Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-39553 NONE &mdash; 2025-09-09 Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 5.0.9.
CVE-2025-47437 NONE &mdash; 2025-09-09 Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 7.0.1.
CVE-2025-47569 NONE &mdash; 2025-09-09 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card&hellip;
CVE-2025-47570 NONE &mdash; 2025-09-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This is&hellip;
CVE-2025-47571 NONE &mdash; 2025-09-09 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp a&hellip;
CVE-2025-47579 HIGH Patched 8.1 2025-09-09 Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.
CVE-2025-47694 NONE &mdash; 2025-09-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Des&hellip;
CVE-2025-47695 NONE &mdash; 2025-09-09 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer-pro.This iss&hellip;
CVE-2025-47997 MEDIUM Patched 6.5 2025-09-09 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2025-48101 HIGH 8.8 2025-09-09 Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: &hellip;
CVE-2025-49430 NONE &mdash; 2025-09-09 Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultimate Video Player: from &hellip;
CVE-2025-49692 HIGH Patched 7.8 2025-09-09 Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-49734 HIGH Patched 7.0 2025-09-09 Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-49860 NONE &mdash; 2025-09-09 Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0.
CVE-2025-53291 NONE &mdash; 2025-09-09 Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a through <= 2.1.5.
CVE-2025-53303 NONE &mdash; 2025-09-09 Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core: from n/a through <= 1.4.2.
CVE-2025-53340 NONE &mdash; 2025-09-09 Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a t&hellip;
CVE-2025-53348 MEDIUM 5.3 2025-09-09 Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalium: from n/a t&hellip;
CVE-2025-53796 MEDIUM Patched 6.5 2025-09-09 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-53797 MEDIUM Patched 6.5 2025-09-09 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-53798 MEDIUM Patched 6.5 2025-09-09 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-53799 MEDIUM Patched 5.5 2025-09-09 Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
CVE-2025-53800 HIGH Patched 7.8 2025-09-09 No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-53801 HIGH Patched 7.8 2025-09-09 Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2025-53802 HIGH Patched 7.0 2025-09-09 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.