31,594 indexed

CVECVE vulnerabilities

31,594 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 2,651–2,700 of 8,314 in Critical · page 54 of 167

IDTitleSummary
CVE-2025-9149CVE-2025-9149
CVSS 9.8
A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation o…
CVE-2025-9114CVE-2025-9114
CVSS 9.8
The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0. This is due to the plugin providing us…
CVE-2025-9113CVE-2025-9113
CVSS 9.8
The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'doccure_temp_upload_to_media' functio…
CVE-2025-9090CVE-2025-9090
CVSS 9.8
A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. T…
CVE-2025-9089CVE-2025-9089
CVSS 9.8
A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform/SetIpMacBind. The manipulation of the …
CVE-2025-9088CVE-2025-9088
CVSS 9.8
A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the file /goform/formSetVirtualSer. The ma…
CVE-2025-9087CVE-2025-9087
CVSS 9.8
A vulnerability has been found in Tenda AC20 16.03.08.12. This affects the function set_qosMib_list of the file /goform/SetNetControlList of the component SetN…
CVE-2025-9083CVE-2025-9083
CVSS 9.8
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection…
CVE-2025-9064CVE-2025-9064
CVSS 9.1
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete …
CVE-2025-9063CVE-2025-9063
CVSS 9.8
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows …
CVE-2025-9060CVE-2025-9060
CVSS 9.1
A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration …
CVE-2025-9054CVE-2025-9054
CVSS 9.8
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privi…
CVE-2025-9053CVE-2025-9053
CVSS 9.8
A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /updatesubcategory.php. The m…
CVE-2025-9052CVE-2025-9052
CVSS 9.8
A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file /updatepackage.php. The manipulation of …
CVE-2025-9051CVE-2025-9051
CVSS 9.8
A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /updatecategory.…
CVE-2025-9050CVE-2025-9050
CVSS 9.8
A vulnerability was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /addcategory.ph…
CVE-2025-9047CVE-2025-9047
CVSS 9.8
A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /visitor_out.php. The manipulation o…
CVE-2025-9028CVE-2025-9028
CVSS 9.8
A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /adphar.php. Executing manipulation of th…
CVE-2025-9027CVE-2025-9027
CVSS 9.8
A vulnerability has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /addelivery.php. The manipulatio…
CVE-2025-9026CVE-2025-9026
CVSS 9.8
A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple Service Di…
CVE-2025-9024CVE-2025-9024
CVSS 9.8
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /book-appo…
CVE-2025-9022CVE-2025-9022
CVSS 9.8
A vulnerability was identified in SourceCodester Online Bank Management System up to 1.0. This issue affects some unknown processing of the file /bank/statemen…
CVE-2025-9021CVE-2025-9021
CVSS 9.8
A vulnerability was determined in SourceCodester Online Bank Management System up to 1.0. This vulnerability affects unknown code of the file /bank/transfer.ph…
CVE-2025-9013CVE-2025-9013
CVSS 9.8
A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recover…
CVE-2025-9012CVE-2025-9012
CVSS 9.8
A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The…
CVE-2025-9011CVE-2025-9011
CVSS 9.8
A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/sig…
CVE-2025-9010CVE-2025-9010
CVSS 9.8
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …
CVE-2025-9009CVE-2025-9009
CVSS 9.8
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/email_setup.php…
CVE-2025-9008CVE-2025-9008
CVSS 9.8
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/sms_…
CVE-2025-9004CVE-2025-9004
CVSS 9.1
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to impr…
CVE-2025-9002CVE-2025-9002
CVSS 9.8
A vulnerability was identified in Surbowl dormitory-management-php 1.0. This affects an unknown part of the file login.php. The manipulation of the argument Ac…
CVE-2025-8995CVE-2025-8995
CVSS 9.8
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authentica…
CVE-2025-8993CVE-2025-8993
CVSS 9.8
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/expense_report.php. The…
CVE-2025-8990CVE-2025-8990
CVSS 9.8
A vulnerability was determined in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /browsemdcn.php. The manipulation of the…
CVE-2025-8989CVE-2025-8989
CVSS 9.8
A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. This issue affects some unknown processing of the file /edit-phlebotomist.p…
CVE-2025-8988CVE-2025-8988
CVSS 9.8
A vulnerability has been found in SourceCodester COVID 19 Testing Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-re…
CVE-2025-8987CVE-2025-8987
CVSS 9.8
A vulnerability was identified in SourceCodester COVID 19 Testing Management System 1.0. This affects an unknown part of the file /test-details.php. The manipu…
CVE-2025-8986CVE-2025-8986
CVSS 9.8
A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /sear…
CVE-2025-8985CVE-2025-8985
CVSS 9.8
A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /pro…
CVE-2025-8984CVE-2025-8984
CVSS 9.8
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/expe…
CVE-2025-8983CVE-2025-8983
CVSS 9.8
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/oper…
CVE-2025-8982CVE-2025-8982
CVSS 9.8
A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operati…
CVE-2025-8981CVE-2025-8981
CVSS 9.8
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/operations/payment.php.…
CVE-2025-8974CVE-2025-8974
CVSS 9.8
A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/ja…
CVE-2025-8973CVE-2025-8973
CVSS 9.8
A vulnerability has been found in SourceCodester Cashier Queuing System 1.0. Affected is an unknown function of the file /Actions.php. The manipulation of the …
CVE-2025-8972CVE-2025-8972
CVSS 9.8
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/page…
CVE-2025-8971CVE-2025-8971
CVSS 9.8
A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operati…
CVE-2025-8970CVE-2025-8970
CVSS 9.8
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/operations/booking.php.…
CVE-2025-8969CVE-2025-8969
CVSS 9.8
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /…
CVE-2025-8968CVE-2025-8968
CVSS 9.8
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.