Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-10126 MEDIUM 6.4 2025-09-10 The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' shortcode in all versions up to, and including, 1.0.8 due…
CVE-2025-10142 MEDIUM 4.9 2025-09-10 The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 4.44.3…
CVE-2025-41714 HIGH 8.8 2025-09-10 The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to creat…
CVE-2025-6189 MEDIUM 6.5 2025-09-10 The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter in all versions up to, and including, 2.9.5 due to i…
CVE-2025-7049 HIGH 8.8 2025-09-10 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_ad…
CVE-2025-7826 MEDIUM 6.5 2025-09-10 The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient escapi…
CVE-2025-7843 MEDIUM 6.4 2025-09-10 The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the fetch_images() fu…
CVE-2025-8778 MEDIUM 4.3 2025-09-10 The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in …
CVE-2025-9367 MEDIUM 5.5 2025-09-10 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient inpu…
CVE-2025-9463 MEDIUM 6.5 2025-09-10 The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order…
CVE-2025-9622 MEDIUM 4.3 2025-09-10 The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.6. This is due to missin…
CVE-2025-9857 MEDIUM 6.4 2025-09-10 The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all version…
CVE-2025-9888 MEDIUM 4.3 2025-09-10 The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing o…
CVE-2025-9943 CRITICAL 9.1 2025-09-10 An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to…
CVE-2025-9979 MEDIUM 4.3 2025-09-10 The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_c…
CVE-2025-36756 NONE — 2025-09-10 A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.
CVE-2025-36757 NONE — 2025-09-10 It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain limited access to the system.
CVE-2025-36758 NONE — 2025-09-10 It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.
CVE-2025-36759 NONE — 2025-09-10 Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addresses and phone numbers.
CVE-2025-10213 HIGH 7.8 2025-09-10 DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a dxt…
CVE-2025-10214 HIGH 7.8 2025-09-10 DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FRE…
CVE-2025-10215 HIGH 7.8 2025-09-10 DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FRE…
CVE-2025-40725 NONE — 2025-09-10 Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending th…
CVE-2025-40979 NONE — 2025-09-10 DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this vulnerability could allow attackers with local acce…
CVE-2025-10219 NONE — 2025-09-10 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.