92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,051–5,100 of 8,161 in High · page 102 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-53192 | CVE-2025-53192 CVSS 8.8 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commo… |
| CVE-2025-5318 | CVE-2025-5318 CVSS 5.4redhat | A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect com… |
| CVE-2025-53145 | CVE-2025-53145 CVSS 8.8 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. |
| CVE-2025-53144 | CVE-2025-53144 CVSS 8.8 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. |
| CVE-2025-53143 | CVE-2025-53143 CVSS 8.8 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. |
| CVE-2025-53131 | CVE-2025-53131 CVSS 8.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. |
| CVE-2025-53106 | CVE-2025-53106 CVSS 8.8 | Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated p… |
| CVE-2025-53098 | CVE-2025-53098 CVSS 8.1 | Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within t… |
| CVE-2025-53095 | CVE-2025-53095 CVSS 8.8 | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Fo… |
| CVE-2025-53093 | CVE-2025-53093 CVSS 8.6 | TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HT… |
| CVE-2025-53085 | CVE-2025-53085 CVSS 8.8 | A memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data fro… |
| CVE-2025-53049 | CVE-2025-53049 CVSS 8.4oracle | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions… |
| CVE-2025-53043 | CVE-2025-53043 CVSS 8.1oracle | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.14.… |
| CVE-2025-53036 | CVE-2025-53036 CVSS 8.6oracle | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). … |
| CVE-2025-53028 | CVE-2025-53028 CVSS 8.2 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploi… |
| CVE-2025-53027 | CVE-2025-53027 CVSS 8.2 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploi… |
| CVE-2025-53024 | CVE-2025-53024 CVSS 8.2 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploi… |
| CVE-2025-53022 | CVE-2025-53022 CVSS 8.6 | TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While pr… |
| CVE-2025-5302 | CVE-2025-5302 CVSS 8.6 | A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerabili… |
| CVE-2025-52970 | CVE-2025-52970 CVSS 8.1 | A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may … |
| CVE-2025-52930 | CVE-2025-52930 CVSS 8.8 | A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data f… |
| CVE-2025-52914 | CVE-2025-52914 CVSS 8.8 | A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to condu… |
| CVE-2025-52907 | CVE-2025-52907 CVSS 8.8 | Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B202412… |
| CVE-2025-52904 | CVE-2025-52904 CVSS 8.0filebrowser | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions … |
| CVE-2025-52903 | CVE-2025-52903 CVSS 8.0filebrowser | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions … |
| CVE-2025-52898 | CVE-2025-52898 CVSS 8.8 | Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting ac… |
| CVE-2025-52890 | CVE-2025-52890 CVSS 8.1 | Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables ru… |
| CVE-2025-52873 | CVE-2025-52873 CVSS 8.1 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and d… |
| CVE-2025-52872 | CVE-2025-52872 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then ex… |
| CVE-2025-52870 | CVE-2025-52870 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t… |
| CVE-2025-52869 | CVE-2025-52869 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t… |
| CVE-2025-52868 | CVE-2025-52868 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t… |
| CVE-2025-52864 | CVE-2025-52864 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then ex… |
| CVE-2025-52863 | CVE-2025-52863 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then ex… |
| CVE-2025-52841 | CVE-2025-52841 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This issue affects Laundry: 2.3.0. |
| CVE-2025-52828 | CVE-2025-52828 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Red Art redart allows Object Injection.This issue affects Red Art: from n/a through <= 3.8. |
| CVE-2025-52827 | CVE-2025-52827 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in uxper Nuss nuss allows Object Injection.This issue affects Nuss: from n/a through <= 1.3.3. |
| CVE-2025-52826 | CVE-2025-52826 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in uxper Sala allows Object Injection. This issue affects Sala: from n/a through 1.1.3. |
| CVE-2025-52825 | CVE-2025-52825 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Privilege Escalation.This issue affects Real Est… |
| CVE-2025-52824 | CVE-2025-52824 CVSS 8.8 | Missing Authorization vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This is… |
| CVE-2025-52823 | CVE-2025-52823 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ovatheme Cube Portfolio cubeportfolio allows SQL Injectio… |
| CVE-2025-52822 | CVE-2025-52822 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WP Roadmap wp-roadmap allows SQL Injection.… |
| CVE-2025-52821 | CVE-2025-52821 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager video-list-manager allows… |
| CVE-2025-52820 | CVE-2025-52820 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin WooCommerce Point Of Sale (POS) woo-point-… |
| CVE-2025-52819 | CVE-2025-52819 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pakkemx Pakke Envíos pakke allows SQL Injection.This issu… |
| CVE-2025-52818 | CVE-2025-52818 CVSS 8.2 | Missing Authorization vulnerability in Dejan Jasnic Trusty Whistleblowing trusty-whistleblowing-solution allows Exploiting Incorrectly Configured Access Contro… |
| CVE-2025-52817 | CVE-2025-52817 CVSS 8.2 | Missing Authorization vulnerability in ZealousWeb Abandoned Contact Form 7 abandoned-contact-form-7 allows Exploiting Incorrectly Configured Access Control Sec… |
| CVE-2025-52815 | CVE-2025-52815 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CityGov citygov allows PH… |
| CVE-2025-52814 | CVE-2025-52814 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme BRW ova-brw allows PHP Local … |
| CVE-2025-52813 | CVE-2025-52813 CVSS 8.1 | Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: fr… |