Vulnerability intelligence
VULONE Vulnerability Database
Stay ahead of what gets exploited. Every CVE from NVD, enriched every 30 minutes with EPSS, CISA KEV, ransomware linkage and automated analysis.
Filters Show:
27 results. Thinkphp Thinkphp.
Page 1 of 2| ID | Severity | Score | Technology | Weakness | CISA KEV | Exploit | EPSS | Published |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-25270 | Critical | 9.3 | Insecure direct object reference | - | 1 ref | 0.89% | Apr 22, 2026 | |
| CVE-2025-63889 | High | 7.5 | Out-of-bounds read | - | - | 0.30% | Nov 20, 2025 | |
| CVE-2025-63888 | Critical | 9.8 | PHP remote file inclusion | - | - | 0.57% | Nov 20, 2025 | |
| CVE-2025-50707 | Critical | 9.8 | Code injection | - | 2 refs | 1.0% | Aug 5, 2025 | |
| CVE-2025-50706 | Critical | 9.8 | Code injection | - | 2 refs | 1.0% | Aug 5, 2025 | |
| CVE-2024-48112 | Critical | 9.8 | Deserialization of untrusted data | - | 1 ref | 0.89% | Oct 30, 2024 | |
| CVE-2024-44902 | Critical | 9.8 | Deserialization of untrusted data | - | - | 4.2% | Sep 9, 2024 | |
| CVE-2024-34467 | Medium | 6.1 | Cross-site scripting | - | 2 refs | 0.42% | May 4, 2024 | |
| CVE-2022-45982 | Critical | 9.8 | Deserialization of untrusted data | - | 2 refs | 1.2% | Feb 8, 2023 | |
| CVE-2022-47945 | Critical | 9.8 | Path traversal | - | 2 refs | 28% | Dec 23, 2022 | |
| CVE-2022-44289 | High | 8.8 | Unrestricted file upload | - | 2 refs | 3.0% | Dec 6, 2022 | |
| CVE-2022-38352 | Critical | 9.8 | Deserialization of untrusted data | - | 2 refs | 21% | Sep 15, 2022 | |
| CVE-2022-33107 | Critical | 9.8 | Deserialization of untrusted data | - | 2 refs | 24% | Jun 29, 2022 | |
| CVE-2021-23592 | Critical | 9.8 | Deserialization of untrusted data | - | - | 1.7% | May 6, 2022 | |
| CVE-2022-25481 | High | 7.5 | Exposure of resource to wrong sphe | - | 2 refs | 4.7% | Mar 21, 2022 | |
| CVE-2021-44892 | High | 8.8 | - | - | 2 refs | 2.0% | Feb 10, 2022 | |
| CVE-2021-44350 | Critical | 9.8 | SQL injection | - | 2 refs | 1.4% | Dec 15, 2021 | |
| CVE-2021-36567 | Critical | 9.8 | Deserialization of untrusted data | - | 2 refs | 2.4% | Dec 6, 2021 | |
| CVE-2021-36564 | Critical | 9.8 | Deserialization of untrusted data | - | 2 refs | 1.8% | Dec 6, 2021 | |
| CVE-2020-20120 | Critical | 9.8 | SQL injection | - | 2 refs | 1.8% | Sep 28, 2021 |