92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,351–5,400 of 8,161 in High · page 108 of 164

IDTitleSummary
CVE-2025-49276CVE-2025-49276
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Blogmine blogmine allows PHP …
CVE-2025-49275CVE-2025-49275
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Blogbyte blogbyte allows PHP …
CVE-2025-49267CVE-2025-49267
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-f…
CVE-2025-49261CVE-2025-49261
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local Fil…
CVE-2025-49260CVE-2025-49260
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local Fil…
CVE-2025-49259CVE-2025-49259
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local Fil…
CVE-2025-49258CVE-2025-49258
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Maia maia allows PHP Local Fil…
CVE-2025-49257CVE-2025-49257
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local Fil…
CVE-2025-49256CVE-2025-49256
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Sapa sapa allows PHP Local Fil…
CVE-2025-49255CVE-2025-49255
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Ruza ruza allows PHP Local Fil…
CVE-2025-49254CVE-2025-49254
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local Fil…
CVE-2025-49253CVE-2025-49253
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Lasa lasa allows PHP Local Fil…
CVE-2025-49252CVE-2025-49252
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local Fil…
CVE-2025-49251CVE-2025-49251
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local Fil…
CVE-2025-4922CVE-2025-4922
CVSS 8.1
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identif…
CVE-2025-49215CVE-2025-49215
CVSS 8.8
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installa…
CVE-2025-49214CVE-2025-49214
CVSS 8.8
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a post-authentication remote code execution on affected…
CVE-2025-4919CVE-2025-4919
CVSS 8.8mozilla
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 1…
CVE-2025-49181CVE-2025-49181
CVSS 8.6
Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTT…
CVE-2025-49155CVE-2025-49155
CVSS 8.8
An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to a…
CVE-2025-49141CVE-2025-49141
CVSS 8.8
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string…
CVE-2025-49126CVE-2025-49126
CVSS 8.8
Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-S…
CVE-2025-49124CVE-2025-49124
CVSS 8.4
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without speci…
CVE-2025-49113RoundCube Webmail Deserialization of Untrusted Data Vulnerability
KEVCVSS 8.8Roundcube
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from paramet…
CVE-2025-49091CVE-2025-49091
CVSS 8.2
KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// …
CVE-2025-49050CVE-2025-49050
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allo…
CVE-2025-49049CVE-2025-49049
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ZoomIt DZS Video Gallery dzs-videogallery allows SQL Inje…
CVE-2025-49036CVE-2025-49036
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addons for Ki…
CVE-2025-49033CVE-2025-49033
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-a…
CVE-2025-48999CVE-2025-48999
CVSS 8.8
DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a mali…
CVE-2025-48998CVE-2025-48998
CVSS 8.8
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenti…
CVE-2025-48986CVE-2025-48986
CVSS 8.8revive-adserver
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy t…
CVE-2025-48984CVE-2025-48984
CVSS 8.8veeam
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2025-48981CVE-2025-48981
CVSS 8.6
An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the …
CVE-2025-48950CVE-2025-48950
CVSS 8.8
MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common di…
CVE-2025-48936CVE-2025-48936
CVSS 8.8
Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset …
CVE-2025-48921CVE-2025-48921
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 before 12.3.…
CVE-2025-48918CVE-2025-48918
CVSS 8.8
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).Thi…
CVE-2025-48915CVE-2025-48915
CVSS 8.6
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scrip…
CVE-2025-48914CVE-2025-48914
CVSS 8.6
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scrip…
CVE-2025-48911CVE-2025-48911
CVSS 8.2
Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-48906CVE-2025-48906
CVSS 8.8
Authentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-48905CVE-2025-48905
CVSS 8.1
Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wa…
CVE-2025-48881CVE-2025-48881
CVSS 8.3
Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEASE, all ob…
CVE-2025-4887CVE-2025-4887
CVSS 8.8
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0. Affected by this issue is some unkn…
CVE-2025-48860CVE-2025-48860
CVSS 8.0
A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to backup a…
CVE-2025-48828CVE-2025-48828
CVSS 8.1
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template co…
CVE-2025-48826CVE-2025-48826
CVSS 8.8planet
A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to…
CVE-2025-48824CVE-2025-48824
CVSS 8.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-48822CVE-2025-48822
CVSS 8.6
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.