NVD · CISA KEV · CERT-In
CVE Tracker
Vulnerabilities ranked for Indian enterprises. Filter by severity, exploitation status and CERT-In advisories; sign in for WhatsApp/email alerts on your product stack.
8.9CVE-2025-9798Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability…Unknown8.8CVE-2024-32011A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown8.8CVE-2025-9223Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated…Unknown8.8CVE-2025-9890The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,…Unknown8.8CVE-2025-8593The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in…Unknown8.8CVE-2025-20334A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject…Unknown8.8CVE-2025-9900A flaw was found in Libtiff.Unknown8.8CVE-2025-9844Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace…Unknown8.8CVE-2025-58244Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This…Unknown8.8CVE-2025-10205Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON:…Unknown8.8CVE-2025-9216The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More…Unknown8.8CVE-2025-10057The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code…Unknown8.8CVE-2025-8425The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead…Unknown8.8CVE-2025-7718The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to…Unknown8.8CVE-2025-53303Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object…Unknown8.8CVE-2025-54742Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object…Unknown8.6CVE-2025-20315A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could…Unknown8.5CVE-2025-8067A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the…Unknown8.4CVE-2025-10906A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS.Unknown8.2CVE-2025-59430Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect.Unknown8.1CVE-2025-10058The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary…Unknown8.1CVE-2025-42916Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the…Unknown8.1CVE-2025-9566There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files…Unknown8.1CVE-2025-9990The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all…Unknown8.1CVE-2025-54731Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase…Unknown8.1CVE-2025-53584Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software &…Unknown8.1CVE-2025-53583Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight…Unknown8.1CVE-2025-53572Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows…Unknown8.1CVE-2024-34394libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while…Unknown8.1CVE-2024-34393libxmljs2 is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while…Unknown7.8CVE-2025-10101Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may…Unknown7.8CVE-2024-32010A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown7.8CVE-2024-32009A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown7.8CVE-2024-32008A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2).Unknown7.8CVE-2025-10541iMonitor EAM 9.6394 installs a system service (eamusbsrv64.exe) that runs with NT AUTHORITY\SYSTEM privileges.Unknown7.8CVE-2025-9450A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS…Unknown7.8CVE-2025-9449A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release…Unknown7.8CVE-2025-9447An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on…Unknown7.8CVE-2025-9578Local privilege escalation due to insecure folder permissions.Unknown7.7CVE-2025-59002Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme…Unknown7.7CVE-2025-54029Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in extendons…Unknown7.7CVE-2025-53588Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V.Unknown7.6CVE-2025-58788Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad…Unknown7.6CVE-2025-9959Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution…Unknown7.5CVE-2024-3884A flaw was found in Undertow that can cause remote denial of service attacks.Unknown7.5CVE-2025-7007NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning…Unknown7.5CVE-2025-9902Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export…Unknown7.5CVE-2025-40933Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely.Unknown7.5CVE-2025-10143The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and…Unknown7.5CVE-2025-9807The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’…Unknown7.5CVE-2025-9874The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all…Unknown7.5CVE-2025-8696If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use…Unknown7.5CVE-2025-48317Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay…Unknown7.5CVE-2025-0280A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.Unknown7.5CVE-2025-58047Volto is a React based frontend for the Plone Content Management System.Unknown7.4CVE-2025-13947A flaw was found in WebKitGTK.Unknown7.4CVE-2025-20340A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could…Unknown7.3CVE-2024-45370An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy…Unknown7.3CVE-2024-21923Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation…Unknown7.3CVE-2024-21922A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation,…Unknown7.3CVE-2025-23257NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor…Unknown7.2CVE-2025-10239In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with…Unknown7.2CVE-2025-58662Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows…Unknown7.1CVE-2025-58268Cross-Site Request Forgery (CSRF) vulnerability in WPMK WPMK PDF Generator wpmk-pdf-generator allows…Unknown7.1CVE-2025-57968Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in…Unknown7.1CVE-2025-9969Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability…Unknown7.1CVE-2025-8411Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability…Unknown7.1CVE-2025-58852Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager mstw-league-manager…Unknown7.1CVE-2024-32589Missing Authorization vulnerability in Dmitry V.Unknown7.1CVE-2025-54724Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in…Unknown7.1CVE-2025-54714Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows…Unknown7.1CVE-2025-54710Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality…Unknown7.1CVE-2025-53289Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in…Unknown