92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,951–5,000 of 8,161 in High · page 100 of 164

IDTitleSummary
CVE-2025-53969CVE-2025-53969
CVSS 8.8
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software…
CVE-2025-53967CVE-2025-53967
CVSS 8.0
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST reques…
CVE-2025-53966CVE-2025-53966
CVSS 8.4
An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, and 1580. Incorrect Handling of the NL80211 vendor command leads to a buffer overf…
CVE-2025-5395CVE-2025-5395
CVSS 8.8
The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php' file in …
CVE-2025-53949CVE-2025-53949
CVSS 7.2fortinet
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0…
CVE-2025-53946CVE-2025-53946
CVSS 8.8
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio…
CVE-2025-53939CVE-2025-53939
CVSS 6.3accellion
Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly …
CVE-2025-53912CVE-2025-53912
CVSS 8.1
An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead …
CVE-2025-5391CVE-2025-5391
CVSS 8.1
The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() fun…
CVE-2025-53900CVE-2025-53900
CVSS 6.5accellion
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on …
CVE-2025-53896CVE-2025-53896
CVSS 7.1accellion
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a us…
CVE-2025-53895CVE-2025-53895
CVSS 8.8
ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability i…
CVE-2025-53868CVE-2025-53868
CVSS 8.7f5
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using …
CVE-2025-53847CVE-2025-53847
CVSS 6.5fortinet
A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11…
CVE-2025-53844CVE-2025-53844
CVSS 8.8fortinet
A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execu…
CVE-2025-53836CVE-2025-53836
CVSS 8.8
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting…
CVE-2025-53823CVE-2025-53823
CVSS 8.8
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection vulnerabi…
CVE-2025-53786CVE-2025-53786
CVSS 8.0microsoft
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these cha…
CVE-2025-53784CVE-2025-53784
CVSS 8.4
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-53778CVE-2025-53778
CVSS 8.8
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-53772CVE-2025-53772
CVSS 8.8
Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.
CVE-2025-5375CVE-2025-5375
CVSS 8.8
A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critical. Affected is an unknown function of t…
CVE-2025-53740CVE-2025-53740
CVSS 8.4
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-5374CVE-2025-5374
CVSS 8.8
A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affects some unknown processing of the file …
CVE-2025-53733CVE-2025-53733
CVSS 8.4
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-53731CVE-2025-53731
CVSS 8.4
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-5373CVE-2025-5373
CVSS 8.8
A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulnerability affects unknown code of the fil…
CVE-2025-53727CVE-2025-53727
CVSS 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n…
CVE-2025-53720CVE-2025-53720
CVSS 8.0
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
CVE-2025-5372CVE-2025-5372
CVSS 5.0libssh
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to i…
CVE-2025-53691CVE-2025-53691
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This …
CVE-2025-53689CVE-2025-53689
CVSS 8.8
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privi…
CVE-2025-5368CVE-2025-5368
CVSS 8.8
A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affects some unknown processing of the file…
CVE-2025-5366CVE-2025-5366
CVSS 8.1
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.
CVE-2025-53652CVE-2025-53652
CVSS 8.2
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered c…
CVE-2025-53641CVE-2025-53641
CVSS 8.2
Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into t…
CVE-2025-53637CVE-2025-53637
CVSS 8.0
Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive per…
CVE-2025-53628CVE-2025-53628
CVSS 8.8
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitt…
CVE-2025-53595CVE-2025-53595
CVSS 8.8
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to…
CVE-2025-53587CVE-2025-53587
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo findgo allows Cross Site Request Forgery.This issue affects Findgo: from n/a through <= 1.3…
CVE-2025-53586CVE-2025-53586
CVSS 8.8
Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object Injection.This issue affects WeMusic: from n/a through <= 1.9.1.
CVE-2025-53584CVE-2025-53584
CVSS 8.1
Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System wp-ticket allows Object Injection…
CVE-2025-53583CVE-2025-53583
CVSS 8.1
Deserialization of Untrusted Data vulnerability in emarket-design Employee Spotlight employee-spotlight allows Object Injection.This issue affects Employee Spo…
CVE-2025-53578CVE-2025-53578
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso kipso allows PHP Local Fi…
CVE-2025-53576CVE-2025-53576
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ovatheme Events ova-events al…
CVE-2025-53572CVE-2025-53572
CVSS 8.1
Deserialization of Untrusted Data vulnerability in emarket-design WP Easy Contact wp-easy-contact allows Object Injection.This issue affects WP Easy Contact: f…
CVE-2025-53567CVE-2025-53567
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Ghost Kit ghostkit allows PHP Local…
CVE-2025-53565CVE-2025-53565
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Widget for Google Reviews …
CVE-2025-53560CVE-2025-53560
CVSS 8.8
Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0.
CVE-2025-53558CVE-2025-53558
CVSS 8.8
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log i…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.