Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified HIGH 7.5
CVE-2025-63036

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DFDevelopment Ronneby Theme …

Mitigation only
Fix from $1,950 2025-12-09
Unclassified HIGH 7.5
CVE-2025-63003

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North - Required …

Mitigation only
Fix from $1,950 2025-12-09
Unclassified HIGH 8.1
CVE-2025-12851

The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' …

Mitigation only
Fix from $1,950 2025-12-05
Dcat Admin CRITICAL 9.8
CVE-2025-65656

dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

Fix: after 2.2.3
Fix from $2,300 2025-12-02
Unclassified MEDIUM 6.6
CVE-2025-66115

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice ea…

Mitigation only
Fix from $1,600 2025-11-21
Thinkphp CRITICAL 9.8
CVE-2025-63888

The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

Mitigation only
Fix from $2,300 2025-11-20
Ewio2 M Firmware CRITICAL 9.8
CVE-2025-41734

An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.

Fix: 2.2.0+
Fix from $2,300 2025-11-18
Unclassified HIGH 8.8
CVE-2025-13088

The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0. This …

Mitigation only
Fix from $1,950 2025-11-18
Unclassified MEDIUM 5.8
CVE-2025-64714

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthe…

Patch available
Fix from $1,600 2025-11-13
Unclassified HIGH 8.7
CVE-2022-4982

DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The device's web server exposes han…

No fix yet
Fix from $1,950 2025-11-12
Tquadra Cms HIGH 7.5
CVE-2025-60574

A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which fails to prope…

No fix yet
Fix from $1,950 2025-11-07
Unclassified HIGH 8.1
CVE-2025-64287

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Alloggio - Hotel…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-62075

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ido Kobelkowsky Simple Payme…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-62066

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Revolution revolu…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.1
CVE-2025-62067

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Savory savory.…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.1
CVE-2025-62053

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez.Thi…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.1
CVE-2025-62055

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Academist acad…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.1
CVE-2025-62045

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Ele…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.1
CVE-2025-62014

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme ITok itok.This iss…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60248

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.1
CVE-2025-62010

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Famita famita allo…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60204

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach WooCommerce St…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60240

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alexander AnyComment anycomm…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60241

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce premmerc…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.1
CVE-2025-60198

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Saxon - Viral Content…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 8.1
CVE-2025-60199

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx InHype - Blog & Magaz…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60200

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress LearnPress Export …

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60201

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in aguilatechnologies WP Custom…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60202

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kyle Phillips Favorites favo…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.5
CVE-2025-60203

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach Store Exporter…

Mitigation only
Fix from $1,950 2025-11-06