NVD · CISA KEV · CERT-In

CVE Tracker

Vulnerabilities ranked for Indian enterprises. Filter by severity, exploitation status and CERT-In advisories; sign in for WhatsApp/email alerts on your product stack.

Exploited (KEV)🇮🇳 CERT-InClear filters
10.0CVE-2025-60206Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows…Unknown10.0CVE-2025-49060Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows…Unknown10.0CVE-2025-48106Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows…Unknown10.0CVE-2025-9846Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information…Unknown9.9CVE-2025-58048Paymenter is a free and open-source webshop solution for hostings.Unknown9.8CVE-2025-64130Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a…Unknown9.8CVE-2025-9967The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account…Unknown9.8CVE-2025-9286The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to…Unknown9.8CVE-2025-41715The database for the web application is exposed without authentication, allowing an unauthenticated remote…Unknown9.8CVE-2025-8570The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT…Unknown9.8CVE-2025-9994The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication…Unknown9.8CVE-2025-8359The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and…Unknown9.8CVE-2025-54738Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster…Unknown9.8CVE-2025-54725Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows…Unknown9.6CVE-2025-59434Flowise is a drag & drop user interface to build a customized large language model flow.Unknown9.6CVE-2025-58255Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Images…Unknown9.3CVE-2025-47569Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in…Unknown9.3CVE-2025-54720Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in…Unknown9.1CVE-2025-9943An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the…Unknown9.1CVE-2025-10134The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion…Unknown9.1CVE-2025-49796A vulnerability was found in libxml2.Unknown9.1CVE-2025-49794A use-after-free vulnerability was found in libxml2.Unknown9.0CVE-2025-9976An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release…Unknown