TROYANOSYVIRUS

CVE Schwachstellen

CVE-Datenbank angereichert mit CISA KEV und NVD Daten

Gesamt: 17,178 CVEs
CVE IDCVSSSchweregradKEVSichtungen
CVE-2025-69367

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Oyster - Photography WordPress Theme oyster allows DOM-Based XSS.This issue affects Oyst...

7.1HIGH0
CVE-2026-2162

A vulnerability was determined in itsourcecode News Portal Project 1.0. This affects an unknown part of the file /admin/aboutus.php. This manipulation of the argument pagetitle causes sql injection. T...

4.7MEDIUM0
CVE-2025-69371

Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a through <= 1.6.1.

9.8CRITICAL0
CVE-2025-69374

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Eleblog – Elementor Blog And Magazine Addons ele-blog allows PHP Local...

8.1HIGH0
CVE-2025-69376

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fiel...

8.6HIGH0
CVE-2025-69379

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows Path Traversal.This issue affects Upload ...

8.6HIGH0
CVE-2025-69381

Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe...

7.1HIGH0
CVE-2025-69382

Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1.

9.8CRITICAL0
CVE-2025-69383

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows PHP Local File Inclusion.T...

7.5HIGH0
CVE-2026-22399

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Holmes holmes allows PHP Local File Inclusion.This issue affects ...

8.1HIGH0
CVE-2025-69386

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realvirtualmx RVCFDI para Woocommerce rvcfdi-para-woocommerce allows Reflected XSS.This issue affe...

7.1HIGH0
CVE-2025-69388

Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cliengo – Chatbot: from n/a through ...

6.5MEDIUM0
CVE-2026-26090

Rejected reason: Not used

N/ANONE0
CVE-2026-26092

Rejected reason: Not used

N/ANONE0
CVE-2025-20107

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-22845

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-24321

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-24524

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-26471

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2026-20987

Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands.

N/ANONE0
CVE-2025-27928

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-29869

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-31145

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-31364

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-32009

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-32085

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-32733

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-35960

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-29951

A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privilege escalation and arbitrary code execution.

N/ANONE0
CVE-2025-35962

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-35993

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-36523

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-36524

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-36532

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-36538

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-36545

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2025-36552

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

N/ANONE0
CVE-2026-1783

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accide...

N/ANONE0
CVE-2025-48515

Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code exe...

N/ANONE0
CVE-2025-52534

Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.

N/ANONE0
CVE-2026-26043

Rejected reason: Not used

N/ANONE0
CVE-2025-14892

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to ...

9.8CRITICAL0
CVE-2025-14343

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd. E-Commerce Product allows Reflected XSS.This issue affects E-Comm...

7.6HIGH0
CVE-2026-2101

A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary s...

8.7HIGH0
CVE-2025-71194

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock in wait_current_trans() due to ignored transaction type When wait_current_trans() is called during start_trans...

N/ANONE0
CVE-2026-25343

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS wp-sms allows DOM-Based XSS.This issue affects WP SMS: from n/a through <= 7.1.

5.9MEDIUM0
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI au...

8.1HIGH0
CVE-2025-67849

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. W...

7.3HIGH0
CVE-2025-67850

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A rem...

7.3HIGH0
CVE-2025-67851

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, wh...

6.1MEDIUM0
Seite 245 von 344

This product uses data from the NVD API but is not endorsed or certified by the NVD.