVE-2025-58763
8
Media Multiple Products

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

2025-09-09
CVE-2025-58762
Analyzed
9.1
Unknown Multiple Products

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access...

2025-09-09
CVE-2025-58761
8.6
Media Multiple Products

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

2025-09-09
CVE-2025-58760
8.6
Media Multiple Products

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

2025-09-09
CVE-2025-58757
8.8
MONAI Multiple Products

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging

2025-09-09
CVE-2025-58756
8.8
MONAI Multiple Products

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging

2025-09-09
CVE-2025-58755
8.8
MONAI Multiple Products

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging

2025-09-09
CVE-2025-58754
Analyzed
7.5
HTTP Multiple Products

Axios is a promise based HTTP client for the browser and Node

2025-09-12
CVE-2025-58750
8.2
Unknown Multiple Products

rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server

2025-09-09
CVE-2025-58746
Analyzed
9
Unknown Multiple Products

The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdo...

2025-09-08
CVE-2025-58745
Analyzed
9.9
HP Multiple Products

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. Th...

2025-09-08
CVE-2025-58728
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58724
7.8
Microsoft Multiple Products

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58722
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58720
7.8
Microsoft Multiple Products

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information l...

2025-10-14
CVE-2025-58718
8.8
Unknown Multiple Products

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network

2025-10-14
CVE-2025-58716
8.8
Microsoft Multiple Products

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58715
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58714
7.8
Microsoft Multiple Products

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58710
8.6
Unknown Multiple Products

Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation

2025-12-19
CVE-2025-58692
8.8
Fortinet Multiple Products

An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] in Fortinet FortiVoice 7

2025-11-19
CVE-2025-58690
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect allows Stored XSS

2025-09-22
CVE-2025-58688
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support allows Stored XSS

2025-09-22
CVE-2025-58687
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin allows Stored XSS

2025-09-22
CVE-2025-58686
Analyzed
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows...

2025-09-22
CVE-2025-58677
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews allows Stored XSS

2025-09-22
CVE-2025-58676
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER allows Stored XSS

2025-09-22
CVE-2025-58671
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auction Feed allows Stored XSS

2025-09-22