32,772 indexed

CVECVE vulnerabilities

32,772 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,701–5,750 of 8,314 in Critical · page 115 of 167

IDTitleSummary
CVE-2025-4026CVE-2025-4026
CVSS 9.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown proc…
CVE-2025-4025CVE-2025-4025
CVSS 9.8
A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of…
CVE-2025-4024CVE-2025-4024
CVSS 9.8
A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.p…
CVE-2025-4023CVE-2025-4023
CVSS 9.8
A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the fil…
CVE-2025-4020CVE-2025-4020
CVSS 9.8
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …
CVE-2025-4019CVE-2025-4019
CVSS 9.8
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function ge…
CVE-2025-4016CVE-2025-4016
CVSS 9.1
A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIn…
CVE-2025-4014CVE-2025-4014
CVSS 9.8
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown funct…
CVE-2025-4013CVE-2025-4013
CVSS 9.8
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /adm…
CVE-2025-4005CVE-2025-4005
CVSS 9.8
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the…
CVE-2025-4004CVE-2025-4004
CVSS 9.8
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the…
CVE-2025-3998CVE-2025-3998
CVSS 9.8
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?i…
CVE-2025-3976CVE-2025-3976
CVSS 9.8
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …
CVE-2025-3974CVE-2025-3974
CVSS 9.8
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the f…
CVE-2025-3973CVE-2025-3973
CVSS 9.8
A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This affects an unknown part of the file /che…
CVE-2025-3972CVE-2025-3972
CVSS 9.8
A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown f…
CVE-2025-3971CVE-2025-3971
CVSS 9.8
A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionalit…
CVE-2025-3969CVE-2025-3969
CVSS 9.8
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the …
CVE-2025-3963CVE-2025-3963
CVSS 9.8
A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processing of the f…
CVE-2025-39601CVE-2025-39601
CVSS 9.6
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & P…
CVE-2025-3960CVE-2025-3960
CVSS 9.8
A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …
CVE-2025-39596CVE-2025-39596
CVSS 9.8
Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects Quentn WP: from n/a through <= 1.2.8.
CVE-2025-39595CVE-2025-39595
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows SQL Injection.…
CVE-2025-39588CVE-2025-39588
CVSS 9.8
Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Object Injection.This issue affects U…
CVE-2025-39587CVE-2025-39587
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder …
CVE-2025-3957CVE-2025-3957
CVSS 9.8
A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main\resources…
CVE-2025-3956CVE-2025-3956
CVSS 9.8
A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the function RestResp of the file novel-cl…
CVE-2025-39557CVE-2025-39557
CVSS 9.1
Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Upload …
CVE-2025-39551CVE-2025-39551
CVSS 9.8
Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injection.This issue affects FluentBoards: from…
CVE-2025-39550CVE-2025-39550
CVSS 9.8
Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Injection.This issue affects FluentCommunity:…
CVE-2025-39504CVE-2025-39504
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlayers Hotel gdlr-hotel allows Blind SQL I…
CVE-2025-39503CVE-2025-39503
CVSS 9.8
Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hotel gdlr-hotel allows Object Injection.This issue affects Goodlayers Hotel: from n/a…
CVE-2025-39501CVE-2025-39501
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Blind SQL…
CVE-2025-39500CVE-2025-39500
CVSS 9.8
Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Object Injection.This issue affects Goodlayers Hostel: from …
CVE-2025-39499CVE-2025-39499
CVSS 9.8
Deserialization of Untrusted Data vulnerability in BoldThemes Medicare medicare allows Object Injection.This issue affects Medicare: from n/a through <= 2.1.0.
CVE-2025-39496CVE-2025-39496
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Injection.This…
CVE-2025-39495CVE-2025-39495
CVSS 9.8
Deserialization of Untrusted Data vulnerability in BoldThemes Avantage avantage allows Object Injection.This issue affects Avantage: from n/a through <= 2.4.9.
CVE-2025-39494CVE-2025-39494
CVSS 9.8
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP…
CVE-2025-39489CVE-2025-39489
CVSS 9.8
Incorrect Privilege Assignment vulnerability in pebas CouponXL couponxl allows Privilege Escalation.This issue affects CouponXL: from n/a through <= 4.5.0.
CVE-2025-39485CVE-2025-39485
CVSS 9.8
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue affects Grand Tour: from n/a through <= 5…
CVE-2025-39484CVE-2025-39484
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects En…
CVE-2025-39481CVE-2025-39481
CVSS 9.8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer eventer allows Blind SQL Injection.This…
CVE-2025-39480CVE-2025-39480
CVSS 9.8
Deserialization of Untrusted Data vulnerability in ThemeMakers Car Dealer cardealer allows Object Injection.This issue affects Car Dealer: from n/a through < 1…
CVE-2025-39479CVE-2025-39479
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection…
CVE-2025-39477CVE-2025-39477
CVSS 9.8
Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWa…
CVE-2025-39474CVE-2025-39474
CVSS 9.8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Amely amely allows SQL Injection.This issue aff…
CVE-2025-39471CVE-2025-39471
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal Survey modal-survey.This issue affects M…
CVE-2025-3945CVE-2025-3945
CVSS 9.8
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterpris…
CVE-2025-39445CVE-2025-39445
CVSS 9.3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp allows …
CVE-2025-3944CVE-2025-3944
CVSS 9.8
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.