Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-39553 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 5.0.9. | |
| CVE-2025-47437 | NONE | — | 2025-09-09 | Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 7.0.1. | |
| CVE-2025-47569 | NONE | — | 2025-09-09 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card… | |
| CVE-2025-47570 | NONE | — | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This is… | |
| CVE-2025-47571 | NONE | — | 2025-09-09 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp a… | |
| CVE-2025-47579 | HIGH | Patched | 8.1 | 2025-09-09 | Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2. |
| CVE-2025-47694 | NONE | — | 2025-09-09 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Des… | |
| CVE-2025-47695 | NONE | — | 2025-09-09 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer-pro.This iss… | |
| CVE-2025-47997 | MEDIUM | Patched | 6.5 | 2025-09-09 | Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2025-48101 | HIGH | 8.8 | 2025-09-09 | Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: … | |
| CVE-2025-49430 | NONE | — | 2025-09-09 | Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultimate Video Player: from … | |
| CVE-2025-49692 | HIGH | Patched | 7.8 | 2025-09-09 | Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49734 | HIGH | Patched | 7.0 | 2025-09-09 | Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49860 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0. | |
| CVE-2025-53291 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a through <= 2.1.5. | |
| CVE-2025-53303 | NONE | — | 2025-09-09 | Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core: from n/a through <= 1.4.2. | |
| CVE-2025-53340 | NONE | — | 2025-09-09 | Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a t… | |
| CVE-2025-53348 | MEDIUM | 5.3 | 2025-09-09 | Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalium: from n/a t… | |
| CVE-2025-53796 | MEDIUM | Patched | 6.5 | 2025-09-09 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-53797 | MEDIUM | Patched | 6.5 | 2025-09-09 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-53798 | MEDIUM | Patched | 6.5 | 2025-09-09 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-53799 | MEDIUM | Patched | 5.5 | 2025-09-09 | Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. |
| CVE-2025-53800 | HIGH | Patched | 7.8 | 2025-09-09 | No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53801 | HIGH | Patched | 7.8 | 2025-09-09 | Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. |
| CVE-2025-53802 | HIGH | Patched | 7.0 | 2025-09-09 | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |