Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-58980 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Properly Constrained by ACL… | |
| CVE-2025-58981 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Cont… | |
| CVE-2025-58982 | MEDIUM | 5.9 | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline's Email Protector pixelines-email-protector allows S… | |
| CVE-2025-58983 | NONE | — | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Lissa Include Me include-me allows Stored XSS.This issue affec… | |
| CVE-2025-58984 | NONE | — | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issu… | |
| CVE-2025-58985 | NONE | — | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-… | |
| CVE-2025-58987 | NONE | — | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool football-pool allows Stored XSS.This issue affe… | |
| CVE-2025-58988 | NONE | — | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Dolson My Tickets my-tickets allows Stored XSS.This issue affects … | |
| CVE-2025-58989 | NONE | — | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 Dynamic Text Field For Contact Form 7 dynamic-text-fi… | |
| CVE-2025-58990 | MEDIUM | Patched | 5.4 | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems ShopLentor woolentor-addons allows Stored XSS.This issue affe… |
| CVE-2025-58991 | HIGH | 7.1 | 2025-09-09 | Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. This issue affects WooCommerce Booking Bundle Hours: … | |
| CVE-2025-58993 | NONE | — | 2025-09-09 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS tutor allows SQL Injection.This issue affects Tutor … | |
| CVE-2025-58997 | NONE | — | 2025-09-09 | Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/a through <= 4.10. | |
| CVE-2025-59005 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in frenify Categorify categorify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Categorify: … | |
| CVE-2025-59008 | NONE | — | 2025-09-09 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection zip-code-based-content-p… | |
| CVE-2025-5005 | HIGH | Patched | 7.3 | 2025-09-09 | A vulnerability was detected in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. This affects an unknown function of the file crm/WeiXinApp/dingtalk/ind… |
| CVE-2025-5500 | MEDIUM | 5.3 | 2025-09-09 | A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.xiaoxun.xunover… | |
| CVE-2025-10198 | HIGH | 7.8 | 2025-09-09 | Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH dir… | |
| CVE-2025-10199 | HIGH | 7.8 | 2025-09-09 | A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path. | |
| CVE-2025-57078 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the formModifyPppAuthWhiteMac function. This vulnerabili… |
| CVE-2025-57085 | CRITICAL | Patched | 9.8 | 2025-09-09 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Deni… |
| CVE-2025-57086 | HIGH | Patched | 7.5 | 2025-09-09 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to … |
| CVE-2025-57665 | MEDIUM | Patched | 6.4 | 2025-09-09 | Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-… |
| CVE-2025-9269 | NONE | — | 2025-09-09 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can be leveraged by an atta… | |
| CVE-2025-10164 | HIGH | 7.3 | 2025-09-09 | A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the function main of the file /update_weights_from_tensor. The manipulation of … |