33,486 indexed

CVECVE vulnerabilities

33,486 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 7,401–7,450 of 8,314 in Critical · page 149 of 167

IDTitleSummary
CVE-2025-14659CVE-2025-14659
CVSS 9.8
A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation …
CVE-2025-14653CVE-2025-14653
CVSS 9.8
A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /addrecord.php. This manipulation of …
CVE-2025-14652CVE-2025-14652
CVSS 9.8
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?action=edit.…
CVE-2025-14650CVE-2025-14650
CVSS 9.8
A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing manipulation o…
CVE-2025-14649CVE-2025-14649
CVSS 9.8
A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown functionality of the file /cakeshop/suppli…
CVE-2025-14647CVE-2025-14647
CVSS 9.8
A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of th…
CVE-2025-14646CVE-2025-14646
CVSS 9.8
A security flaw has been discovered in code-projects Student File Management System 1.0. This impacts an unknown function of the file /admin/delete_student.php…
CVE-2025-14645CVE-2025-14645
CVSS 9.8
A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of the file /admin/delete_user.php. The ma…
CVE-2025-14644CVE-2025-14644
CVSS 9.8
A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /update_subject.php. Exec…
CVE-2025-14643CVE-2025-14643
CVSS 9.8
A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown function of the file /check.php. Performing …
CVE-2025-14640CVE-2025-14640
CVSS 9.8
A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /admin/save_student.php. Exe…
CVE-2025-14639CVE-2025-14639
CVSS 9.8
A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /uprec.php. Performing manipulation of …
CVE-2025-14638CVE-2025-14638
CVSS 9.8
A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects some unknown processing of the file /pet1/…
CVE-2025-14637CVE-2025-14637
CVSS 9.8
A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. Thi…
CVE-2025-14623CVE-2025-14623
CVSS 9.8
A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown processing of the file /admin/update_studen…
CVE-2025-14622CVE-2025-14622
CVSS 9.8
A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.p…
CVE-2025-14621CVE-2025-14621
CVSS 9.8
A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipu…
CVE-2025-14620CVE-2025-14620
CVSS 9.8
A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/log…
CVE-2025-14619CVE-2025-14619
CVSS 9.8
A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login_que…
CVE-2025-14611Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
KEVCVSS 9.8Gladinet
Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degr…
CVE-2025-14598CVE-2025-14598
CVSS 9.8
BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQ…
CVE-2025-14590CVE-2025-14590
CVSS 9.8
A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown function of the file /admin/search1.php. The m…
CVE-2025-14588CVE-2025-14588
CVSS 9.8
A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /update_program.php. Per…
CVE-2025-14587CVE-2025-14587
CVSS 9.8
A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of the file /pet1/available.php. Such manipu…
CVE-2025-14586CVE-2025-14586
CVSS 9.8
A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?acti…
CVE-2025-14585CVE-2025-14585
CVSS 9.8
A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=zone. …
CVE-2025-14584CVE-2025-14584
CVSS 9.8
A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin L…
CVE-2025-14583CVE-2025-14583
CVSS 9.8
A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing a manipula…
CVE-2025-14578CVE-2025-14578
CVSS 9.8
A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /update_account.php. This…
CVE-2025-14577CVE-2025-14577
CVSS 9.8
Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sendin…
CVE-2025-14571CVE-2025-14571
CVSS 9.8
A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /borro…
CVE-2025-14570CVE-2025-14570
CVSS 9.8
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_adm…
CVE-2025-14566CVE-2025-14566
CVSS 9.8
A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function…
CVE-2025-14565CVE-2025-14565
CVSS 9.8
A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of t…
CVE-2025-14543CVE-2025-14543
CVSS 9.1
Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue…
CVE-2025-14537CVE-2025-14537
CVSS 9.8
A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some unknown functionality of the file /prev…
CVE-2025-14536CVE-2025-14536
CVSS 9.8
A security flaw has been discovered in code-projects Class and Exam Timetable Management 1.0. Affected by this vulnerability is an unknown functionality of the…
CVE-2025-14535CVE-2025-14535
CVSS 9.8
A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulat…
CVE-2025-14534CVE-2025-14534
CVSS 9.8
A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endp…
CVE-2025-14533CVE-2025-14533
CVSS 9.8
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to t…
CVE-2025-14532CVE-2025-14532
CVSS 9.8
DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result …
CVE-2025-14529CVE-2025-14529
CVSS 9.8
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. T…
CVE-2025-14527CVE-2025-14527
CVSS 9.8
A weakness has been identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /view_book.php. Exe…
CVE-2025-14522CVE-2025-14522
CVSS 9.8
A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /Public/Kin…
CVE-2025-14520CVE-2025-14520
CVSS 9.1
A weakness has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of the file /admin/index.php/data…
CVE-2025-14518CVE-2025-14518
CVSS 9.8
A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/commo…
CVE-2025-14515CVE-2025-14515
CVSS 9.8
A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_u…
CVE-2025-14514CVE-2025-14514
CVSS 9.8
A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of…
CVE-2025-14502CVE-2025-14502
CVSS 9.8
The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the template paramet…
CVE-2025-14500CVE-2025-14500
CVSS 9.8
IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.