Search
66,771 CVEs
CVEs (66,771, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 66,771 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-6588 | MEDIUM | 6.1 | 2025-07-24 | The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to, and including, 1.4.3 due to insuffic… | |
| CVE-2025-7640 | HIGH | 8.1 | 2025-07-24 | The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to missing or incorrect n… | |
| CVE-2025-7690 | MEDIUM | 6.1 | 2025-07-24 | The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce v… | |
| CVE-2025-7695 | HIGH | 8.8 | 2025-07-24 | The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST endpoint in ver… | |
| CVE-2025-7780 | MEDIUM | 6.5 | 2025-07-24 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to … | |
| CVE-2025-7822 | MEDIUM | 4.3 | 2025-07-24 | The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all versions up to… | |
| CVE-2025-7835 | MEDIUM | 4.3 | 2025-07-24 | The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due to missing or … | |
| CVE-2025-7959 | MEDIUM | 6.4 | 2025-07-24 | The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter in all versions up to, and including, 2.4.2 due to … | |
| CVE-2025-7966 | MEDIUM | 6.4 | 2025-07-24 | The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and 'subs_count’ parameters in all versions up to, and i… | |
| CVE-2025-8071 | MEDIUM | 6.4 | 2025-07-24 | Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all versions up to, and including, 2.1.10 due to insufficient i… | |
| CVE-2025-40680 | NONE | — | 2025-07-24 | Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT session token in plain text within different… | |
| CVE-2025-4822 | CRITICAL | Patched | 9.8 | 2025-07-24 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection. Thi… |
| CVE-2025-5243 | CRITICAL | Patched | 10.0 | 2025-07-24 | Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software In… |
| CVE-2025-45731 | MEDIUM | 6.5 | 2025-07-24 | A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other operations are pending. | |
| CVE-2025-4784 | CRITICAL | Patched | 9.8 | 2025-07-24 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection. This issue affects Tourtella:… |
| CVE-2025-33013 | MEDIUM | Patched | 6.2 | 2025-07-24 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.… |
| CVE-2025-33109 | HIGH | 7.5 | 2025-07-24 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or … | |
| CVE-2025-36005 | MEDIUM | Patched | 5.9 | 2025-07-24 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.… |
| CVE-2025-51082 | MEDIUM | 5.3 | 2025-07-24 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based buffer… | |
| CVE-2025-51085 | MEDIUM | 5.3 | 2025-07-24 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads to stack-based… | |
| CVE-2025-51087 | HIGH | 8.6 | 2025-07-24 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based buffer overflow. | |
| CVE-2025-51088 | MEDIUM | 5.3 | 2025-07-24 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argument `shareSpeed` leads to stack-based buffer overflow. | |
| CVE-2025-51089 | MEDIUM | 6.5 | 2025-07-24 | Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow. | |
| CVE-2025-8114 | MEDIUM | Patched | 4.7 | 2025-07-24 | A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryp… |
| CVE-2025-25214 | HIGH | 8.8 | 2025-07-24 | A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series of specially crafted HT… |