92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,101–5,150 of 8,161 in High · page 103 of 164

IDTitleSummary
CVE-2025-52812CVE-2025-52812
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Domnoo domnoo allows PHP Local …
CVE-2025-52811CVE-2025-52811
CVSS 8.1
Path Traversal: '.../...//' vulnerability in Creanncy Davenport - Versatile Blog and Magazine WordPress Theme davenport allows PHP Local File Inclusion.This is…
CVE-2025-52810CVE-2025-52810
CVSS 8.1
Path Traversal vulnerability in TMRW-studio Katerio - Magazine allows PHP Local File Inclusion. This issue affects Katerio - Magazine: from n/a through 1.5.1.
CVE-2025-52809CVE-2025-52809
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Russell National Weather Service …
CVE-2025-52808CVE-2025-52808
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in real-web RealtyElite realtyelite allow…
CVE-2025-52807CVE-2025-52807
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCommerce Wo…
CVE-2025-5280CVE-2025-5280
CVSS 8.8
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…
CVE-2025-52797CVE-2025-52797
CVSS 8.2
Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap wp-storymap allows SQL Injection.This issue affects StoryMap: from n/a through <= 2.1.
CVE-2025-52768CVE-2025-52768
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Faith & Hope faith-hope a…
CVE-2025-52745CVE-2025-52745
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Farm Agrico farmagrico al…
CVE-2025-52740CVE-2025-52740
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows Object Injection.This issue affects Boldermail: from n/a thro…
CVE-2025-52737CVE-2025-52737
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator allows Object Injection.This issue affects WP Store Locator: f…
CVE-2025-52732CVE-2025-52732
CVSS 8.8
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 GMap Targeting gmap-targeti…
CVE-2025-52729CVE-2025-52729
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local Fil…
CVE-2025-52726CVE-2025-52726
CVSS 8.6
Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types couponxxl-cpt allows Privilege Escalation.This issue affects CouponXxL Custom…
CVE-2025-52723CVE-2025-52723
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codesupplyco Networker networker allow…
CVE-2025-52692CVE-2025-52692
CVSS 8.8linksys
Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration…
CVE-2025-52690CVE-2025-52690
CVSS 8.1
Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially leading to the loss of confidentiality,…
CVE-2025-5269CVE-2025-5269
CVSS 8.1mozilla
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort t…
CVE-2025-5268CVE-2025-5268
CVSS 8.1mozilla
Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption…
CVE-2025-52664CVE-2025-52664
CVSS 8.8revive-adserver
SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users
CVE-2025-52644CVE-2025-52644
CVSS 8.2
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce t…
CVE-2025-52631CVE-2025-52631
CVSS 8.1
HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially expo…
CVE-2025-52628CVE-2025-52628
CVSS 8.8
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potenti…
CVE-2025-52613CVE-2025-52613
CVSS 4.6hcltech
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the …
CVE-2025-5260CVE-2025-5260
CVSS 8.6
Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Request Forgery. This issue affects Pik On…
CVE-2025-52577CVE-2025-52577
CVSS 8.8
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requ…
CVE-2025-52566CVE-2025-52566
CVSS 8.8
llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer impl…
CVE-2025-52560CVE-2025-52560
CVSS 8.8
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be sent with …
CVE-2025-52538CVE-2025-52538
CVSS 8.0
Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in loss of confide…
CVE-2025-52488CVE-2025-52488
CVSS 8.6
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM …
CVE-2025-52482CVE-2025-52482
CVSS 8.3
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teac…
CVE-2025-52477CVE-2025-52477
CVSS 8.6
Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SS…
CVE-2025-52464CVE-2025-52464
CVSS 8.3
Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resultin…
CVE-2025-52456CVE-2025-52456
CVSS 8.8
A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .…
CVE-2025-52454CVE-2025-52454
CVSS 8.2
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing…
CVE-2025-52453CVE-2025-52453
CVSS 8.2
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. T…
CVE-2025-52452CVE-2025-52452
CVSS 8.5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - dupli…
CVE-2025-52451CVE-2025-52451
CVSS 8.5
Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolu…
CVE-2025-52449CVE-2025-52449
CVSS 8.5
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alter…
CVE-2025-52448CVE-2025-52448
CVSS 8.1
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interfa…
CVE-2025-52447CVE-2025-52447
CVSS 8.1
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows I…
CVE-2025-52446CVE-2025-52446
CVSS 8.0
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulati…
CVE-2025-52389CVE-2025-52389
CVSS 8.8
An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other u…
CVE-2025-52360CVE-2025-52360
CVSS 8.8
A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. Unsanitized input entered in the search …
CVE-2025-52351CVE-2025-52351
CVSS 8.8
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 sends a newly generated password to users in plaintext via email and also includes the same password as …
CVE-2025-52289CVE-2025-52289
CVSS 8.0
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbi…
CVE-2025-52287CVE-2025-52287
CVSS 8.8
OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.
CVE-2025-5228CVE-2025-5228
CVSS 8.8
A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi …
CVE-2025-52264CVE-2025-52264
CVSS 8.0
StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.