Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
Showing 3,521 - 3,540 of 3,615 CVEs
CVE-2025-68987 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama - A WordPress Theme for Movie Studios and Filmmakers cinerama allows PHP Local File Inclusion.This issue affects Cinerama - A WordPress Theme for Mo...

Published: Dec 30, 2025
Source: NVD
CVE-2025-68985 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local File Inclusion.This issue affects Aora: from n/a through <= 1.3.15.

Published: Dec 30, 2025
Source: NVD
CVE-2025-68984 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Puca puca allows PHP Local File Inclusion.This issue affects Puca: from n/a through <= 2.6.39.

Published: Dec 30, 2025
Source: NVD
CVE-2025-68983 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart allows PHP Local File Inclusion.This issue affects Greenmart: from n/a through <= 4.2.11.

Published: Dec 30, 2025
Source: NVD
CVE-2025-68974 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a t...

Published: Dec 30, 2025
Source: NVD
CVE-2025-15359 CRITICAL - 9.8

DVP-12SE11T - Out-of-bound memory write Vulnerability

Vendor: deltaww
Product: dvp-12se11t_firmware
Published: Dec 30, 2025
Source: NVD
CVE-2025-15243 CRITICAL - 9.8

A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/login.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

Vendor: carmelo
Product: simple_stock_system
Published: Dec 30, 2025
Source: NVD
CVE-2025-15103 CRITICAL - 9.8

DVP-12SE11T - Authentication Bypass via Partial Password Disclosure

Vendor: deltaww
Product: dvp-12se11t_firmware
Published: Dec 30, 2025
Source: NVD
CVE-2025-15102 CRITICAL - 9.8

DVP-12SE11T - Password Protection Bypass

Vendor: deltaww
Product: dvp-12se11t_firmware
Published: Dec 30, 2025
Source: NVD
CVE-2025-69234 CRITICAL - 9.1

Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

Vendor: navercorp
Product: whale
Published: Dec 30, 2025
Source: NVD
CVE-2025-15212 CRITICAL - 9.8

A vulnerability was detected in code-projects Refugee Food Management System 1.0. This issue affects some unknown processing of the file /home/regfood.php. Performing manipulation of the argument a results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 30, 2025
Source: NVD
CVE-2025-15211 CRITICAL - 9.8

A flaw has been found in code-projects Refugee Food Management System 1.0. Impacted is an unknown function of the file /home/refugee.php. Executing manipulation of the argument refNo/Fname/Lname/sex/age/contact/nationality_nid can lead to sql injection. The attack can be executed remotely. The explo...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 30, 2025
Source: NVD
CVE-2025-15210 CRITICAL - 9.8

A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This vulnerability affects unknown code of the file /home/editrefugee.php. Such manipulation of the argument a/b/c/sex/d/e/nationality_nid leads to sql injection. The attack may be launched remotely. The ...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 30, 2025
Source: NVD
CVE-2025-15209 CRITICAL - 9.8

A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown part of the file /home/editfood.php. This manipulation of the argument a/b/c/d causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15208 CRITICAL - 9.8

A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/editrefugee.php. The manipulation of the argument rfid results in sql injection. The attack can be launched remotely. The exploit has been r...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-68860 CRITICAL - 9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder allows Authentication Abuse.This issue affects Mobile builder: from n/a through 1.4.2.

Published: Dec 29, 2025
Source: NVD
CVE-2025-68562 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through 8.7.3.

Published: Dec 29, 2025
Source: NVD
CVE-2025-15207 CRITICAL - 9.8

A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the pub...

Vendor: campcodes
Product: supplier_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15206 CRITICAL - 9.8

A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing manipulation of the argument txtAreaCode can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

Vendor: campcodes
Product: supplier_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2024-27480 CRITICAL - 9.8

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

Vendor: vvveb
Product: vvvebjs
Published: Dec 29, 2025
Source: NVD