92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,051–5,100 of 8,161 in High · page 102 of 164

IDTitleSummary
CVE-2025-53192CVE-2025-53192
CVSS 8.8
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commo…
CVE-2025-5318CVE-2025-5318
CVSS 5.4redhat
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect com…
CVE-2025-53145CVE-2025-53145
CVSS 8.8
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
CVE-2025-53144CVE-2025-53144
CVSS 8.8
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
CVE-2025-53143CVE-2025-53143
CVSS 8.8
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
CVE-2025-53131CVE-2025-53131
CVSS 8.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-53106CVE-2025-53106
CVSS 8.8
Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated p…
CVE-2025-53098CVE-2025-53098
CVSS 8.1
Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within t…
CVE-2025-53095CVE-2025-53095
CVSS 8.8
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Fo…
CVE-2025-53093CVE-2025-53093
CVSS 8.6
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HT…
CVE-2025-53085CVE-2025-53085
CVSS 8.8
A memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data fro…
CVE-2025-53049CVE-2025-53049
CVSS 8.4oracle
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions…
CVE-2025-53043CVE-2025-53043
CVSS 8.1oracle
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.14.…
CVE-2025-53036CVE-2025-53036
CVSS 8.6oracle
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). …
CVE-2025-53028CVE-2025-53028
CVSS 8.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploi…
CVE-2025-53027CVE-2025-53027
CVSS 8.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploi…
CVE-2025-53024CVE-2025-53024
CVSS 8.2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploi…
CVE-2025-53022CVE-2025-53022
CVSS 8.6
TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While pr…
CVE-2025-5302CVE-2025-5302
CVSS 8.6
A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerabili…
CVE-2025-52970CVE-2025-52970
CVSS 8.1
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may …
CVE-2025-52930CVE-2025-52930
CVSS 8.8
A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data f…
CVE-2025-52914CVE-2025-52914
CVSS 8.8
A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to condu…
CVE-2025-52907CVE-2025-52907
CVSS 8.8
Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B202412…
CVE-2025-52904CVE-2025-52904
CVSS 8.0filebrowser
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions …
CVE-2025-52903CVE-2025-52903
CVSS 8.0filebrowser
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions …
CVE-2025-52898CVE-2025-52898
CVSS 8.8
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting ac…
CVE-2025-52890CVE-2025-52890
CVSS 8.1
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables ru…
CVE-2025-52873CVE-2025-52873
CVSS 8.1
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and d…
CVE-2025-52872CVE-2025-52872
CVSS 8.1
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then ex…
CVE-2025-52870CVE-2025-52870
CVSS 8.1
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t…
CVE-2025-52869CVE-2025-52869
CVSS 8.1
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t…
CVE-2025-52868CVE-2025-52868
CVSS 8.1
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t…
CVE-2025-52864CVE-2025-52864
CVSS 8.1
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then ex…
CVE-2025-52863CVE-2025-52863
CVSS 8.1
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then ex…
CVE-2025-52841CVE-2025-52841
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This issue affects Laundry: 2.3.0.
CVE-2025-52828CVE-2025-52828
CVSS 8.8
Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affects Red Art: from n/a through <= 3.8.
CVE-2025-52827CVE-2025-52827
CVSS 8.8
Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from n/a through <= 1.3.3.
CVE-2025-52826CVE-2025-52826
CVSS 8.8
Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3.
CVE-2025-52825CVE-2025-52825
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Privilege Escalation.This issue affects Real Est…
CVE-2025-52824CVE-2025-52824
CVSS 8.8
Missing Authorization vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This is…
CVE-2025-52823CVE-2025-52823
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ovatheme Cube Portfolio cubeportfolio allows SQL Injectio…
CVE-2025-52822CVE-2025-52822
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WP Roadmap wp-roadmap allows SQL Injection.…
CVE-2025-52821CVE-2025-52821
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager video-list-manager allows…
CVE-2025-52820CVE-2025-52820
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) woo-point-…
CVE-2025-52819CVE-2025-52819
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Envíos pakke allows SQL Injection.This issu…
CVE-2025-52818CVE-2025-52818
CVSS 8.2
Missing Authorization vulnerability in Dejan Jasnic Trusty Whistleblowing trusty-whistleblowing-solution allows Exploiting Incorrectly Configured Access Contro…
CVE-2025-52817CVE-2025-52817
CVSS 8.2
Missing Authorization vulnerability in ZealousWeb Abandoned Contact Form 7 abandoned-contact-form-7 allows Exploiting Incorrectly Configured Access Control Sec…
CVE-2025-52815CVE-2025-52815
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CityGov citygov allows PH…
CVE-2025-52814CVE-2025-52814
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme BRW ova-brw allows PHP Local …
CVE-2025-52813CVE-2025-52813
CVSS 8.1
Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: fr…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.