92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,151–5,200 of 8,161 in High · page 104 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-52263 | CVE-2025-52263 CVSS 8.0 | An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted fir… |
| CVE-2025-52187 | CVE-2025-52187 CVSS 8.2 | GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php. |
| CVE-2025-52164 | CVE-2025-52164 CVSS 8.2 | Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext. |
| CVE-2025-52159 | CVE-2025-52159 CVSS 8.8 | Hardcoded credentials in default configuration of PPress 0.0.9. |
| CVE-2025-52089 | CVE-2025-52089 CVSS 8.8 | A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS … |
| CVE-2025-52085 | CVE-2025-52085 CVSS 8.8 | An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint… |
| CVE-2025-52079 | CVE-2025-52079 CVSS 8.8 | The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted PO… |
| CVE-2025-52042 | CVE-2025-52042 CVSS 8.2 | In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vulnerable to… |
| CVE-2025-52041 | CVE-2025-52041 CVSS 8.2 | In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Inje… |
| CVE-2025-52040 | CVE-2025-52040 CVSS 8.2 | In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can ext… |
| CVE-2025-52039 | CVE-2025-52039 CVSS 8.2 | In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable t… |
| CVE-2025-51991 | CVE-2025-51991 CVSS 8.8 | XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info fie… |
| CVE-2025-5190 | CVE-2025-5190 CVSS 8.8 | The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is due to incorrect authentication checki… |
| CVE-2025-51865 | CVE-2025-51865 CVSS 8.8 | Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to… |
| CVE-2025-5186 | CVE-2025-5186 CVSS 8.8 | A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of… |
| CVE-2025-51726 | CVE-2025-51726 CVSS 8.4 | CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnerable to collision attacks. This allows a… |
| CVE-2025-51672 | CVE-2025-51672 CVSS 8.0 | A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability exists in the manage-c… |
| CVE-2025-5164 | CVE-2025-5164 CVSS 8.1 | A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handle… |
| CVE-2025-51629 | CVE-2025-51629 CVSS 8.8 | A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or H… |
| CVE-2025-51606 | CVE-2025-51606 CVSS 8.8 | hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled bin… |
| CVE-2025-51605 | CVE-2025-51605 CVSS 8.1 | An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origi… |
| CVE-2025-5155 | CVE-2025-5155 CVSS 8.8 | A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the function batchCope of the file app/adm… |
| CVE-2025-51534 | CVE-2025-51534 CVSS 8.1 | A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTM… |
| CVE-2025-5150 | CVE-2025-5150 CVSS 8.8 | A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/dat… |
| CVE-2025-5149 | CVE-2025-5149 CVSS 8.1 | A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /in… |
| CVE-2025-51482 | CVE-2025-51482 CVSS 8.8 | Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Pyth… |
| CVE-2025-51480 | CVE-2025-51480 CVSS 8.8 | Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted … |
| CVE-2025-51464 | CVE-2025-51464 CVSS 8.8 | Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python code submitt… |
| CVE-2025-51414 | CVE-2025-51414 CVSS 8.8 | In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my… |
| CVE-2025-5139 | CVE-2025-5139 CVSS 8.1 | A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /html/ad/adcon… |
| CVE-2025-5132 | CVE-2025-5132 CVSS 8.8 | A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmall/admin/ac… |
| CVE-2025-5126 | CVE-2025-5126 CVSS 8.8 | A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the file \usr\www\application\models\setti… |
| CVE-2025-5124 | CVE-2025-5124 CVSS 8.1 | A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects … |
| CVE-2025-5117 | CVE-2025-5117 CVSS 8.8 | The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata… |
| CVE-2025-51087 | CVE-2025-51087 CVSS 8.6tenda | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/saveParentControlInfo. The manipulation of the argument time leads to stack-based… |
| CVE-2025-51056 | CVE-2025-51056 CVSS 8.2vedo_suite_project | An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploit… |
| CVE-2025-51055 | CVE-2025-51055 CVSS 8.6vedo_suite_project | Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text cre… |
| CVE-2025-5100 | CVE-2025-5100 CVSS 8.0 | A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory corruption and potentially arbitrary code … |
| CVE-2025-50983 | CVE-2025-50983 CVSS 8.3 | SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4.15.2787. The endpoint fails to properl… |
| CVE-2025-50979 | CVE-2025-50979 CVSS 8.6 | NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sani… |
| CVE-2025-50944 | CVE-2025-50944 CVSS 8.8 | An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used… |
| CVE-2025-50902 | CVE-2025-50902 CVSS 8.8 | Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensiti… |
| CVE-2025-50881 | CVE-2025-50881 CVSS 8.8 | The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, th… |
| CVE-2025-50850 | CVE-2025-50850 CVSS 8.6cs-cart | An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limitin… |
| CVE-2025-50849 | CVE-2025-50849 CVSS 8.0 | CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through a paramet… |
| CVE-2025-5080 | CVE-2025-5080 CVSS 8.8 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanF… |
| CVE-2025-50753 | CVE-2025-50753 CVSS 8.4 | Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "deviceinfo show file" is supposed to be use… |
| CVE-2025-5071 | CVE-2025-5071 CVSS 8.8 | The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs… |
| CVE-2025-5068 | CVE-2025-5068 CVSS 8.8 | Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro… |
| CVE-2025-5063 | CVE-2025-5063 CVSS 8.8 | Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |