Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,513
Quick preset (or use dates below)
Clear Filters
Showing 3,121 - 3,140 of 3,601 CVEs
CVE-2025-68018 CRITICAL - 9.4

Missing Authorization vulnerability in ilmosys Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Listener for WooCommerce: from n/a through <= 3.6.1.

Vendor: ilmosys
Product: Order Listener for WooCommerce
Published: Jan 22, 2026
Source: NVD
CVE-2025-68015 CRITICAL - 9.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.3.

Vendor: Vollstart
Product: Event Tickets with Ticket Scanner
Published: Jan 22, 2026
Source: NVD
CVE-2025-68001 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a Web Shell to a Web Server.This issue affects g-FFL Checkout: from n/a through <= 2.1.0.

Vendor: garidium
Product: g-FFL Checkout
Published: Jan 22, 2026
Source: NVD
CVE-2025-67968 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue affects Real Homes CRM: from n/a through <= 1.0.0.

Vendor: InspiryThemes
Product: Real Homes CRM
Published: Jan 22, 2026
Source: NVD
CVE-2025-67945 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite โ€“ WooCommerce integration woo-mailerlite allows SQL Injection.This issue affects MailerLite โ€“ WooCommerce integration: from n/a through <= 3.1.2.

Vendor: MailerLite
Product: MailerLite โ€“ WooCommerce integration
Published: Jan 22, 2026
Source: NVD
CVE-2025-67944 CRITICAL - 9.1

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.1.8.

Vendor: Nelio Software
Product: Nelio AB Testing
Published: Jan 22, 2026
Source: NVD
CVE-2025-67617 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a through <= 1.4.3.

Vendor: themeton
Product: Consult Aid
Published: Jan 22, 2026
Source: NVD
CVE-2025-64252 CRITICAL - 9.1

Server-Side Request Forgery (SSRF) vulnerability in Marco Milesi ANAC XML Viewer anac-xml-viewer allows Server Side Request Forgery.This issue affects ANAC XML Viewer: from n/a through <= 1.8.2.

Vendor: Marco Milesi
Product: ANAC XML Viewer
Published: Jan 22, 2026
Source: NVD
CVE-2025-63017 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes WerkStatt Plugin werkstatt-plugin allows PHP Local File Inclusion.This issue affects WerkStatt Plugin: from n/a through <= 1.6.6.

Vendor: fuelthemes
Product: WerkStatt Plugin
Published: Jan 22, 2026
Source: NVD
CVE-2025-62754 CRITICAL - 9.1

Missing Authorization vulnerability in Kapil Paul Payment Gateway bKash for WC woo-payment-bkash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway bKash for WC: from n/a through <= 3.1.0.

Vendor: Kapil Paul
Product: Payment Gateway bKash for WC
Published: Jan 22, 2026
Source: NVD
CVE-2025-62741 CRITICAL - 9.1

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3.

Vendor: SmartDataSoft
Product: Pool Services
Published: Jan 22, 2026
Source: NVD
CVE-2025-62056 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <= 1.0.1.

Vendor: blazethemes
Product: News Event
Published: Jan 22, 2026
Source: NVD
CVE-2025-62050 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.0.3.

Vendor: blazethemes
Product: Blogmatic
Published: Jan 22, 2026
Source: NVD
CVE-2025-54003 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Depot depot allows PHP Local File Inclusion.This issue affects Depot: from n/a through <= 1.16.

Vendor: Mikado-Themes
Product: Depot
Published: Jan 22, 2026
Source: NVD
CVE-2025-50004 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a through <= 4.10.1.

Vendor: artbees
Product: JupiterX Core
Published: Jan 22, 2026
Source: NVD
CVE-2025-50003 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Amuli amuli allows PHP Local File Inclusion.This issue affects Amuli: from n/a through <= 2.3.0.

Vendor: axiomthemes
Product: Amuli
Published: Jan 22, 2026
Source: NVD
CVE-2025-50002 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects Energia: from n/a through <= 1.1.2.

Vendor: Farost
Product: Energia
Published: Jan 22, 2026
Source: NVD
CVE-2025-49994 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Athens athens allows PHP Local File Inclusion.This issue affects Athens: from n/a through <= 1.1.6.

Vendor: ovatheme
Product: Athens
Published: Jan 22, 2026
Source: NVD
CVE-2025-49055 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through <= 2.5.

Vendor: kamleshyadav
Product: WP Lead Capturing Pages
Published: Jan 22, 2026
Source: NVD
CVE-2025-49050 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through <= 2.5.

Vendor: kamleshyadav
Product: WP Lead Capturing Pages
Published: Jan 22, 2026
Source: NVD