Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-10126 | MEDIUM | 6.4 | 2025-09-10 | The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' shortcode in all versions up to, and including, 1.0.8 due… | |
| CVE-2025-10142 | MEDIUM | 4.9 | 2025-09-10 | The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 4.44.3… | |
| CVE-2025-41714 | HIGH | 8.8 | 2025-09-10 | The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to creat… | |
| CVE-2025-6189 | MEDIUM | 6.5 | 2025-09-10 | The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter in all versions up to, and including, 2.9.5 due to i… | |
| CVE-2025-7049 | HIGH | 8.8 | 2025-09-10 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_ad… | |
| CVE-2025-7826 | MEDIUM | 6.5 | 2025-09-10 | The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient escapi… | |
| CVE-2025-7843 | MEDIUM | 6.4 | 2025-09-10 | The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the fetch_images() fu… | |
| CVE-2025-8778 | MEDIUM | 4.3 | 2025-09-10 | The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in … | |
| CVE-2025-9367 | MEDIUM | 5.5 | 2025-09-10 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient inpu… | |
| CVE-2025-9463 | MEDIUM | 6.5 | 2025-09-10 | The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order… | |
| CVE-2025-9622 | MEDIUM | 4.3 | 2025-09-10 | The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.6. This is due to missin… | |
| CVE-2025-9857 | MEDIUM | 6.4 | 2025-09-10 | The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all version… | |
| CVE-2025-9888 | MEDIUM | 4.3 | 2025-09-10 | The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing o… | |
| CVE-2025-9943 | CRITICAL | 9.1 | 2025-09-10 | An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to… | |
| CVE-2025-9979 | MEDIUM | 4.3 | 2025-09-10 | The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_c… | |
| CVE-2025-36756 | NONE | — | 2025-09-10 | A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known. | |
| CVE-2025-36757 | NONE | — | 2025-09-10 | It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain limited access to the system. | |
| CVE-2025-36758 | NONE | — | 2025-09-10 | It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle. | |
| CVE-2025-36759 | NONE | — | 2025-09-10 | Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addresses and phone numbers. | |
| CVE-2025-10213 | HIGH | 7.8 | 2025-09-10 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a dxt… | |
| CVE-2025-10214 | HIGH | 7.8 | 2025-09-10 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FRE… | |
| CVE-2025-10215 | HIGH | 7.8 | 2025-09-10 | DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FRE… | |
| CVE-2025-40725 | NONE | — | 2025-09-10 | Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending th… | |
| CVE-2025-40979 | NONE | — | 2025-09-10 | DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this vulnerability could allow attackers with local acce… | |
| CVE-2025-10219 | NONE | — | 2025-09-10 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |