92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,151–5,200 of 8,161 in High · page 104 of 164

IDTitleSummary
CVE-2025-52263CVE-2025-52263
CVSS 8.0
An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted fir…
CVE-2025-52187CVE-2025-52187
CVSS 8.2
GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php.
CVE-2025-52164CVE-2025-52164
CVSS 8.2
Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.
CVE-2025-52159CVE-2025-52159
CVSS 8.8
Hardcoded credentials in default configuration of PPress 0.0.9.
CVE-2025-52089CVE-2025-52089
CVSS 8.8
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS …
CVE-2025-52085CVE-2025-52085
CVSS 8.8
An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint…
CVE-2025-52079CVE-2025-52079
CVSS 8.8
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted PO…
CVE-2025-52042CVE-2025-52042
CVSS 8.2
In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vulnerable to…
CVE-2025-52041CVE-2025-52041
CVSS 8.2
In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Inje…
CVE-2025-52040CVE-2025-52040
CVSS 8.2
In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can ext…
CVE-2025-52039CVE-2025-52039
CVSS 8.2
In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable t…
CVE-2025-51991CVE-2025-51991
CVSS 8.8
XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info fie…
CVE-2025-5190CVE-2025-5190
CVSS 8.8
The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is due to incorrect authentication checki…
CVE-2025-51865CVE-2025-51865
CVSS 8.8
Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to…
CVE-2025-5186CVE-2025-5186
CVSS 8.8
A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of…
CVE-2025-51726CVE-2025-51726
CVSS 8.4
CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnerable to collision attacks. This allows a…
CVE-2025-51672CVE-2025-51672
CVSS 8.0
A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability exists in the manage-c…
CVE-2025-5164CVE-2025-5164
CVSS 8.1
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handle…
CVE-2025-51629CVE-2025-51629
CVSS 8.8
A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or H…
CVE-2025-51606CVE-2025-51606
CVSS 8.8
hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled bin…
CVE-2025-51605CVE-2025-51605
CVSS 8.1
An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origi…
CVE-2025-5155CVE-2025-5155
CVSS 8.8
A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the function batchCope of the file app/adm…
CVE-2025-51534CVE-2025-51534
CVSS 8.1
A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTM…
CVE-2025-5150CVE-2025-5150
CVSS 8.8
A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/dat…
CVE-2025-5149CVE-2025-5149
CVSS 8.1
A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /in…
CVE-2025-51482CVE-2025-51482
CVSS 8.8
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Pyth…
CVE-2025-51480CVE-2025-51480
CVSS 8.8
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted …
CVE-2025-51464CVE-2025-51464
CVSS 8.8
Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitt…
CVE-2025-51414CVE-2025-51414
CVSS 8.8
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my…
CVE-2025-5139CVE-2025-5139
CVSS 8.1
A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /html/ad/adcon…
CVE-2025-5132CVE-2025-5132
CVSS 8.8
A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmall/admin/ac…
CVE-2025-5126CVE-2025-5126
CVSS 8.8
A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the file \usr\www\application\models\setti…
CVE-2025-5124CVE-2025-5124
CVSS 8.1
A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects …
CVE-2025-5117CVE-2025-5117
CVSS 8.8
The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata…
CVE-2025-51087CVE-2025-51087
CVSS 8.6tenda
Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based…
CVE-2025-51056CVE-2025-51056
CVSS 8.2vedo_suite_project
An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploit…
CVE-2025-51055CVE-2025-51055
CVSS 8.6vedo_suite_project
Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text cre…
CVE-2025-5100CVE-2025-5100
CVSS 8.0
A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory corruption and potentially arbitrary code …
CVE-2025-50983CVE-2025-50983
CVSS 8.3
SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4.15.2787. The endpoint fails to properl…
CVE-2025-50979CVE-2025-50979
CVSS 8.6
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sani…
CVE-2025-50944CVE-2025-50944
CVSS 8.8
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used…
CVE-2025-50902CVE-2025-50902
CVSS 8.8
Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensiti…
CVE-2025-50881CVE-2025-50881
CVSS 8.8
The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, th…
CVE-2025-50850CVE-2025-50850
CVSS 8.6cs-cart
An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limitin…
CVE-2025-50849CVE-2025-50849
CVSS 8.0
CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through a paramet…
CVE-2025-5080CVE-2025-5080
CVSS 8.8
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanF…
CVE-2025-50753CVE-2025-50753
CVSS 8.4
Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "deviceinfo show file" is supposed to be use…
CVE-2025-5071CVE-2025-5071
CVSS 8.8
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs…
CVE-2025-5068CVE-2025-5068
CVSS 8.8
Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…
CVE-2025-5063CVE-2025-5063
CVSS 8.8
Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.