92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,201–5,250 of 8,161 in High · page 105 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-5061 | CVE-2025-5061 CVSS 8.8 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' func… |
| CVE-2025-5060 | CVE-2025-5060 CVSS 8.1 | The Bravis User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly… |
| CVE-2025-50585 | CVE-2025-50585 CVSS 8.8daycloud | StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl. |
| CVE-2025-50572 | CVE-2025-50572 CVSS 8.8 | Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user… |
| CVE-2025-50503 | CVE-2025-50503 CVSS 8.8 | A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipul… |
| CVE-2025-50465 | CVE-2025-50465 CVSS 8.8 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO inter… |
| CVE-2025-50383 | CVE-2025-50383 CVSS 8.1easyappointments | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter. |
| CVE-2025-50360 | CVE-2025-50360 CVSS 8.4 | A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2bb7. Malicious execution of a pepper so… |
| CVE-2025-5030 | CVE-2025-5030 CVSS 8.1 | A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of the file … |
| CVE-2025-50286 | CVE-2025-50286 CVSS 8.1 | A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install … |
| CVE-2025-50263 | CVE-2025-50263 CVSS 8.1 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter. |
| CVE-2025-50258 | CVE-2025-50258 CVSS 8.1 | Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter. |
| CVE-2025-50189 | CVE-2025-50189 CVSS 8.8 | Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST … |
| CVE-2025-50177 | CVE-2025-50177 CVSS 8.1 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
| CVE-2025-50164 | CVE-2025-50164 CVSS 8.0 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2025-50163 | CVE-2025-50163 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-50162 | CVE-2025-50162 CVSS 8.0 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2025-50160 | CVE-2025-50160 CVSS 8.0 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2025-50151 | CVE-2025-50151 CVSS 8.8 | File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. U… |
| CVE-2025-5015 | CVE-2025-5015 CVSS 8.8 | A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a mal… |
| CVE-2025-5014 | CVE-2025-5014 CVSS 8.8 | The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wp_… |
| CVE-2025-50129 | CVE-2025-50129 CVSS 8.8 | A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a… |
| CVE-2025-5012 | CVE-2025-5012 CVSS 8.8 | The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file ty… |
| CVE-2025-50110 | CVE-2025-50110 CVSS 8.8 | An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sen… |
| CVE-2025-50106 | CVE-2025-50106 CVSS 8.1 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions t… |
| CVE-2025-50105 | CVE-2025-50105 CVSS 8.1 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). Supported versions that are aff… |
| CVE-2025-50062 | CVE-2025-50062 CVSS 8.1 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that … |
| CVE-2025-50060 | CVE-2025-50060 CVSS 8.1 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 an… |
| CVE-2025-50059 | CVE-2025-50059 CVSS 8.6 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported ve… |
| CVE-2025-50007 | CVE-2025-50007 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Jthemes xSmart xsmart allows Privilege Escalation.This issue affects xSmart: from n/a through <= 1.2.9.4. |
| CVE-2025-50004 | CVE-2025-50004 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in artbees JupiterX Core jupiterx-core allows Object Injection.This issue affects JupiterX Core: from n/a throu… |
| CVE-2025-50003 | CVE-2025-50003 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Amuli amuli allows PHP Loc… |
| CVE-2025-49994 | CVE-2025-49994 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Athens athens allows PHP Loca… |
| CVE-2025-49943 | CVE-2025-49943 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Femme femme allows PHP Lo… |
| CVE-2025-49942 | CVE-2025-49942 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gardis gardis allows PHP … |
| CVE-2025-49941 | CVE-2025-49941 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes GlamChic glamchic allows … |
| CVE-2025-4992 | CVE-2025-4992 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Relea… |
| CVE-2025-49916 | CVE-2025-49916 CVSS 8.6 | Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained by ACLs.Th… |
| CVE-2025-49910 | CVE-2025-49910 CVSS 8.2 | Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs.This iss… |
| CVE-2025-4991 | CVE-2025-4991 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEX… |
| CVE-2025-49900 | CVE-2025-49900 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in bPlugins Advanced scrollbar advanced-scrollbar allows Privilege Escalation.This issue affects Advanced scrollba… |
| CVE-2025-4990 | CVE-2025-4990 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE … |
| CVE-2025-49897 | CVE-2025-49897 CVSS 8.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical scroll slideshow gallery v2 allows Blin… |
| CVE-2025-49894 | CVE-2025-49894 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File … |
| CVE-2025-49892 | CVE-2025-49892 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Uxper Booking uxper-booking allo… |
| CVE-2025-49891 | CVE-2025-49891 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in uxper Uxper Booking uxper-booking allows Blind SQL Inject… |
| CVE-2025-4989 | CVE-2025-4989 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025… |
| CVE-2025-49889 | CVE-2025-49889 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT edge-cpt allows P… |
| CVE-2025-49886 | CVE-2025-49886 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebGeniusLab Zikzag Core zikzag-core a… |
| CVE-2025-49883 | CVE-2025-49883 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart allows PHP… |