92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,351–5,400 of 8,161 in High · page 108 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-49276 | CVE-2025-49276 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Blogmine blogmine allows PHP … |
| CVE-2025-49275 | CVE-2025-49275 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Blogbyte blogbyte allows PHP … |
| CVE-2025-49267 | CVE-2025-49267 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-f… |
| CVE-2025-49261 | CVE-2025-49261 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local Fil… |
| CVE-2025-49260 | CVE-2025-49260 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local Fil… |
| CVE-2025-49259 | CVE-2025-49259 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local Fil… |
| CVE-2025-49258 | CVE-2025-49258 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Maia maia allows PHP Local Fil… |
| CVE-2025-49257 | CVE-2025-49257 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local Fil… |
| CVE-2025-49256 | CVE-2025-49256 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Sapa sapa allows PHP Local Fil… |
| CVE-2025-49255 | CVE-2025-49255 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Ruza ruza allows PHP Local Fil… |
| CVE-2025-49254 | CVE-2025-49254 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local Fil… |
| CVE-2025-49253 | CVE-2025-49253 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Lasa lasa allows PHP Local Fil… |
| CVE-2025-49252 | CVE-2025-49252 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local Fil… |
| CVE-2025-49251 | CVE-2025-49251 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local Fil… |
| CVE-2025-4922 | CVE-2025-4922 CVSS 8.1 | Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identif… |
| CVE-2025-49215 | CVE-2025-49215 CVSS 8.8 | A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installa… |
| CVE-2025-49214 | CVE-2025-49214 CVSS 8.8 | An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected… |
| CVE-2025-4919 | CVE-2025-4919 CVSS 8.8mozilla | An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 1… |
| CVE-2025-49181 | CVE-2025-49181 CVSS 8.6 | Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTT… |
| CVE-2025-49155 | CVE-2025-49155 CVSS 8.8 | An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to a… |
| CVE-2025-49141 | CVE-2025-49141 CVSS 8.8 | HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string… |
| CVE-2025-49126 | CVE-2025-49126 CVSS 8.8 | Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-S… |
| CVE-2025-49124 | CVE-2025-49124 CVSS 8.4 | Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without speci… |
| CVE-2025-49113 | RoundCube Webmail Deserialization of Untrusted Data Vulnerability KEVCVSS 8.8Roundcube | RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from paramet… |
| CVE-2025-49091 | CVE-2025-49091 CVSS 8.2 | KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// … |
| CVE-2025-49050 | CVE-2025-49050 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allo… |
| CVE-2025-49049 | CVE-2025-49049 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video Gallery dzs-videogallery allows SQL Inje… |
| CVE-2025-49036 | CVE-2025-49036 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addons for Ki… |
| CVE-2025-49033 | CVE-2025-49033 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-a… |
| CVE-2025-48999 | CVE-2025-48999 CVSS 8.8 | DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a mali… |
| CVE-2025-48998 | CVE-2025-48998 CVSS 8.8 | DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenti… |
| CVE-2025-48986 | CVE-2025-48986 CVSS 8.8revive-adserver | Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy t… |
| CVE-2025-48984 | CVE-2025-48984 CVSS 8.8veeam | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
| CVE-2025-48981 | CVE-2025-48981 CVSS 8.6 | An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the … |
| CVE-2025-48950 | CVE-2025-48950 CVSS 8.8 | MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common di… |
| CVE-2025-48936 | CVE-2025-48936 CVSS 8.8 | Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset … |
| CVE-2025-48921 | CVE-2025-48921 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 before 12.3.… |
| CVE-2025-48918 | CVE-2025-48918 CVSS 8.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).Thi… |
| CVE-2025-48915 | CVE-2025-48915 CVSS 8.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scrip… |
| CVE-2025-48914 | CVE-2025-48914 CVSS 8.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scrip… |
| CVE-2025-48911 | CVE-2025-48911 CVSS 8.2 | Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability. |
| CVE-2025-48906 | CVE-2025-48906 CVSS 8.8 | Authentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability. |
| CVE-2025-48905 | CVE-2025-48905 CVSS 8.1 | Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wa… |
| CVE-2025-48881 | CVE-2025-48881 CVSS 8.3 | Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEASE, all ob… |
| CVE-2025-4887 | CVE-2025-4887 CVSS 8.8 | A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0. Affected by this issue is some unkn… |
| CVE-2025-48860 | CVE-2025-48860 CVSS 8.0 | A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to backup a… |
| CVE-2025-48828 | CVE-2025-48828 CVSS 8.1 | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template co… |
| CVE-2025-48826 | CVE-2025-48826 CVSS 8.8planet | A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to… |
| CVE-2025-48824 | CVE-2025-48824 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-48822 | CVE-2025-48822 CVSS 8.6 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. |