92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,251–5,300 of 8,161 in High · page 106 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-4988 | CVE-2025-4988 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer from Release 3DEXPERIENCE R2022x throu… |
| CVE-2025-49879 | CVE-2025-49879 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in themezaa Litho litho allows Path Traversal.This issue affects L… |
| CVE-2025-49876 | CVE-2025-49876 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-a… |
| CVE-2025-4987 | CVE-2025-4987 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Release 3DEXPERIENCE R2023x through Releas… |
| CVE-2025-49869 | CVE-2025-49869 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= … |
| CVE-2025-4986 | CVE-2025-4986 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R… |
| CVE-2025-4985 | CVE-2025-4985 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3DEXPERIENCE R2022x through Release 3DEXP… |
| CVE-2025-49847 | CVE-2025-49847 CVSS 8.8 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b5662, an attacker‐supplied GGUF model vocabulary can trigger a buffer overflow in l… |
| CVE-2025-4984 | CVE-2025-4984 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to exec… |
| CVE-2025-4983 | CVE-2025-4983 CVSS 8.7 | A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DEXPERIENCE R2025x allows an attacker to … |
| CVE-2025-49828 | CVE-2025-49828 CVSS 8.8 | Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (for… |
| CVE-2025-49759 | CVE-2025-49759 CVSS 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n… |
| CVE-2025-49758 | CVE-2025-49758 CVSS 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n… |
| CVE-2025-49757 | CVE-2025-49757 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49753 | CVE-2025-49753 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49747 | CVE-2025-49747 CVSS 8.8 | Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-49746 | CVE-2025-49746 CVSS 8.8 | Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-49740 | CVE-2025-49740 CVSS 8.8 | Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2025-49739 | CVE-2025-49739 CVSS 8.8 | Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-49735 | CVE-2025-49735 CVSS 8.1 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49729 | CVE-2025-49729 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49724 | CVE-2025-49724 CVSS 8.8 | Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49723 | CVE-2025-49723 CVSS 8.8 | Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. |
| CVE-2025-49717 | CVE-2025-49717 CVSS 8.5 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2025-49713 | CVE-2025-49713 CVSS 8.8 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49712 | CVE-2025-49712 CVSS 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-49704 | Microsoft SharePoint Code Injection Vulnerability KEVCVSS 8.8Microsoft | Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could b… |
| CVE-2025-49701 | CVE-2025-49701 CVSS 8.8 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-49697 | CVE-2025-49697 CVSS 8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-49696 | CVE-2025-49696 CVSS 8.4 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-49695 | CVE-2025-49695 CVSS 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-49691 | CVE-2025-49691 CVSS 8.0 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network. |
| CVE-2025-49688 | CVE-2025-49688 CVSS 8.8 | Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49687 | CVE-2025-49687 CVSS 8.8 | Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. |
| CVE-2025-49676 | CVE-2025-49676 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49674 | CVE-2025-49674 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49673 | CVE-2025-49673 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49672 | CVE-2025-49672 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49669 | CVE-2025-49669 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49668 | CVE-2025-49668 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49663 | CVE-2025-49663 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49657 | CVE-2025-49657 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-49653 | CVE-2025-49653 CVSS 8.0 | Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform. |
| CVE-2025-49651 | CVE-2025-49651 CVSS 8.1 | Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the sessi… |
| CVE-2025-49619 | CVE-2025-49619 CVSS 8.5 | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper … |
| CVE-2025-49587 | CVE-2025-49587 CVSS 8.0 | XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass… |
| CVE-2025-49586 | CVE-2025-49586 CVSS 8.8 | XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki)… |
| CVE-2025-49585 | CVE-2025-49585 CVSS 8.0 | XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or … |
| CVE-2025-49582 | CVE-2025-49582 CVSS 8.0 | XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer ri… |
| CVE-2025-49581 | CVE-2025-49581 CVSS 8.8 | XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming… |