92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,401–5,450 of 8,161 in High · page 109 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-48817 | CVE-2025-48817 CVSS 8.8 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2025-48769 | CVE-2025-48769 CVSS 8.1apache | Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two d… |
| CVE-2025-48734 | CVE-2025-48734 CVSS 8.8 | Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers fro… |
| CVE-2025-48725 | CVE-2025-48725 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then ex… |
| CVE-2025-48724 | CVE-2025-48724 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t… |
| CVE-2025-48723 | CVE-2025-48723 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t… |
| CVE-2025-4866 | CVE-2025-4866 CVSS 8.8 | A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown function of the component Management Console… |
| CVE-2025-48650 | CVE-2025-48650 CVSS 8.4 | In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no additional exe… |
| CVE-2025-48636 | CVE-2025-48636 CVSS 8.4 | In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. This could lead to lo… |
| CVE-2025-4863 | CVE-2025-4863 CVSS 8.6 | A vulnerability, which was classified as critical, was found in Advaya Softech GEMS ERP Portal 2.1. This affects an unknown part of the file /studentLogin/stud… |
| CVE-2025-48619 | CVE-2025-48619 CVSS 8.4 | In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the code. Thi… |
| CVE-2025-48605 | CVE-2025-48605 CVSS 8.4 | In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation… |
| CVE-2025-48602 | CVE-2025-48602 CVSS 8.4 | In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This… |
| CVE-2025-48593 | CVE-2025-48593 CVSS 8.0google | In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution … |
| CVE-2025-48582 | CVE-2025-48582 CVSS 8.4 | In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. This could lead to loc… |
| CVE-2025-48581 | CVE-2025-48581 CVSS 8.4google | In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the code. This could lead to local escalat… |
| CVE-2025-48579 | CVE-2025-48579 CVSS 8.4 | In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confused deputy. This could lead to local es… |
| CVE-2025-48574 | CVE-2025-48574 CVSS 8.4 | In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission check. This c… |
| CVE-2025-48572 | CVE-2025-48572 KEVCVSS 7.8google | In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of pri… |
| CVE-2025-48543 | Android Runtime Use-After-Free Vulnerability KEVCVSS 8.8Android | Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation. |
| CVE-2025-48539 | CVE-2025-48539 CVSS 8.0 | In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead to remote (proximal/adjacent) code execu… |
| CVE-2025-48534 | CVE-2025-48534 CVSS 8.8 | In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to loca… |
| CVE-2025-48530 | CVE-2025-48530 CVSS 8.1 | In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This could lead to remote code execution in… |
| CVE-2025-48492 | CVE-2025-48492 CVSS 8.8 | GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject ar… |
| CVE-2025-48477 | CVE-2025-48477 CVSS 8.1 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires the user to perform a correct sequence… |
| CVE-2025-48476 | CVE-2025-48476 CVSS 8.8 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user records using the fill() method, there is … |
| CVE-2025-48475 | CVE-2025-48475 CVSS 8.1 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a check on which "clients" of the System an… |
| CVE-2025-48474 | CVE-2025-48474 CVSS 8.1 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly checks user access rights for conversations… |
| CVE-2025-48472 | CVE-2025-48472 CVSS 8.1 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that the user is disabling notifications fo… |
| CVE-2025-48466 | CVE-2025-48466 CVSS 8.1 | Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentia… |
| CVE-2025-48446 | CVE-2025-48446 CVSS 8.8 | Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.… |
| CVE-2025-48445 | CVE-2025-48445 CVSS 8.8 | Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redirect): from … |
| CVE-2025-48416 | CVE-2025-48416 CVSS 8.1 | An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image for the "root" user. However, in the defa… |
| CVE-2025-48396 | CVE-2025-48396 CVSS 8.3 | Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the lates… |
| CVE-2025-4839 | CVE-2025-4839 CVSS 8.1 | A vulnerability has been found in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functi… |
| CVE-2025-48384 | Git Link Following Vulnerability KEVCVSS 8.0Git | Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files. |
| CVE-2025-48383 | CVE-2025-48383 CVSS 8.2 | Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and M… |
| CVE-2025-48371 | CVE-2025-48371 CVSS 8.8 | OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and doc… |
| CVE-2025-4835 | CVE-2025-4835 CVSS 8.8 | A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an un… |
| CVE-2025-4834 | CVE-2025-4834 CVSS 8.8 | A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of th… |
| CVE-2025-4833 | CVE-2025-4833 CVSS 8.8 | A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This issue affects some unknown processing of … |
| CVE-2025-4832 | CVE-2025-4832 CVSS 8.8 | A vulnerability has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This vulnerability affects unknown code o… |
| CVE-2025-4831 | CVE-2025-4831 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the fi… |
| CVE-2025-4830 | CVE-2025-4830 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this issue is some un… |
| CVE-2025-48292 | CVE-2025-48292 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GoodLayers Tourmaster tourmaster allow… |
| CVE-2025-48290 | CVE-2025-48290 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in bslthemes Kinsley kinsley allows PHP L… |
| CVE-2025-4829 | CVE-2025-4829 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this vulnerability is the function sub… |
| CVE-2025-48278 | CVE-2025-48278 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.Thi… |
| CVE-2025-4827 | CVE-2025-4827 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the… |
| CVE-2025-4826 | CVE-2025-4826 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown p… |