8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 4201-4250 of 8341 CVEs Page 85 of 167
CVE-2025-52823
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ovatheme Cube Portfolio allows SQL Injection

2025-08-14
CVE-2025-52820
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) a...

2025-08-14
CVE-2025-52819
8.5
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Envíos allows SQL Injection

2025-07-16
CVE-2025-52813
8.1
Unknown Multiple Products

Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels

2025-07-06
CVE-2025-52807
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCo...

2025-07-05
CVE-2025-52806
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in eyecix JobSearch allows PHP L...

2025-08-14
CVE-2025-52805
7.5
HP Multiple Products

Path Traversal vulnerability in VaultDweller Leyka allows PHP Local File Inclusion

2025-07-06
CVE-2025-52804
7.5
Unknown Multiple Products

Missing Authorization vulnerability in uxper Nuss allows Accessing Functionality Not Properly Constrained by ACLs

2025-07-16
CVE-2025-52803
7.5
Unknown Multiple Products

Missing Authorization vulnerability in uxper Sala allows Accessing Functionality Not Properly Constrained by ACLs

2025-07-16
CVE-2025-52801
7.3
VonStroheim Multiple Products

Missing Authorization vulnerability in VonStroheim TheBooking allows Accessing Functionality Not Properly Constrained by ACLs

2025-08-15
CVE-2025-52800
7.3
Unity Business Multiple Products

Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP allows Accessing Functionality Not Properly Constrained by...

2025-08-15
CVE-2025-52797
8.2
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap allows SQL Injection

2025-08-14
CVE-2025-52787
7.1
EZiHosting Tennis Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EZiHosting Tennis Court Bookings allows Reflecte...

2025-07-16
CVE-2025-52786
7.1
Kingdom Creation Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kingdom Creation Media Folder allows Reflected X...

2025-07-16
CVE-2025-52779
Analyzed
7.1
HP Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot html,php,xml etc pages allows Re...

2025-07-16
CVE-2025-52777
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmsMinds Pay with Contact Form 7 allows Reflecte...

2025-07-16
CVE-2025-52768
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Faith & Hope fai...

2025-12-19
CVE-2025-52761
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager allows Object Injection. This issue affects WP Funnel Manager: from n/a...

2025-08-28
CVE-2025-52758
9.1
Unknown Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicious Files.This issue affects Zi...

2025-10-23
CVE-2025-52756
7.4
Sayan Datta WP Last Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Remote Code...

2025-10-23
CVE-2025-52745
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Farm Agrico farm...

2025-12-19
CVE-2025-52741
Analyzed
9
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barry Kooij Post Connector post-connector allows...

2025-10-22
CVE-2025-52740
8.8
Hernan Villanueva Multiple Products

Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows Object Injection

2025-10-23
CVE-2025-52739
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS

2026-01-01
CVE-2025-52737
8.8
Tijmen Smit WP Store Multiple Products

Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator allows Object Injection

2025-10-22
CVE-2025-52735
7.3
XLPlugins NextMove Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextm...

2025-10-23
CVE-2025-52734
7.3
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ERA404 CropRefine croprefine allows Reflected XS...

2025-10-23
CVE-2025-52732
Analyzed
8.8
Google Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 Google Map Targeti...

2025-08-14
CVE-2025-52731
7.5
WordPress Multiple Products

Missing Authorization vulnerability in themefunction WordPress Event Manager, Event Calendar and Booking Plugin allows Exploiting Incorrectly Configur...

2025-08-14
CVE-2025-52728
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Pos...

2025-08-14
CVE-2025-52720
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder allows SQL Injecti...

2025-08-14
CVE-2025-52716
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acato WP REST Cache allows PH...

2025-08-14
CVE-2025-52714
Analyzed
9.3
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler allows SQL Injection. This i...

2025-07-16
CVE-2025-52694
Analyzed
10
Intel Multiple Products

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vul...

2026-01-12
CVE-2025-52692
8.8
Successful Multiple Products

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain admin...

2025-12-19
CVE-2025-52691
KEV Analyzed
10
HP Multiple Products

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, pot...

2025-12-29
CVE-2025-52690
8.1
Successful Multiple Products

Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confide...

2025-07-16
CVE-2025-52689
Analyzed
9.8
Unknown Multiple Products

Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with administrator privileges by spo...

2025-07-16
CVE-2025-52688
Analyzed
9.8
Unknown Multiple Products

Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the access point, potentially leading...

2025-07-16
CVE-2025-52670
7.1
Revive Multiple Products

Missing authorization check in Revive Adserver 5

2025-11-20
CVE-2025-52668
8.7
Unknown Multiple Products

Improper input neutralization in the stats-conversions

2025-11-20
CVE-2025-52665
Analyzed
10
Unknown Multiple Products

A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access, that expose...

2025-10-31
CVE-2025-52664
8.8
Revive Multiple Products

SQL injection in Revive Adserver 6

2025-10-31
CVE-2025-52656
7.6
HCL Multiple Products

HCL MyXalytics: 6

2025-10-03
CVE-2025-52653
7.6
Unknown Multiple Products

HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application

2025-10-03
CVE-2025-52650
8.2
Inline Multiple Products

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2

2025-10-10
CVE-2025-5261
7.5
Pik Online Multiple Products

Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A

2025-08-20
CVE-2025-5260
8.6
Unknown Multiple Products

Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A

2025-08-20
CVE-2025-52585
7.5
LTM Multiple Products

When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabl...

2025-08-14
CVE-2025-52584
Analyzed
7.8
Intel Multiple Products

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12

2025-08-19