Search Results (9565 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-41089 1 Microsoft 11 .net Framework, Windows 10, Windows 11 and 8 more 2025-07-22 7.8 High
.NET Framework Remote Code Execution Vulnerability
CVE-2022-26806 1 Microsoft 1 365 Apps 2025-07-22 7.8 High
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2022-26805 1 Microsoft 1 365 Apps 2025-07-22 7.8 High
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2022-26804 1 Microsoft 1 365 Apps 2025-07-22 7.8 High
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2022-44702 1 Microsoft 3 Terminal, Windows 10, Windows 11 2025-07-22 7.8 High
Windows Terminal Remote Code Execution Vulnerability
CVE-2022-44695 1 Microsoft 3 365 Apps, Office, Visio 2025-07-22 7.8 High
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-44694 1 Microsoft 2 365 Apps, Office 2025-07-22 7.8 High
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-44693 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2025-07-22 8.8 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-44692 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-07-22 7.8 High
Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2022-44690 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2025-07-22 8.8 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-44676 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-07-22 8.1 High
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2022-44668 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-07-22 7.8 High
Windows Media Remote Code Execution Vulnerability
CVE-2022-44667 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2025-07-22 7.8 High
Windows Media Remote Code Execution Vulnerability
CVE-2022-41127 1 Microsoft 2 Dynamics 365 Business Central, Dynamics Nav 2025-07-22 8.5 High
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
CVE-2025-7645 2025-07-22 8.1 High
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete-file' field in all versions up to, and including, 3.2.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, when an administrator deletes the submission, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
CVE-2025-6222 2025-07-22 9.8 Critical
The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2025-7438 2025-07-22 7.5 High
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability is difficult to exploit due to timing requirements and environmental factors.
CVE-2025-7643 1 Wordpress 1 Wordpress 2025-07-22 9.1 Critical
The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions() function in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
CVE-2025-7697 2025-07-22 9.8 Critical
The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.
CVE-2025-7696 2025-07-22 9.8 Critical
The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.3 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.