NVD · CISA KEV · CERT-In

CVE Tracker

Vulnerabilities ranked for Indian enterprises. Filter by severity, exploitation status and CERT-In advisories; sign in for WhatsApp/email alerts on your product stack.

Exploited (KEV)🇮🇳 CERT-InClear filters
10.0CVE-2025-60206Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows…Unknown10.0CVE-2025-49060Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows…Unknown10.0CVE-2025-48106Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows…Unknown10.0CVE-2025-9846Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information…Unknown9.9CVE-2025-58048Paymenter is a free and open-source webshop solution for hostings.Unknown9.8CVE-2025-64130Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a…Unknown9.8CVE-2025-9967The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account…Unknown9.8CVE-2025-9286The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to…Unknown9.8CVE-2025-41715The database for the web application is exposed without authentication, allowing an unauthenticated remote…Unknown9.8CVE-2025-8570The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT…Unknown9.8CVE-2025-9994The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication…Unknown9.8CVE-2025-8359The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and…Unknown9.8CVE-2025-54738Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster…Unknown9.8CVE-2025-54725Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows…Unknown9.6CVE-2025-59434Flowise is a drag & drop user interface to build a customized large language model flow.Unknown9.6CVE-2025-58255Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Images…Unknown9.3CVE-2025-47569Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in…Unknown9.3CVE-2025-54720Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in…Unknown9.1CVE-2025-9943An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the…Unknown9.1CVE-2025-10134The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion…Unknown9.1CVE-2025-49796A vulnerability was found in libxml2.Unknown9.1CVE-2025-49794A use-after-free vulnerability was found in libxml2.Unknown9.0CVE-2025-9976An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release…Unknown8.9CVE-2025-9798Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability…Unknown8.8CVE-2024-32011A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown8.8CVE-2025-9223Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated…Unknown8.8CVE-2025-9890The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,…Unknown8.8CVE-2025-8593The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in…Unknown8.8CVE-2025-20334A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject…Unknown8.8CVE-2025-9900A flaw was found in Libtiff.Unknown8.8CVE-2025-9844Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace…Unknown8.8CVE-2025-58244Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This…Unknown8.8CVE-2025-10205Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON:…Unknown8.8CVE-2025-9216The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More…Unknown8.8CVE-2025-10057The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code…Unknown8.8CVE-2025-8425The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead…Unknown8.8CVE-2025-7718The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to…Unknown8.8CVE-2025-53303Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object…Unknown8.8CVE-2025-54742Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object…Unknown8.6CVE-2025-20315A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could…Unknown8.5CVE-2025-8067A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the…Unknown8.4CVE-2025-10906A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS.Unknown8.2CVE-2025-59430Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect.Unknown8.1CVE-2025-10058The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary…Unknown8.1CVE-2025-42916Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the…Unknown8.1CVE-2025-9566There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files…Unknown8.1CVE-2025-9990The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all…Unknown8.1CVE-2025-54731Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase…Unknown8.1CVE-2025-53584Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software &…Unknown8.1CVE-2025-53583Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight…Unknown8.1CVE-2025-53572Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows…Unknown8.1CVE-2024-34394libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while…Unknown8.1CVE-2024-34393libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while…Unknown7.8CVE-2025-10101Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may…Unknown7.8CVE-2024-32010A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown7.8CVE-2024-32009A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown7.8CVE-2024-32008A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown7.8CVE-2025-10541iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges.Unknown7.8CVE-2025-9450A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS…Unknown7.8CVE-2025-9449A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release…Unknown7.8CVE-2025-9447An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on…Unknown7.8CVE-2025-9578Local privilege escalation due to insecure folder permissions.Unknown7.7CVE-2025-59002Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme…Unknown7.7CVE-2025-54029Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons…Unknown7.7CVE-2025-53588Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V.Unknown7.6CVE-2025-58788Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad…Unknown7.6CVE-2025-9959Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution…Unknown7.5CVE-2024-3884A flaw was found in Undertow that can cause remote denial of service attacks.Unknown7.5CVE-2025-7007NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning…Unknown7.5CVE-2025-9902Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export…Unknown7.5CVE-2025-40933Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely.Unknown7.5CVE-2025-10143The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and…Unknown7.5CVE-2025-9807The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’…Unknown7.5CVE-2025-9874The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all…Unknown7.5CVE-2025-8696If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use…Unknown7.5CVE-2025-48317Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay…Unknown7.5CVE-2025-0280A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.Unknown7.5CVE-2025-58047Volto is a React based frontend for the Plone Content Management System.Unknown7.4CVE-2025-13947A flaw was found in WebKitGTK.Unknown7.4CVE-2025-20340A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could…Unknown7.3CVE-2024-45370An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy…Unknown7.3CVE-2024-21923Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation…Unknown7.3CVE-2024-21922A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation,…Unknown7.3CVE-2025-23257NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor…Unknown7.2CVE-2025-10239In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with…Unknown7.2CVE-2025-58662Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows…Unknown7.1CVE-2025-58268Cross-Site Request Forgery (CSRF) vulnerability in WPMK WPMK PDF Generator wpmk-pdf-generator allows…Unknown7.1CVE-2025-57968Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in…Unknown7.1CVE-2025-9969Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability…Unknown7.1CVE-2025-8411Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability…Unknown7.1CVE-2025-58852Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager mstw-league-manager…Unknown7.1CVE-2024-32589Missing Authorization vulnerability in Dmitry V.Unknown7.1CVE-2025-54724Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in…Unknown7.1CVE-2025-54714Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows…Unknown7.1CVE-2025-54710Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality…Unknown7.1CVE-2025-53289Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in…Unknown