Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,725
Quick preset (or use dates below)
Clear Filters
Showing 2,721 - 2,740 of 3,597 CVEs
CVE-2025-69304 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allmart allmart-core allows Blind SQL Injection.This issue affects Allmart: from n/a through <= 1.1.

Vendor: TeconceTheme
Product: Allmart
Published: Feb 20, 2026
Source: NVD
CVE-2025-69301 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <= 5.6.11.

Vendor: ThemeGoods
Product: PhotoMe
Published: Feb 20, 2026
Source: NVD
CVE-2025-69295 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind SQL Injection.This issue affects Coven Core: from n/a through <= 1.3.

Vendor: TeconceTheme
Product: Coven Core
Published: Feb 20, 2026
Source: NVD
CVE-2025-68549 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affects Wiguard: from n/a through < 2.0.1.

Vendor: zozothemes
Product: Wiguard
Published: Feb 20, 2026
Source: NVD
CVE-2025-68545 CRITICAL - 9.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through <= 1.2.14.

Vendor: thembay
Product: Nika
Published: Feb 20, 2026
Source: NVD
CVE-2025-68541 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.2.0.

Vendor: BoldThemes
Product: Ippsum
Published: Feb 20, 2026
Source: NVD
CVE-2025-67997 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from n/a through < 1.6.7.

Vendor: BoldThemes
Product: Travelicious
Published: Feb 20, 2026
Source: NVD
CVE-2025-67996 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects Nestin: from n/a through < 1.2.6.

Vendor: BoldThemes
Product: Nestin
Published: Feb 20, 2026
Source: NVD
CVE-2025-67995 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affects PatioTime: from n/a through < 2.1.

Vendor: LoftOcean
Product: PatioTime
Published: Feb 20, 2026
Source: NVD
CVE-2025-67979 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in WesternDeal WPForms Google Sheet Connector gsheetconnector-wpforms allows Code Injection.This issue affects WPForms Google Sheet Connector: from n/a through <= 4.0.1.

Vendor: WesternDeal
Product: WPForms Google Sheet Connector
Published: Feb 20, 2026
Source: NVD
CVE-2025-10970 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection.This issue affects Talentics: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in ...

Vendor: Kolay Software Inc.
Product: Talentics
Published: Feb 20, 2026
Source: NVD
CVE-2025-30416 CRITICAL - 10.0

Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

Vendor: Acronis
Product: Acronis Cyber Protect 16, Acronis Cyber Protect 15
Published: Feb 20, 2026
Source: NVD
CVE-2025-30412 CRITICAL - 10.0

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

Vendor: Acronis
Product: Acronis Cyber Protect 16, Acronis Cyber Protect 15
Published: Feb 20, 2026
Source: NVD
CVE-2025-30411 CRITICAL - 10.0

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

Vendor: Acronis
Product: Acronis Cyber Protect 16, Acronis Cyber Protect 15
Published: Feb 20, 2026
Source: NVD
CVE-2025-30410 CRITICAL - 9.8

Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, macOS, Wi...

Vendor: Acronis
Product: Acronis Cyber Protect Cloud Agent, Acronis Cyber Protect 16, Acronis Cyber Protect 15
Published: Feb 20, 2026
Source: NVD
CVE-2026-27476 CRITICAL - 9.8

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target s...

Vendor: Bixat
Product: RustFly
Published: Feb 19, 2026
Source: NVD
CVE-2025-67305 CRITICAL - 9.8

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the P...

Published: Feb 19, 2026
Source: NVD
CVE-2026-27212 CRITICAL - 7.8

Swiper is a free and mobile touch slider with hardware accelerated transitions and native behavior. Versions 6.5.1 through 12.1.1 have a Prototype pollution vulnerability. The vulnerability resides in line 94 of shared/utils.mjs, where the indexOf() function is used to check whether user provided in...

Vendor: npm
Product: swiper
Published: Feb 19, 2026
Source: GitHub
CVE-2025-67304 CRITICAL - 9.8

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticat...

Published: Feb 19, 2026
Source: NVD
CVE-2026-26339 CRITICAL - 9.8

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

Vendor: Hyland
Product: Alfresco Transformation Service (Enterprise), Alfresco Community (Transform Core)
Published: Feb 19, 2026
Source: NVD