92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,001–5,050 of 8,161 in High · page 101 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-53547 | CVE-2025-53547 CVSS 8.6 | Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lea… |
| CVE-2025-53536 | CVE-2025-53536 CVSS 8.1 | Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker with the ability to submit prompts to … |
| CVE-2025-53520 | CVE-2025-53520 CVSS 8.8 | The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitoring Center (… |
| CVE-2025-53515 | CVE-2025-53515 CVSS 8.8 | A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires a… |
| CVE-2025-53510 | CVE-2025-53510 CVSS 8.8 | A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .p… |
| CVE-2025-53501 | CVE-2025-53501 CVSS 8.8 | Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Auth… |
| CVE-2025-5349 | CVE-2025-5349 CVSS 8.8 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway |
| CVE-2025-53483 | CVE-2025-53483 CVSS 8.8 | ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF tokens, allowing attackers to trigger sensi… |
| CVE-2025-53475 | CVE-2025-53475 CVSS 8.8 | A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue r… |
| CVE-2025-53468 | CVE-2025-53468 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail.com Wp tabber widget wp-tabber-widget al… |
| CVE-2025-53453 | CVE-2025-53453 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Hygia hygia allows PHP Loc… |
| CVE-2025-53449 | CVE-2025-53449 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Convex convex allows PHP L… |
| CVE-2025-53448 | CVE-2025-53448 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rally rally allows PHP Loc… |
| CVE-2025-53447 | CVE-2025-53447 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Assembly assembly allows P… |
| CVE-2025-53446 | CVE-2025-53446 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Beautique beautique allows… |
| CVE-2025-53445 | CVE-2025-53445 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Catwalk catwalk allows PHP… |
| CVE-2025-53443 | CVE-2025-53443 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Smash smash allows PHP Loc… |
| CVE-2025-53442 | CVE-2025-53442 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rentic rentic allows PHP L… |
| CVE-2025-53441 | CVE-2025-53441 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Greeny greeny allows PHP L… |
| CVE-2025-53439 | CVE-2025-53439 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Harper harper allows PHP L… |
| CVE-2025-53438 | CVE-2025-53438 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes FitLine fitline allows PHP… |
| CVE-2025-53437 | CVE-2025-53437 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Greenorganic greenorganic al… |
| CVE-2025-53436 | CVE-2025-53436 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Monki monki allows PHP Local … |
| CVE-2025-53435 | CVE-2025-53435 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Plan My Day planmyday allo… |
| CVE-2025-53434 | CVE-2025-53434 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ChildHope childhope allow… |
| CVE-2025-53432 | CVE-2025-53432 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Echo echo allows PHP Loca… |
| CVE-2025-53431 | CVE-2025-53431 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Emberlyn emberlyn allows … |
| CVE-2025-53430 | CVE-2025-53430 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Etta etta allows PHP Loca… |
| CVE-2025-53429 | CVE-2025-53429 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Exit Game exit-game allow… |
| CVE-2025-53428 | CVE-2025-53428 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simple User Reg… |
| CVE-2025-53418 | CVE-2025-53418 CVSS 8.6 | Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability. |
| CVE-2025-53376 | CVE-2025-53376 CVSS 8.8 | Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated, low-priv… |
| CVE-2025-53369 | CVE-2025-53369 CVSS 8.6 | Short Description is a MediaWiki extension that provides local short description support. In version 4.0.0, short descriptions are not properly sanitized befor… |
| CVE-2025-53335 | CVE-2025-53335 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Berger berger allows PHP Loca… |
| CVE-2025-53334 | CVE-2025-53334 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local… |
| CVE-2025-53303 | CVE-2025-53303 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core: from n/a … |
| CVE-2025-5328 | CVE-2025-5328 CVSS 8.8 | A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sys/apps/con… |
| CVE-2025-53277 | CVE-2025-53277 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Infigo Software IS-theme-companion weblizar-companion allows Object Injection.This issue affects IS-theme-co… |
| CVE-2025-5327 | CVE-2025-5327 CVSS 8.8 | A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/api/Gf.php… |
| CVE-2025-5326 | CVE-2025-5326 CVSS 8.8 | A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Affected by this issue is some … |
| CVE-2025-53248 | CVE-2025-53248 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Magazine eximious-magazine al… |
| CVE-2025-53247 | CVE-2025-53247 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpinterface BlogMarks blogmarks allows… |
| CVE-2025-53244 | CVE-2025-53244 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Magazine Elite magazine-elite… |
| CVE-2025-53243 | CVE-2025-53243 CVSS 8.1 | Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-directory a… |
| CVE-2025-53227 | CVE-2025-53227 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Magazine Saga magazine-saga a… |
| CVE-2025-53216 | CVE-2025-53216 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeuniver Glamer glamer allows PHP L… |
| CVE-2025-53207 | CVE-2025-53207 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel WP Travel Gutenberg Blocks w… |
| CVE-2025-53204 | CVE-2025-53204 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme eventlist eventlist allows PH… |
| CVE-2025-53198 | CVE-2025-53198 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez allows PHP Lo… |
| CVE-2025-53194 | CVE-2025-53194 CVSS 8.5 | Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Code Injection.This issue affects JetEngine: from n/a through <= 3.7.… |