583 Total CVEs
461 AI Analyzed
4 CISA KEV
214 Critical
All Vendors
Showing 1-583 of 583 CVEs
CVE-2026-25510
Analyzed
9.9
HP CMS Skeleton

An authenticated user with file editor permissions in CI4MS can achieve Remote Code Execution (RCE) by uploading and executing arbitrary PHP code via...

2026-02-04
CVE-2026-24897
Analyzed
10
HP Multiple Products

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files...

2026-01-29
CVE-2026-24765
Analyzed
7.8
HP Multiple Products

PHPUnit is a testing framework for PHP

2026-01-28
CVE-2026-24635
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edubl...

2026-01-24
CVE-2026-24609
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent...

2026-01-24
CVE-2026-24608
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core la...

2026-01-24
CVE-2026-23843
Analyzed
7.1
HP Multiple Products

teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients

2026-01-20
CVE-2026-23836
Analyzed
9.9
HP Multiple Products

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formu...

2026-01-20
CVE-2026-23722
Analyzed
9.1
HP Multiple Products

WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA s...

2026-01-17
CVE-2026-23593
Analyzed
7.5
HP Multiple Products

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view s...

2026-01-28
CVE-2026-23592
Analyzed
7.2
HP Multiple Products

Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code e...

2026-01-28
CVE-2026-23524
Analyzed
9.8
HP Multiple Products

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the...

2026-01-22
CVE-2026-22704
Analyzed
8
HP Multiple Products

HAX CMS helps manage microsite universe with PHP or NodeJs backends

2026-01-10
CVE-2026-22521
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in G5Theme Handmade Framework al...

2026-01-09
CVE-2026-21875
Analyzed
9.8
HP Multiple Products

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the add...

2026-01-08
CVE-2026-1331
Analyzed
9.8
HP Multiple Products

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execut...

2026-01-22
CVE-2026-1222
Analyzed
7.2
HP Multiple Products

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to uplo...

2026-01-20
CVE-2026-1160
Analyzed
7.3
HP Multiple Products

A security vulnerability has been detected in PHPGurukul Directory Management System 1

2026-01-20
CVE-2026-1056
Analyzed
9.8
HP Multiple Products

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dir...

2026-01-29
CVE-2026-1021
Analyzed
9.8
HP Multiple Products

Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload an...

2026-01-16
CVE-2026-0859
Analyzed
7.8
HP Multiple Products

TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized dur...

2026-01-15
CVE-2026-0761
Analyzed
9.8
HP Multiple Products

Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers t...

2026-01-23
CVE-2026-0726
Analyzed
8.1
HP Multiple Products

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4

2026-01-21
CVE-2025-9933
Analyzed
7.3
HP Multiple Products

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1

2025-09-04
CVE-2025-9932
Analyzed
7.3
HP Multiple Products

A flaw has been found in PHPGurukul Beauty Parlour Management System 1

2025-09-04
CVE-2025-9846
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command Inj...

2025-09-23
CVE-2025-9831
Analyzed
7.3
HP Multiple Products

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1

2025-09-02
CVE-2025-9830
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1

2025-09-02
CVE-2025-9829
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1

2025-09-02
CVE-2025-9814
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1

2025-09-02
CVE-2025-9501
Analyzed
9
HP Multiple Products

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated u...

2025-11-18
CVE-2025-9307
Analyzed
7.3
HP Multiple Products

A flaw has been found in PHPGurukul Online Course Registration 3

2025-08-21
CVE-2025-9302
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in PHPGurukul User Management System 1

2025-08-21
CVE-2025-9275
Analyzed
7.8
HP Multiple Products

Oxford Instruments Imaris Viewer IMS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

2025-09-02
CVE-2025-9274
Analyzed
7.8
HP Multiple Products

Oxford Instruments Imaris Viewer IMS File Parsing Uninitialized Pointer Remote Code Execution Vulnerability

2025-09-02
CVE-2025-9150
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317

2025-08-19
CVE-2025-8955
7.3
HP Multiple Products

A vulnerability has been found in PHPGurukul Hospital Management System 4

2025-08-15
CVE-2025-8954
7.3
HP Multiple Products

A vulnerability was identified in PHPGurukul Hospital Management System 4

2025-08-15
CVE-2025-8951
7.3
HP Multiple Products

A vulnerability has been found in PHPGurukul Teachers Record Management System 2

2025-08-15
CVE-2025-8450
Analyzed
8.2
HP Multiple Products

Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order...

2025-08-19
CVE-2025-8431
Analyzed
7.3
HP Multiple Products

A vulnerability has been found in PHPGurukul Boat Booking System 1

2025-08-01
CVE-2025-8417
Analyzed
8.1
HP Multiple Products

The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5

2025-09-12
CVE-2025-8356
Analyzed
9.8
HP Multiple Products

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead...

2025-08-08
CVE-2025-8323
Analyzed
8.8
HP Multiple Products

The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoor...

2025-07-30
CVE-2025-8289
Analyzed
7.5
HP Multiple Products

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3

2025-08-20
CVE-2025-8179
7.3
HP Multiple Products

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2

2025-07-28
CVE-2025-8145
Analyzed
8.8
HP Multiple Products

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3

2025-08-20
CVE-2025-7757
Analyzed
7.3
HP Multiple Products

A vulnerability classified as critical was found in PHPGurukul Land Record System 1

2025-07-17
CVE-2025-7604
Analyzed
7.3
HP Multiple Products

A vulnerability was found in PHPGurukul Hospital Management System 4

2025-07-14
CVE-2025-7542
Analyzed
7.3
HP Multiple Products

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3

2025-07-14
CVE-2025-7534
Analyzed
7.3
HP Multiple Products

A vulnerability was found in PHPGurukul Student Result Management System 2

2025-07-14
CVE-2025-7521
Analyzed
7.3
HP Multiple Products

A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1

2025-07-14
CVE-2025-7514
Analyzed
7.3
HP Multiple Products

A vulnerability was found in code-projects Modern Bag 1

2025-07-14
CVE-2025-7384
Analyzed
9.8
HP Multiple Products

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includ...

2025-08-13
CVE-2025-70893
Analyzed
8.8
HP Multiple Products

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1

2026-01-16
CVE-2025-70892
Analyzed
9.8
HP Multiple Products

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly v...

2026-01-16
CVE-2025-69342
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Calafate calafate a...

2026-01-07
CVE-2025-69200
Analyzed
7.5
HP Multiple Products

phpMyFAQ is an open source FAQ web application

2025-12-30
CVE-2025-69087
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes FreeAgent allows PH...

2026-01-06
CVE-2025-69086
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Jwsthemes Issabella allows PH...

2026-01-07
CVE-2025-69083
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Frappé allows P...

2026-01-07
CVE-2025-69081
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Group Hope charity-i...

2026-01-08
CVE-2025-69080
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko allows PHP Lo...

2026-01-08
CVE-2025-69039
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allo...

2026-01-24
CVE-2025-68996
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Pos...

2025-12-31
CVE-2025-68987
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama - A Word...

2025-12-31
CVE-2025-68985
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP...

2025-12-31
CVE-2025-68984
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Puca puca allows PHP...

2025-12-31
CVE-2025-68983
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart a...

2025-12-31
CVE-2025-68974
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social L...

2025-12-31
CVE-2025-68897
Analyzed
9.9
HP Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode allows Code Injection.This issue affects...

2025-12-30
CVE-2025-6888
7.3
HP Multiple Products

A vulnerability was found in PHPGurukul Teachers Record Management System 2

2025-07-06
CVE-2025-68877
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CedCommerce CedCommerce Integ...

2025-12-30
CVE-2025-68870
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in reDim GmbH CookieHint WP allo...

2025-12-30
CVE-2025-6885
7.3
HP Multiple Products

A vulnerability, which was classified as critical, was found in PHPGurukul Teachers Record Management System 2

2025-07-06
CVE-2025-68668
Analyzed
9.9
HP Multiple Products

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node...

2025-12-27
CVE-2025-6863
7.3
HP Multiple Products

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2

2025-07-06
CVE-2025-68563
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Unloc...

2025-12-25
CVE-2025-68562
Analyzed
9.9
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG:...

2025-12-30
CVE-2025-68560
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elem...

2025-12-24
CVE-2025-68546
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Thembay Nika allows PHP Local...

2025-12-24
CVE-2025-68544
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Thembay Diza allows PHP Local...

2025-12-24
CVE-2025-68540
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP...

2025-12-25
CVE-2025-68537
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP...

2025-12-25
CVE-2025-68530
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Bookory bookory al...

2025-12-25
CVE-2025-68506
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache do...

2025-12-25
CVE-2025-68434
Analyzed
8.8
HP Multiple Products

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework

2025-12-18
CVE-2025-68147
Analyzed
8.1
HP Multiple Products

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework

2025-12-18
CVE-2025-68109
Analyzed
9.1
HP Multiple Products

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or...

2025-12-18
CVE-2025-68068
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm stock...

2025-12-17
CVE-2025-68067
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm Core...

2025-12-17
CVE-2025-68066
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad a...

2025-12-17
CVE-2025-68065
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LiquidThemes Hub Core hub-cor...

2025-12-17
CVE-2025-68062
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog a...

2025-12-17
CVE-2025-68061
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall all...

2025-12-17
CVE-2025-68038
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Object Injection.This issue affects Ic...

2025-12-25
CVE-2025-67937
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon a...

2026-01-09
CVE-2025-67936
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly all...

2026-01-09
CVE-2025-67935
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimi...

2026-01-09
CVE-2025-67934
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring well...

2026-01-09
CVE-2025-67925
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zozothemes Corpkit corpkit al...

2026-01-09
CVE-2025-67920
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Neo Ocular neoo...

2026-01-09
CVE-2025-67510
Analyzed
9.4
HP Multiple Products

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided b...

2025-12-11
CVE-2025-67509
Analyzed
8.2
HP Multiple Products

Neuron is a PHP framework for creating and orchestrating AI Agents

2025-12-11
CVE-2025-67504
Analyzed
9.1
HP Multiple Products

WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwords using PHP's rand(). rand()...

2025-12-10
CVE-2025-6742
Analyzed
7.5
HP Multiple Products

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...

2025-07-11
CVE-2025-67289
Analyzed
9.6
HP Multiple Products

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading...

2025-12-23
CVE-2025-67164
Analyzed
9.9
HP Multiple Products

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary co...

2025-12-18
CVE-2025-6715
Analyzed
9.8
HP Multiple Products

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to...

2025-08-13
CVE-2025-67147
Analyzed
9.8
HP Multiple Products

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1)...

2026-01-13
CVE-2025-67146
Analyzed
9.4
HP Multiple Products

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) traine...

2026-01-13
CVE-2025-66802
Analyzed
9.8
HP Multiple Products

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into i...

2026-01-13
CVE-2025-66299
Analyzed
8.8
HP Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-66131
Analyzed
9.1
HP Multiple Products

Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc allows Exploiting Incorrectly Con...

2025-12-17
CVE-2025-66029
Analyzed
7.6
HP Multiple Products

Open OnDemand provides remote web access to supercomputers

2025-12-18
CVE-2025-65875
8.8
HP file

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1

2026-02-04
CVE-2025-65656
9.8
HP Multiple Products

dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

2025-12-04
CVE-2025-65473
Analyzed
9.1
HP Multiple Products

An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privil...

2025-12-12
CVE-2025-65358
9.8
HP Multiple Products

Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

2025-12-04
CVE-2025-65354
Analyzed
9.8
HP Multiple Products

Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST par...

2025-12-24
CVE-2025-64767
Analyzed
9.1
HP Multiple Products

hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, the public SenderContext Seal()...

2025-11-22
CVE-2025-6464
7.5
HP Multiple Products

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up...

2025-07-06
CVE-2025-64519
Analyzed
8.8
HP Multiple Products

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php

2025-11-11
CVE-2025-64500
7.3
HP Multiple Products

Symfony is a PHP framework for web and console applications and a set of reusable PHP components

2025-11-14
CVE-2025-64360
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Ele...

2025-10-31
CVE-2025-64359
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting con...

2025-10-31
CVE-2025-64287
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Alloggio - Hotel...

2025-11-06
CVE-2025-64284
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Sup...

2025-10-29
CVE-2025-64216
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeSphere SmartMag smart-ma...

2025-10-29
CVE-2025-64205
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows...

2025-12-19
CVE-2025-64195
Analyzed
7.6
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Eduma eduma allows...

2025-10-29
CVE-2025-64128
Analyzed
10
HP Multiple Products

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting...

2025-11-27
CVE-2025-64081
Analyzed
9.8
HP Multiple Products

SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to ex...

2025-12-09
CVE-2025-64050
Analyzed
7.2
HP Multiple Products

A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5

2025-11-26
CVE-2025-63889
Analyzed
7.5
HP Multiple Products

The fetch function in file thinkphp\library\think\Template

2025-11-20
CVE-2025-63689
Analyzed
10
HP Multiple Products

Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remot...

2025-11-08
CVE-2025-63622
Analyzed
9.8
HP Multiple Products

A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/admin/subcategory.ph...

2025-10-30
CVE-2025-63611
Analyzed
8.7
HP Multiple Products

Cross-Site Scripting in phpgurukul Hostel Management System v2

2026-01-09
CVE-2025-63535
Analyzed
9.6
HP Multiple Products

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize...

2025-12-02
CVE-2025-63532
Analyzed
9.6
HP Multiple Products

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly saniti...

2025-12-02
CVE-2025-63531
Analyzed
10
HP Multiple Products

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly...

2025-12-02
CVE-2025-63525
Analyzed
9.6
HP Multiple Products

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted...

2025-12-02
CVE-2025-63453
Analyzed
9.8
HP Multiple Products

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.

2025-11-04
CVE-2025-63452
Analyzed
9.4
HP Multiple Products

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.

2025-11-04
CVE-2025-63451
Analyzed
9.8
HP Multiple Products

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.

2025-11-04
CVE-2025-63414
Analyzed
10
HP Multiple Products

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execu...

2025-12-17
CVE-2025-6327
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons allows Upload a Web Shell to a W...

2025-11-06
CVE-2025-63076
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 Elements dt-...

2025-12-11
CVE-2025-63074
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 dt-the7 allo...

2025-12-11
CVE-2025-63062
Analyzed
7.6
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AndonDesign UDesign Core u-de...

2025-12-11
CVE-2025-63036
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DFDevelopment Ronneby Theme C...

2025-12-11
CVE-2025-63003
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required P...

2025-12-11
CVE-2025-62959
Analyzed
9.1
HP Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Remote Cod...

2025-10-27
CVE-2025-62868
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows P...

2025-10-24
CVE-2025-62753
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MadrasThemes MAS Videos allow...

2025-12-31
CVE-2025-62606
Analyzed
8.8
HP Multiple Products

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view

2025-10-22
CVE-2025-62521
Analyzed
10
HP Multiple Products

ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's...

2025-12-18
CVE-2025-62519
Analyzed
7.2
HP Multiple Products

phpMyFAQ is an open source FAQ web application

2025-11-18
CVE-2025-62510
Analyzed
8.1
HP Multiple Products

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations

2025-10-20
CVE-2025-62509
Analyzed
8.1
HP Multiple Products

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations

2025-10-20
CVE-2025-62075
7.3
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ido Kobelkowsky Simple Paymen...

2025-11-06
CVE-2025-62067
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Savory savory

2025-11-06
CVE-2025-62066
7.4
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Revolution revolut...

2025-11-06
CVE-2025-62055
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Academist acade...

2025-11-06
CVE-2025-62054
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez Theme - Fun...

2025-10-23
CVE-2025-62053
8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez

2025-11-06
CVE-2025-62045
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elem...

2025-11-06
CVE-2025-62029
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themesion Grevo grevo

2025-10-23
CVE-2025-62014
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme ITok itok

2025-11-08
CVE-2025-62010
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Famita famita allow...

2025-11-08
CVE-2025-61934
Analyzed
10
HP Multiple Products

A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an una...

2025-10-23
CVE-2025-61913
Analyzed
9.9
HP Multiple Products

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in...

2025-10-09
CVE-2025-61481
Analyzed
10
HP Multiple Products

An issue in MikroTik RouterOS v.7.14.2 and SwitchOS v.2.18 allows a remote attacker to execute arbitrary code via the HTTP- only WebFig management com...

2025-10-27
CVE-2025-61455
Analyzed
9.8
HP Multiple Products

SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorpor...

2025-10-20
CVE-2025-61247
Analyzed
8.2
HP Multiple Products

indieka900 online-shopping-system-php 1

2025-10-27
CVE-2025-61246
9.8
HP Multiple Products

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

2026-01-09
CVE-2025-61168
Analyzed
9.8
HP Multiple Products

An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

2025-11-26
CVE-2025-60786
Analyzed
8.8
HP Multiple Products

A Zip Slip vulnerability in the import a Project component of iceScrum v7

2025-12-16
CVE-2025-60736
9.8
HP Multiple Products

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

2025-12-04
CVE-2025-60316
Analyzed
9.4
HP Multiple Products

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.

2025-10-10
CVE-2025-60248
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options...

2025-11-08
CVE-2025-60241
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce premmerce...

2025-11-08
CVE-2025-60240
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alexander AnyComment anycomme...

2025-11-08
CVE-2025-60225
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue affects BugsPatrol: from n/a...

2025-10-22
CVE-2025-60219
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro allows Upload a Web Shell to a Web Server. This is...

2025-09-26
CVE-2025-60210
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.T...

2025-10-23
CVE-2025-60204
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach WooCommerce Sto...

2025-11-06
CVE-2025-60203
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach Store Exporter...

2025-11-06
CVE-2025-60202
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kyle Phillips Favorites favor...

2025-11-06
CVE-2025-60201
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aguilatechnologies WP Custome...

2025-11-06
CVE-2025-60200
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress LearnPress Export I...

2025-11-06
CVE-2025-60199
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx InHype - Blog & Magazi...

2025-11-06
CVE-2025-60198
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Saxon - Viral Content...

2025-11-06
CVE-2025-60197
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in owenr88 Simple Contact Forms...

2025-11-06
CVE-2025-60196
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Clearblue Clearblue® Ovulatio...

2025-11-06
CVE-2025-60194
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Product S...

2025-11-06
CVE-2025-60193
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce User Role...

2025-11-06
CVE-2025-60192
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Wholesale...

2025-11-06
CVE-2025-60191
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Wishlist...

2025-11-06
CVE-2025-60190
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hinnerk Altenburg Immocaster...

2025-11-06
CVE-2025-60174
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.This...

2025-12-19
CVE-2025-60153
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe To Unlock...

2025-09-26
CVE-2025-60150
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe to Downlo...

2025-09-26
CVE-2025-60126
Analyzed
8.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider...

2025-09-26
CVE-2025-60091
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP...

2025-12-19
CVE-2025-60090
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gra...

2025-12-19
CVE-2025-60089
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects...

2025-12-19
CVE-2025-60075
Analyzed
7.1
HP Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS

2025-10-29
CVE-2025-60074
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Processby Lazy Load Optimizer...

2025-11-06
CVE-2025-60072
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Processby Anchor smooth scrol...

2025-12-19
CVE-2025-60063
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rosalinda rosalin...

2025-12-19
CVE-2025-60055
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Fabrica fabrica...

2025-12-19
CVE-2025-60054
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes OnLeash onleash...

2025-12-19
CVE-2025-60053
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MaxCube maxcube...

2025-12-19
CVE-2025-60052
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes W&D wd allows PH...

2025-12-19
CVE-2025-60051
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Rare Radio rarer...

2025-12-19
CVE-2025-60050
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Panda panda allow...

2025-12-19
CVE-2025-60049
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Soleil soleil all...

2025-12-19
CVE-2025-5997
Analyzed
8.8
HP Multiple Products

Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse

2025-07-28
CVE-2025-59943
Analyzed
8.1
HP Multiple Products

phpMyFAQ is an open source FAQ web application

2025-10-03
CVE-2025-59939
Analyzed
8.8
HP Multiple Products

WeGIA is a Web manager for charitable institutions

2025-09-28
CVE-2025-59738
Analyzed
9.8
HP Multiple Products

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands...

2025-10-02
CVE-2025-59588
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad allows PH...

2025-09-22
CVE-2025-59564
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall all...

2025-10-23
CVE-2025-59558
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allow...

2025-10-23
CVE-2025-59555
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Medizin medizin all...

2025-10-23
CVE-2025-59550
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allo...

2025-10-23
CVE-2025-59465
7.5
HP Multiple Products

A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node

2026-01-21
CVE-2025-59304
Analyzed
9.8
HP Multiple Products

A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted...

2025-09-17
CVE-2025-58973
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hashthemes Easy Elementor Add...

2025-09-22
CVE-2025-58967
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Businext businext a...

2025-10-23
CVE-2025-58963
Analyzed
9.8
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a Web Server.This issue affects M...

2025-10-23
CVE-2025-58958
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepure...

2025-10-23
CVE-2025-58955
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Karzo karzo allo...

2025-10-22
CVE-2025-58947
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Athos athos allow...

2025-12-19
CVE-2025-58946
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Vocal vocal allow...

2025-12-19
CVE-2025-58945
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes EcoGrow ecogrow a...

2025-12-19
CVE-2025-58944
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Manufactory manuf...

2025-12-19
CVE-2025-58943
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Agricola agricola...

2025-12-19
CVE-2025-58942
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Dwell dwell allow...

2025-12-19
CVE-2025-58941
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Fabric fabric all...

2025-12-19
CVE-2025-58940
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Basil basil allow...

2025-12-19
CVE-2025-58932
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Prisma prisma all...

2025-12-19
CVE-2025-58931
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Palatio palatio a...

2025-12-19
CVE-2025-58930
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes FitFlex fitflex a...

2025-12-19
CVE-2025-58929
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Pantry pantry all...

2025-12-19
CVE-2025-58898
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes HealthHub health...

2025-12-19
CVE-2025-58896
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Otaku otaku allo...

2025-12-19
CVE-2025-58895
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Integro integro...

2025-12-19
CVE-2025-58894
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Good Mood good-mo...

2025-12-19
CVE-2025-58893
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Alright alright a...

2025-12-19
CVE-2025-58892
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Tourimo tourimo...

2025-12-19
CVE-2025-58891
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Sanger sanger al...

2025-12-19
CVE-2025-58890
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Playful playful...

2025-12-19
CVE-2025-58889
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Towny towny allow...

2025-12-19
CVE-2025-58885
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pathfinder pathf...

2025-12-19
CVE-2025-58879
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Festy festy allo...

2025-12-19
CVE-2025-58819
Analyzed
9.1
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image allows Upload a Web Shell to a Web Server. This issue a...

2025-09-05
CVE-2025-58803
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Algenix algenix a...

2025-12-19
CVE-2025-58745
Analyzed
9.9
HP Multiple Products

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. Th...

2025-09-08
CVE-2025-58637
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart all...

2025-09-03
CVE-2025-58608
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuddyDev MediaPress allows PH...

2025-09-03
CVE-2025-58462
Analyzed
9.8
HP Multiple Products

OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacke...

2025-09-09
CVE-2025-58215
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston allows PHP Loca...

2025-09-09
CVE-2025-58214
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri allows PHP Loc...

2025-09-05
CVE-2025-58206
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach allows PHP...

2025-09-05
CVE-2025-58159
Analyzed
9.9
HP Multiple Products

WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper...

2025-08-29
CVE-2025-58048
Analyzed
9.9
HP Multiple Products

Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a...

2025-08-28
CVE-2025-57925
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart Tea...

2025-09-22
CVE-2025-57889
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 InPost Gallery all...

2025-09-05
CVE-2025-57794
Analyzed
9.1
HP Multiple Products

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The applicat...

2026-01-29
CVE-2025-57567
Analyzed
9.1
HP Multiple Products

A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme...

2025-10-17
CVE-2025-57151
Analyzed
8.8
HP Multiple Products

phpgurukul Complaint Management System 2

2025-09-03
CVE-2025-57150
7.2
HP Multiple Products

phpgurukul Complaint Management System in PHP 2

2025-09-04
CVE-2025-57148
Analyzed
9.1
HP Multiple Products

phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.

2025-09-03
CVE-2025-57147
Analyzed
7.5
HP Multiple Products

A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2

2025-09-03
CVE-2025-57146
Analyzed
8.1
HP Multiple Products

phpgurukul Complaint Management System in PHP 2

2025-09-04
CVE-2025-57119
Analyzed
9.8
HP Multiple Products

An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function

2025-09-17
CVE-2025-56710
Analyzed
7.3
HP Multiple Products

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2

2025-09-15
CVE-2025-56265
Analyzed
8.8
HP Multiple Products

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1

2025-09-08
CVE-2025-56216
Analyzed
8.5
HP Multiple Products

phpgurukul Hospital Management System 4

2025-08-25
CVE-2025-56214
9.8
HP Multiple Products

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.

2025-08-26
CVE-2025-56212
9.8
HP Multiple Products

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.

2025-08-26
CVE-2025-56074
Analyzed
9.8
HP Multiple Products

A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. Th...

2025-09-22
CVE-2025-55849
Analyzed
8.4
HP Multiple Products

WeiPHP v5

2025-09-08
CVE-2025-55835
Analyzed
9.8
HP Multiple Products

File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.

2025-09-12
CVE-2025-55746
Analyzed
9.3
HP Multiple Products

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file upda...

2025-08-20
CVE-2025-55727
Analyzed
10
HP Multiple Products

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to versi...

2025-09-09
CVE-2025-55444
Analyzed
9.8
HP Multiple Products

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote att...

2025-08-21
CVE-2025-55287
Analyzed
8
HP Multiple Products

Genealogy is a family tree PHP application

2025-08-19
CVE-2025-54987
Analyzed
9.4
HP Multiple Products

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and e...

2025-08-05
CVE-2025-54948
KEV Analyzed
9.4
HP Multiple Products

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and e...

2025-08-05
CVE-2025-54762
Analyzed
9.8
HP Multiple Products

SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS co...

2025-08-28
CVE-2025-54750
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FunnelKit Funnel Builder by F...

2025-08-20
CVE-2025-54716
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ireca allows PHP Loc...

2025-08-28
CVE-2025-54713
Analyzed
9.8
HP Multiple Products

Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce allows Authentication Ab...

2025-08-20
CVE-2025-54709
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala

2025-09-09
CVE-2025-54701
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp allows PHP...

2025-08-14
CVE-2025-54700
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic allows P...

2025-08-14
CVE-2025-54693
Analyzed
9
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block allows Upload a Web Shell to a Web Server. This issue affects Form...

2025-08-14
CVE-2025-54690
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek Xinterio allows PHP...

2025-08-14
CVE-2025-54689
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna allows PHP Local...

2025-08-14
CVE-2025-54483
Analyzed
9.8
HP Multiple Products

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa...

2025-08-25
CVE-2025-54418
Analyzed
9.8
HP Multiple Products

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the...

2025-07-28
CVE-2025-54378
8.3
HP Multiple Products

HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends

2025-07-28
CVE-2025-54336
Analyzed
9.8
HP Multiple Products

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an at...

2025-08-19
CVE-2025-54138
Analyzed
7.5
HP Multiple Products

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating syst...

2025-07-23
CVE-2025-54119
Analyzed
10
HP Multiple Products

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper...

2025-08-05
CVE-2025-54052
7.5
HP Multiple Products

Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin allows PHP Local File Inclusion

2025-08-20
CVE-2025-54034
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Tribulant Software Newsletter...

2025-08-20
CVE-2025-54031
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board allows...

2025-08-20
CVE-2025-54028
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Saleswonder Team Tobias CF7 W...

2025-08-20
CVE-2025-54017
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cozmoslabs Paid Member Subscr...

2025-08-20
CVE-2025-53970
Analyzed
9.8
HP Multiple Products

SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS co...

2025-08-28
CVE-2025-53578
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso allows PHP Local...

2025-08-28
CVE-2025-53577
Analyzed
10
HP Multiple Products

Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS allows Remote Code Inclusion. This issue affects Global DN...

2025-08-20
CVE-2025-53576
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ovatheme Events allo...

2025-08-28
CVE-2025-53567
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Ghost Kit allows PHP Local...

2025-08-20
CVE-2025-53529
Analyzed
9.8
HP Multiple Products

WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionario/profile_funcionario.php end...

2025-07-07
CVE-2025-53484
9.8
HP Multiple Products

User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPagesTab() and getErrorsTab() (us...

2025-07-08
CVE-2025-53453
Analyzed
8.2
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Hygia hygia allow...

2025-12-19
CVE-2025-53450
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pluginwale Easy Pricing Table...

2025-09-22
CVE-2025-53433
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes EasyEat easyeat...

2025-12-19
CVE-2025-53429
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Exit Game exit-g...

2025-12-19
CVE-2025-53334
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah allows PHP Loc...

2025-08-28
CVE-2025-53328
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Assaf Parag Poll, Survey & Qu...

2025-08-28
CVE-2025-53326
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodeYatri Gutenify allows PHP...

2025-08-28
CVE-2025-53303
Analyzed
8.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core allows Object Injection

2025-09-09
CVE-2025-53248
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magazine allows PHP...

2025-08-28
CVE-2025-53247
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPInterface BlogMarks allows...

2025-08-28
CVE-2025-53244
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magazine Elite allow...

2025-08-28
CVE-2025-53227
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Unfoldwp Magazine Saga allows...

2025-08-28
CVE-2025-53216
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeUniver Glamer allows PHP...

2025-08-28
CVE-2025-53210
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in bdthemes ZoloBlocks allows PH...

2025-08-20
CVE-2025-53207
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel WP Travel Gutenberg...

2025-08-20
CVE-2025-53204
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme eventlist allows PHP...

2025-08-20
CVE-2025-53198
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP...

2025-08-20
CVE-2025-52807
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCo...

2025-07-05
CVE-2025-52806
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in eyecix JobSearch allows PHP L...

2025-08-14
CVE-2025-52805
7.5
HP Multiple Products

Path Traversal vulnerability in VaultDweller Leyka allows PHP Local File Inclusion

2025-07-06
CVE-2025-52779
Analyzed
7.1
HP Multiple Products

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot html,php,xml etc pages allows Re...

2025-07-16
CVE-2025-52768
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Faith & Hope fai...

2025-12-19
CVE-2025-52761
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager allows Object Injection. This issue affects WP Funnel Manager: from n/a...

2025-08-28
CVE-2025-52745
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Farm Agrico farm...

2025-12-19
CVE-2025-52728
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Pos...

2025-08-14
CVE-2025-52716
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acato WP REST Cache allows PH...

2025-08-14
CVE-2025-52691
KEV Analyzed
10
HP Multiple Products

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, pot...

2025-12-29
CVE-2025-52577
Analyzed
8.8
HP Multiple Products

A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet

2025-07-11
CVE-2025-5243
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabil...

2025-07-25
CVE-2025-52390
Analyzed
9.1
HP Multiple Products

Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method in...

2025-08-01
CVE-2025-52353
Analyzed
9.8
HP Multiple Products

An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP c...

2025-08-27
CVE-2025-52239
Analyzed
9.8
HP Multiple Products

An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.

2025-08-05
CVE-2025-52203
Analyzed
7.6
HP Multiple Products

A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1

2025-07-31
CVE-2025-52021
Analyzed
9.8
HP Multiple Products

A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter...

2025-10-08
CVE-2025-51958
Analyzed
9.8
HP Multiple Products

aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcomma...

2026-01-31
CVE-2025-51567
Analyzed
9.1
HP Multiple Products

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary...

2026-01-13
CVE-2025-50972
Analyzed
9.8
HP Multiple Products

SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index...

2025-08-27
CVE-2025-50870
Analyzed
9.8
HP Multiple Products

Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an em...

2025-08-01
CVE-2025-50722
Analyzed
9.8
HP Multiple Products

Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component

2025-08-25
CVE-2025-50707
Analyzed
9.8
HP Multiple Products

An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

2025-08-05
CVE-2025-50706
Analyzed
9.8
HP Multiple Products

An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function

2025-08-05
CVE-2025-50674
Analyzed
7.8
HP Multiple Products

An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user

2025-08-23
CVE-2025-50567
Analyzed
10
HP Multiple Products

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (ev...

2025-08-19
CVE-2025-49943
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Femme femme allo...

2025-12-19
CVE-2025-49942
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gardis gardis al...

2025-12-19
CVE-2025-49941
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes GlamChic glamchi...

2025-12-19
CVE-2025-49935
7.4
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allo...

2025-10-23
CVE-2025-49921
7.3
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CrocoBlock JetReviews jet-rev...

2025-10-23
CVE-2025-49405
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez allows PHP...

2025-08-28
CVE-2025-49401
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in ExpressTech Systems Quiz And Survey Master allows Object Injection. This issue affects Quiz And Sur...

2025-09-05
CVE-2025-49387
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms allows Upload a Web Shell t...

2025-08-28
CVE-2025-49383
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Neresa allows PHP L...

2025-08-28
CVE-2025-49371
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Strux strux allo...

2025-12-19
CVE-2025-49370
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Lymcoin lymcoin...

2025-12-19
CVE-2025-49369
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Lettuce lettuce...

2025-12-19
CVE-2025-49368
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Palladio palladi...

2025-12-19
CVE-2025-49367
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Monyxi monyxi al...

2025-12-19
CVE-2025-49366
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hanani hanani al...

2025-12-19
CVE-2025-49365
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Jack Well jack-w...

2025-12-19
CVE-2025-49364
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ludos Paradise l...

2025-12-19
CVE-2025-49363
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Kings & Queens k...

2025-12-19
CVE-2025-49362
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gracioza gracioz...

2025-12-19
CVE-2025-49361
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mamita mamita al...

2025-12-19
CVE-2025-49360
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Militarology mil...

2025-12-19
CVE-2025-49359
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ShieldGroup shie...

2025-12-19
CVE-2025-49271
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge T...

2025-08-14
CVE-2025-49264
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cloud Infrastructure Services...

2025-08-14
CVE-2025-49070
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi allows PHP L...

2025-07-06
CVE-2025-49060
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue aff...

2025-10-23
CVE-2025-49036
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addo...

2025-08-14
CVE-2025-48396
Analyzed
8.3
HP Multiple Products

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS

2025-11-04
CVE-2025-48338
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-...

2025-10-23
CVE-2025-48332
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks...

2025-08-14
CVE-2025-48302
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roxnor FundEngine allows PHP...

2025-08-20
CVE-2025-48300
Analyzed
9.1
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg allows Upload a Web Shell to a Web Server. This issue affects...

2025-07-16
CVE-2025-48298
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for M...

2025-08-20
CVE-2025-48293
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dylan Kuhn Geo Mashup allows...

2025-08-14
CVE-2025-48171
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Cena Store allows PHP...

2025-08-20
CVE-2025-48160
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris allows PHP...

2025-08-20
CVE-2025-48157
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality allo...

2025-08-20
CVE-2025-48149
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Cook&Meal allows PHP L...

2025-08-20
CVE-2025-47627
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail A...

2025-07-06
CVE-2025-47571
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder

2025-09-09
CVE-2025-4665
Analyzed
9.6
HP Multiple Products

WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injection vulnerability that cascades...

2025-10-29
CVE-2025-46384
Analyzed
8.8
HP Multiple Products

CWE-434 Unrestricted Upload of File with Dangerous Type

2025-07-21
CVE-2025-45805
7.6
HP Multiple Products

In phpgurukul Doctor Appointment Management System 1

2025-09-03
CVE-2025-45769
Analyzed
7.3
HP Multiple Products

php-jwt v6

2025-07-31
CVE-2025-45065
9.8
HP Multiple Products

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

2025-07-08
CVE-2025-44823
Analyzed
9.9
HP Multiple Products

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/syst...

2025-10-07
CVE-2025-4414
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content...

2025-07-06
CVE-2025-44137
Analyzed
8.2
HP Multiple Products

MapTiler Tileserver-php v2

2025-07-29
CVE-2025-44136
Analyzed
9.8
HP Multiple Products

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html enco...

2025-07-29
CVE-2025-41737
Analyzed
7.5
HP Multiple Products

Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules

2025-11-19
CVE-2025-41736
Analyzed
8.8
HP Multiple Products

A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resul...

2025-11-19
CVE-2025-41734
Analyzed
9.8
HP Multiple Products

An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.

2025-11-19
CVE-2025-40692
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-40691
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-40690
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-40689
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-40687
Analyzed
9.8
HP Multiple Products

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete databas...

2025-09-12
CVE-2025-37164
KEV Analyzed
10
HP Multiple Products

A remote code execution issue exists in HPE OneView.

2025-12-17
CVE-2025-37163
7.2
HP Multiple Products

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform

2025-11-19
CVE-2025-37127
Analyzed
7.2
HP Multiple Products

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to ga...

2025-09-16
CVE-2025-37126
Analyzed
7.2
HP Multiple Products

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run ar...

2025-09-16
CVE-2025-37125
7.5
HP Multiple Products

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS)

2025-09-16
CVE-2025-37124
Analyzed
8.6
HP Multiple Products

A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections

2025-09-16
CVE-2025-37123
Analyzed
8.8
HP Multiple Products

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to esca...

2025-09-16
CVE-2025-37107
Analyzed
7.3
HP Multiple Products

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-16
CVE-2025-37106
Analyzed
7.3
HP Multiple Products

An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-16
CVE-2025-37105
Analyzed
7.5
HP Multiple Products

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-16
CVE-2025-37104
7.1
HP Multiple Products

A security vulnerability has been identified in HPE Telco Service Orchestrator software

2025-07-16
CVE-2025-37103
9.8
HP Multiple Products

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device aut...

2025-07-08
CVE-2025-37099
Analyzed
9.8
HP Multiple Products

A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

2025-07-06
CVE-2025-37098
7.5
HP Multiple Products

A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7

2025-07-06
CVE-2025-37097
7.5
HP Multiple Products

A vulnerability in HPE Insight Remote Support (IRS) prior to v7

2025-07-06
CVE-2025-3703
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScript...

2025-08-14
CVE-2025-36846
Analyzed
9.8
HP Multiple Products

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated us...

2025-07-22
CVE-2025-32657
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slide...

2025-10-23
CVE-2025-32304
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP...

2026-01-07
CVE-2025-32288
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensio...

2025-08-14
CVE-2025-31048
Analyzed
9.9
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: fro...

2026-01-06
CVE-2025-30949
Analyzed
9.8
HP Multiple Products

Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram allows Object Injection. This issue affects Site Chat on Telegram:...

2025-07-16
CVE-2025-30635
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeAtelier IDonatePro allow...

2025-08-14
CVE-2025-29009
Analyzed
10
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce allows Upload a Web She...

2025-07-16
CVE-2025-28979
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PHP...

2025-08-14
CVE-2025-27724
Analyzed
9.3
HP Multiple Products

A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file...

2025-07-28
CVE-2025-27224
Analyzed
9.8
HP Multiple Products

TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the application doesn't properly sanitiz...

2025-10-28
CVE-2025-25174
Analyzed
10
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extensi...

2025-08-14
CVE-2025-25172
Analyzed
8.1
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidMov allows PHP...

2025-08-14
CVE-2025-24775
Analyzed
9.9
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms allows Upload a Web Shell to a Web Server. This issue affects Forms:...

2025-08-14
CVE-2025-24766
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Royal Themes News Magazine...

2025-08-14
CVE-2025-22712
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Typify typify al...

2026-01-09
CVE-2025-22708
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allow...

2026-01-09
CVE-2025-22707
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allo...

2026-01-09
CVE-2025-22509
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TMRW-studio Atlas atlas allow...

2026-01-09
CVE-2025-22470
Analyzed
9.8
HP Multiple Products

CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrary...

2025-08-07
CVE-2025-15457
Analyzed
7.3
HP Multiple Products

A vulnerability was found in bg5sbk MiniCMS up to 1

2026-01-05
CVE-2025-15456
Analyzed
7.3
HP Multiple Products

A vulnerability has been found in bg5sbk MiniCMS up to 1

2026-01-05
CVE-2025-15263
Analyzed
7.3
HP Multiple Products

A weakness has been identified in BiggiDroid Simple PHP CMS 1

2025-12-31
CVE-2025-15240
Analyzed
8.8
HP Multiple Products

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to...

2026-01-05
CVE-2025-15228
Analyzed
9.8
HP Multiple Products

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and exec...

2025-12-29
CVE-2025-15226
Analyzed
9.8
HP Multiple Products

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoo...

2025-12-29
CVE-2025-15142
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in 9786 phpok3w up to 901d96a06809fb28b17f3a4362c59e70411c933c

2025-12-29
CVE-2025-15067
Analyzed
7.7
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web Server

2025-12-29
CVE-2025-14926
Analyzed
7.8
HP Multiple Products

Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability

2025-12-24
CVE-2025-14509
Analyzed
7.2
HP Multiple Products

The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1

2025-12-31
CVE-2025-14502
Analyzed
9.8
HP Multiple Products

The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the templat...

2026-01-14
CVE-2025-14476
Analyzed
8.8
HP Multiple Products

The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1

2025-12-14
CVE-2025-14431
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in THEMELOGI Navian navian allow...

2026-01-09
CVE-2025-14430
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook - Agency Busi...

2026-01-09
CVE-2025-14429
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove AeroLand aeroland a...

2026-01-09
CVE-2025-14388
Analyzed
9.8
HP Multiple Products

The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including,...

2025-12-24
CVE-2025-14359
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in brandexponents Oshine oshin a...

2026-01-09
CVE-2025-14301
Analyzed
9.8
HP Multiple Products

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is du...

2026-01-14
CVE-2025-14091
7.3
HP Multiple Products

A weakness has been identified in TrippWasTaken PHP-Guitar-Shop up to 6ce0868889617c1975982aae6df8e49555d0d555

2025-12-06
CVE-2025-14071
Analyzed
7.5
HP Multiple Products

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2

2025-12-21
CVE-2025-14044
Analyzed
8.1
HP Multiple Products

The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1

2025-12-13
CVE-2025-13888
Analyzed
9.1
HP Multiple Products

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated perm...

2025-12-16
CVE-2025-13786
Analyzed
7.3
HP Multiple Products

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665

2025-12-01
CVE-2025-13773
Analyzed
9.8
HP Multiple Products

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5...

2025-12-24
CVE-2025-13675
Analyzed
9.8
HP Multiple Products

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.p...

2025-11-28
CVE-2025-13597
Analyzed
9.8
HP Multiple Products

The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all ve...

2025-11-26
CVE-2025-13595
Analyzed
9.8
HP Multiple Products

The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all...

2025-11-26
CVE-2025-13555
Analyzed
7.3
HP Multiple Products

A vulnerability was detected in Campcodes School File Management System 1

2025-11-23
CVE-2025-13247
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul Tourism Management System 1

2025-11-17
CVE-2025-13145
Analyzed
7.2
HP Multiple Products

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin...

2025-11-20
CVE-2025-13035
Analyzed
8
HP Multiple Products

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3

2025-11-20
CVE-2025-12867
Analyzed
7.2
HP Multiple Products

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell ba...

2025-11-11
CVE-2025-12844
Analyzed
7.1
HP Multiple Products

The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to, and including, 3

2025-11-14
CVE-2025-12550
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes OchaHouse ochahouse...

2026-01-09
CVE-2025-12549
Analyzed
9.8
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Rozy - Flower Shop...

2026-01-09
CVE-2025-12248
Analyzed
7.3
HP Multiple Products

A security vulnerability has been detected in CLTPHP 3

2025-10-27
CVE-2025-12099
Analyzed
7.2
HP Multiple Products

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...

2025-11-09
CVE-2025-11675
Analyzed
7.2
HP Multiple Products

Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute we...

2025-10-13
CVE-2025-11507
Analyzed
7.3
HP Multiple Products

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1

2025-10-08
CVE-2025-11506
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1

2025-10-08
CVE-2025-11505
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1

2025-10-08
CVE-2025-11503
Analyzed
7.3
HP Multiple Products

A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1

2025-10-08
CVE-2025-11416
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1

2025-10-07
CVE-2025-11415
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1

2025-10-07
CVE-2025-11053
Analyzed
7.3
HP Multiple Products

A weakness has been identified in PHPGurukul Small CRM 4

2025-09-28
CVE-2025-11023
Analyzed
9.8
HP Multiple Products

Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...

2025-10-23
CVE-2025-10967
Analyzed
7.3
HP Multiple Products

A vulnerability was detected in MuFen-mker PHP-Usermm up to 37f2d24e51b04346dfc565b93fc2fc6b37bdaea9

2025-09-25
CVE-2025-10664
Analyzed
7.3
HP Multiple Products

A vulnerability was determined in PHPGurukul Small CRM 4

2025-09-18
CVE-2025-10663
Analyzed
7.3
HP Multiple Products

A vulnerability was found in PHPGurukul Online Course Registration 3

2025-09-18
CVE-2025-10659
Analyzed
9.8
HP Multiple Products

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-suppl...

2025-09-30
CVE-2025-10624
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul User Management System 1

2025-09-18
CVE-2025-10604
Analyzed
7.3
HP Multiple Products

A vulnerability was identified in PHPGurukul Online Discussion Forum 1

2025-09-18
CVE-2025-10603
Analyzed
7.3
HP Multiple Products

A vulnerability was determined in PHPGurukul Online Discussion Forum 1

2025-09-18
CVE-2025-10484
Analyzed
9.8
HP Multiple Products

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a...

2026-01-17
CVE-2025-10459
Analyzed
7.3
HP Multiple Products

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1

2025-09-15
CVE-2025-10403
Analyzed
7.3
HP Multiple Products

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1

2025-09-14
CVE-2025-10402
Analyzed
7.3
HP Multiple Products

A flaw has been found in PHPGurukul Beauty Parlour Management System 1

2025-09-14
CVE-2025-10079
Analyzed
7.3
HP Multiple Products

A flaw has been found in PHPGurukul Small CRM 4

2025-09-08
CVE-2024-54263
Analyzed
7.5
HP Multiple Products

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allow...

2026-02-02
CVE-2024-51770
7.5
HP Multiple Products

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-15
CVE-2024-51769
Analyzed
7.5
HP Multiple Products

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-14
CVE-2024-51768
Analyzed
8
HP Multiple Products

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-14
CVE-2024-51767
Analyzed
7.3
HP Multiple Products

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9

2025-07-14
CVE-2024-45438
Analyzed
9.1
HP Multiple Products

An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within t...

2025-08-21
CVE-2024-44659
Analyzed
9.8
HP Multiple Products

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

2025-11-18
CVE-2024-44373
Analyzed
9.8
HP Multiple Products

A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution via the path...

2025-08-19
CVE-2024-44065
Analyzed
9.8
HP Multiple Products

Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in the qsoresults parameter.

2025-12-27
CVE-2024-14010
Analyzed
9.8
HP Multiple Products

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Atta...

2025-12-13
CVE-2024-13786
Analyzed
9.8
HP Multiple Products

The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted...

2025-07-05
CVE-2023-54339
Analyzed
9.8
HP Multiple Products

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter...

2026-01-14
CVE-2023-54335
Analyzed
9.8
HP Multiple Products

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request....

2026-01-14
CVE-2023-53980
Analyzed
9.8
HP Multiple Products

ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Atta...

2025-12-23
CVE-2023-53979
Analyzed
8.8
HP Multiple Products

MyBB 1

2025-12-23
CVE-2023-53971
Analyzed
8.8
HP Multiple Products

WebTareas 2

2025-12-23
CVE-2023-53963
Analyzed
9.8
HP Multiple Products

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary sh...

2025-12-23
CVE-2023-53957
Analyzed
9.8
HP Multiple Products

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers c...

2025-12-20
CVE-2023-53950
Analyzed
9.8
HP Multiple Products

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through...

2025-12-20
CVE-2023-53941
Analyzed
9.8
HP Multiple Products

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by in...

2025-12-19
CVE-2023-53930
Analyzed
9.8
HP Multiple Products

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipu...

2025-12-18
CVE-2023-53929
Analyzed
8.8
HP Multiple Products

phpMyFAQ 3

2025-12-18
CVE-2023-53927
Analyzed
8.8
HP Multiple Products

PHPJabbers Simple CMS 5

2025-12-18
CVE-2023-53926
Analyzed
9.8
HP Multiple Products

PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries...

2025-12-18
CVE-2023-53923
Analyzed
9.8
HP Multiple Products

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserCo...

2025-12-18
CVE-2023-53922
Analyzed
9.8
HP Multiple Products

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload m...

2025-12-18
CVE-2023-53921
Analyzed
9.8
HP Multiple Products

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. A...

2025-12-18
CVE-2023-53914
Analyzed
9.8
HP Multiple Products

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in t...

2025-12-18
CVE-2023-53894
Analyzed
9.8
HP Multiple Products

phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash valid...

2025-12-17
CVE-2023-50897
Analyzed
9.1
HP Multiple Products

Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Files.This issue affects Media Fi...

2026-01-06
CVE-2022-50912
9.8
HP Multiple Products

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. At...

2026-01-14
CVE-2022-50911
Analyzed
8.8
HP Multiple Products

Bitrix24 contains an authenticated remote code execution vulnerability that allows logged-in attackers to execute arbitrary system commands through th...

2026-01-14
CVE-2022-50905
Analyzed
9.8
HP Multiple Products

e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS tha...

2026-01-14
CVE-2022-50894
Analyzed
9.8
HP Multiple Products

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting S...

2026-01-14
CVE-2022-50893
Analyzed
9.8
HP Multiple Products

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a...

2026-01-14
CVE-2022-50794
Analyzed
9.8
HP Multiple Products

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers c...

2025-12-31
CVE-2022-50695
Analyzed
9.8
HP Multiple Products

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary ho...

2025-12-31
CVE-2022-50690
Analyzed
8.4
HP Multiple Products

Wondershare MirrorGo 2

2025-12-23
CVE-2021-47915
Analyzed
8.1
HP Multiple Products

PHP Melody version 3

2026-02-02
CVE-2021-47909
Analyzed
8.1
HP Multiple Products

Mult-E-Cart Ultimate 2

2026-02-02
CVE-2021-47900
Analyzed
9.8
HP Multiple Products

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system comma...

2026-01-28
CVE-2021-47853
Analyzed
8.8
HP Multiple Products

phpPgAdmin 7

2026-01-22
CVE-2021-47819
Analyzed
9.8
HP Multiple Products

ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code exec...

2026-01-16
CVE-2021-47760
Analyzed
9.8
HP Multiple Products

TestLink versions 1.16 through 1.19 contain an unauthenticated file download vulnerability in the attachmentdownload.php endpoint. Attackers can downl...

2026-01-16
CVE-2021-47753
Analyzed
9.8
HP Multiple Products

phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file...

2026-01-16
CVE-2020-37116
8.8
HP file to

GUnet OpenEclass 1

2026-02-04
CVE-2020-37113
8.8
HP file to

GUnet OpenEclass 1

2026-02-04
CVE-2020-37110
8.2
HP and common

60CycleCMS 2

2026-02-04
CVE-2020-37108
7.1
HP that allows

PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail

2026-02-04
CVE-2020-37105
7.1
HP endpoint with

PMB 5

2026-02-04
CVE-2020-37090
9.8
HP files to

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can uplo...

2026-02-04
CVE-2020-37088
7.5
HP Multiple Products

School ERP Pro 1

2026-02-04
CVE-2020-37083
8.2
HP AddressBook

PHP AddressBook 9

2026-02-04
CVE-2020-37081
7.1
HP that allow

Fishing Reservation System 7

2026-02-04
CVE-2020-37080
9.8
HP administration component

webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete...

2026-02-04
CVE-2020-37076
8.2
HP that allows

Victor CMS version 1

2026-02-04
CVE-2020-37073
8.8
HP files with

Victor CMS 1

2026-02-04
CVE-2020-37071
9.8
HP code through

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a c...

2026-02-04
CVE-2020-37035
Analyzed
8.2
HP Multiple Products

e-Learning PHP Script 0

2026-01-31
CVE-2020-37012
Analyzed
9.8
HP Multiple Products

Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /ap...

2026-01-30
CVE-2020-36997
Analyzed
9.8
HP Multiple Products

BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Handler (SEH) chain through malic...

2026-01-30
CVE-2020-36951
Analyzed
8.2
HP Multiple Products

Phpscript-sgh 0

2026-01-28
CVE-2020-26799
Analyzed
9.8
HP Multiple Products

A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal oth...

2025-07-22
CVE-2019-25260
8.2
HP code into

OXID eShop versions 6

2026-02-04
CVE-2017-20216
Analyzed
9.8
HP Multiple Products

FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFl...

2026-01-08
CVE-2016-10033
KEV Analyzed
9.5
HP PHPMailer

PHPMailer Command Injection Vulnerability - Recently added to CISA KEV.

2025-07-07
CVE-2014-125127
7.5
HP Multiple Products

The mikecao/flight PHP framework in versions prior to v1

2025-09-03
CVE-2012-10020
9.8
HP Multiple Products

The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions u...

2025-07-24
CVE-2011-10018
Analyzed
9.8
HP Multiple Products

myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitra...

2025-08-14