92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,101–5,150 of 8,161 in High · page 103 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-52812 | CVE-2025-52812 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Domnoo domnoo allows PHP Local … |
| CVE-2025-52811 | CVE-2025-52811 CVSS 8.1 | Path Traversal: '.../...//' vulnerability in Creanncy Davenport - Versatile Blog and Magazine WordPress Theme davenport allows PHP Local File Inclusion.This is… |
| CVE-2025-52810 | CVE-2025-52810 CVSS 8.1 | Path Traversal vulnerability in TMRW-studio Katerio - Magazine allows PHP Local File Inclusion. This issue affects Katerio - Magazine: from n/a through 1.5.1. |
| CVE-2025-52809 | CVE-2025-52809 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Russell National Weather Service … |
| CVE-2025-52808 | CVE-2025-52808 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in real-web RealtyElite realtyelite allow… |
| CVE-2025-52807 | CVE-2025-52807 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCommerce Wo… |
| CVE-2025-5280 | CVE-2025-5280 CVSS 8.8 | Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch… |
| CVE-2025-52797 | CVE-2025-52797 CVSS 8.2 | Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap wp-storymap allows SQL Injection.This issue affects StoryMap: from n/a through <= 2.1. |
| CVE-2025-52768 | CVE-2025-52768 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Faith & Hope faith-hope a… |
| CVE-2025-52745 | CVE-2025-52745 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Farm Agrico farmagrico al… |
| CVE-2025-52740 | CVE-2025-52740 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows Object Injection.This issue affects Boldermail: from n/a thro… |
| CVE-2025-52737 | CVE-2025-52737 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator allows Object Injection.This issue affects WP Store Locator: f… |
| CVE-2025-52732 | CVE-2025-52732 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 GMap Targeting gmap-targeti… |
| CVE-2025-52729 | CVE-2025-52729 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local Fil… |
| CVE-2025-52726 | CVE-2025-52726 CVSS 8.6 | Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types couponxxl-cpt allows Privilege Escalation.This issue affects CouponXxL Custom… |
| CVE-2025-52723 | CVE-2025-52723 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codesupplyco Networker networker allow… |
| CVE-2025-52692 | CVE-2025-52692 CVSS 8.8linksys | Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration… |
| CVE-2025-52690 | CVE-2025-52690 CVSS 8.1 | Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality,… |
| CVE-2025-5269 | CVE-2025-5269 CVSS 8.1mozilla | Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort t… |
| CVE-2025-5268 | CVE-2025-5268 CVSS 8.1mozilla | Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption… |
| CVE-2025-52664 | CVE-2025-52664 CVSS 8.8revive-adserver | SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users |
| CVE-2025-52644 | CVE-2025-52644 CVSS 8.2 | HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce t… |
| CVE-2025-52631 | CVE-2025-52631 CVSS 8.1 | HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially expo… |
| CVE-2025-52628 | CVE-2025-52628 CVSS 8.8 | HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potenti… |
| CVE-2025-52613 | CVE-2025-52613 CVSS 4.6hcltech | HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the … |
| CVE-2025-5260 | CVE-2025-5260 CVSS 8.6 | Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Request Forgery. This issue affects Pik On… |
| CVE-2025-52577 | CVE-2025-52577 CVSS 8.8 | A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requ… |
| CVE-2025-52566 | CVE-2025-52566 CVSS 8.8 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer impl… |
| CVE-2025-52560 | CVE-2025-52560 CVSS 8.8 | Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be sent with … |
| CVE-2025-52538 | CVE-2025-52538 CVSS 8.0 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in loss of confide… |
| CVE-2025-52488 | CVE-2025-52488 CVSS 8.6 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM … |
| CVE-2025-52482 | CVE-2025-52482 CVSS 8.3 | Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teac… |
| CVE-2025-52477 | CVE-2025-52477 CVSS 8.6 | Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SS… |
| CVE-2025-52464 | CVE-2025-52464 CVSS 8.3 | Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resultin… |
| CVE-2025-52456 | CVE-2025-52456 CVSS 8.8 | A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .… |
| CVE-2025-52454 | CVE-2025-52454 CVSS 8.2 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing… |
| CVE-2025-52453 | CVE-2025-52453 CVSS 8.2 | Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. T… |
| CVE-2025-52452 | CVE-2025-52452 CVSS 8.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - dupli… |
| CVE-2025-52451 | CVE-2025-52451 CVSS 8.5 | Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolu… |
| CVE-2025-52449 | CVE-2025-52449 CVSS 8.5 | Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alter… |
| CVE-2025-52448 | CVE-2025-52448 CVSS 8.1 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interfa… |
| CVE-2025-52447 | CVE-2025-52447 CVSS 8.1 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows I… |
| CVE-2025-52446 | CVE-2025-52446 CVSS 8.0 | Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulati… |
| CVE-2025-52389 | CVE-2025-52389 CVSS 8.8 | An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other u… |
| CVE-2025-52360 | CVE-2025-52360 CVSS 8.8 | A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. Unsanitized input entered in the search … |
| CVE-2025-52351 | CVE-2025-52351 CVSS 8.8 | Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email and also includes the same password as … |
| CVE-2025-52289 | CVE-2025-52289 CVSS 8.0 | A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbi… |
| CVE-2025-52287 | CVE-2025-52287 CVSS 8.8 | OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability. |
| CVE-2025-5228 | CVE-2025-5228 CVSS 8.8 | A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi … |
| CVE-2025-52264 | CVE-2025-52264 CVSS 8.0 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi. |