8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 4701-4750 of 8341 CVEs Page 95 of 167
CVE-2025-48332
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks...

2025-08-14
CVE-2025-48325
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in shmish111 WP Admin Theme allows Stored XSS

2025-08-28
CVE-2025-48321
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget allows Stored XSS

2025-08-28
CVE-2025-48320
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in cuckoohello 百度分享按钮 allows Stored XSS

2025-08-28
CVE-2025-48317
Analyzed
7.5
Intel Multiple Products

Path Traversal vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay allows Path Traversal

2025-09-05
CVE-2025-48311
7.1
OffClicks Invisible Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in OffClicks Invisible Optin allows Stored XSS

2025-08-28
CVE-2025-48309
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in web-able BetPress allows Stored XSS

2025-08-28
CVE-2025-48308
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module allows Stored XSS

2025-08-28
CVE-2025-48307
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao SEO For Images allows Stored XSS

2025-08-28
CVE-2025-48306
7.1
Unknown Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner allows Stored XSS

2025-08-28
CVE-2025-48304
7.1
Google Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin allows Stored XSS

2025-08-28
CVE-2025-48302
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roxnor FundEngine allows PHP...

2025-08-20
CVE-2025-48301
7.6
YayCommerce SMTP Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid – YaySMTP allows S...

2025-07-16
CVE-2025-48300
Analyzed
9.1
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg allows Upload a Web Shell to a Web Server. This issue affects...

2025-07-16
CVE-2025-48299
7.6
YayCommerce YayExtra Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayExtra allows SQL Injection

2025-07-16
CVE-2025-48298
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for M...

2025-08-20
CVE-2025-48297
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory allows Reflec...

2025-08-20
CVE-2025-48296
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup UpStore allows Reflected XSS

2025-08-20
CVE-2025-48293
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dylan Kuhn Geo Mashup allows...

2025-08-14
CVE-2025-48291
7.1
Wasiliy Strecker Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker / ContestGallery developer Cont...

2025-07-16
CVE-2025-4828
9.8
WordPress Multiple Products

The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete functio...

2025-07-10
CVE-2025-4822
Analyzed
9.8
Unknown Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allo...

2025-07-25
CVE-2025-48208
8.8
Apache Multiple Products

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat

2025-09-10
CVE-2025-48171
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Cena Store allows PHP...

2025-08-20
CVE-2025-48170
7.1
LambertGroup Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player - Addon for...

2025-08-20
CVE-2025-48169
9.9
Unknown Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine allows Remote Code Inclusion. This issue affects Cod...

2025-08-20
CVE-2025-48168
7.1
LambertGroup Apollo Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Au...

2025-08-20
CVE-2025-48165
8.8
DELUCKS DELUCKS SEO Multiple Products

Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO allows Privilege Escalation

2025-08-20
CVE-2025-48164
8.8
Brainstorm Multiple Products

Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash allows Privilege Escalation

2025-08-20
CVE-2025-48163
7.1
LambertGroup SHOUT Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT - HTML5 Radio Player With Ads...

2025-08-20
CVE-2025-48162
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro allow...

2025-08-20
CVE-2025-48161
7.6
YayCommerce YaySMTP Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMTP allows SQL Injection

2025-07-16
CVE-2025-48160
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris allows PHP...

2025-08-20
CVE-2025-48159
7.1
LambertGroup Youtube Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtube Vimeo Video Player and Slid...

2025-08-20
CVE-2025-48158
8.6
Alex Githatu Multiple Products

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field al...

2025-08-20
CVE-2025-48157
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality allo...

2025-08-20
CVE-2025-48154
7.1
LambertGroup Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multimedia Playlist Slider Addon fo...

2025-08-20
CVE-2025-48153
7.1
Atakan Au Import Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images allows Stored XSS

2025-07-16
CVE-2025-48152
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dimafreund Rentsyst allows Reflected XSS

2025-08-20
CVE-2025-48151
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows R...

2025-08-20
CVE-2025-48149
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Cook&Meal allows PHP L...

2025-08-20
CVE-2025-48148
10
Unknown Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce allows Using Malicious Files. This issue...

2025-08-20
CVE-2025-48142
8.8
Saad Iqbal Bookify Multiple Products

Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify allows Privilege Escalation

2025-08-20
CVE-2025-48109
7.1
Xavier Media Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup allows Stored XSS

2025-08-28
CVE-2025-48107
7.1
Unknown Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode allows Reflected XSS

2025-09-26
CVE-2025-48106
10
Unknown Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious Files.This issue affects Clanor...

2025-10-23
CVE-2025-48101
Analyzed
8.8
WordPress Multiple Products

Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection

2025-09-09
CVE-2025-48100
Analyzed
9.1
Unknown Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator allows Remote Code Inclusion. This is...

2025-08-28
CVE-2025-48091
8.5
Alexander AnyComment Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injec...

2025-10-23
CVE-2025-48090
8.2
Path Multiple Products

Path Traversal: '

2025-11-06