92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,401–5,450 of 8,161 in High · page 109 of 164

IDTitleSummary
CVE-2025-48817CVE-2025-48817
CVSS 8.8
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-48769CVE-2025-48769
CVSS 8.1apache
Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two d…
CVE-2025-48734CVE-2025-48734
CVSS 8.8
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers fro…
CVE-2025-48725CVE-2025-48725
CVSS 8.1
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then ex…
CVE-2025-48724CVE-2025-48724
CVSS 8.1
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t…
CVE-2025-48723CVE-2025-48723
CVSS 8.1
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t…
CVE-2025-4866CVE-2025-4866
CVSS 8.8
A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown function of the component Management Console…
CVE-2025-48650CVE-2025-48650
CVSS 8.4
In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no additional exe…
CVE-2025-48636CVE-2025-48636
CVSS 8.4
In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. This could lead to lo…
CVE-2025-4863CVE-2025-4863
CVSS 8.6
A vulnerability, which was classified as critical, was found in Advaya Softech GEMS ERP Portal 2.1. This affects an unknown part of the file /studentLogin/stud…
CVE-2025-48619CVE-2025-48619
CVSS 8.4
In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the code. Thi…
CVE-2025-48605CVE-2025-48605
CVSS 8.4
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation…
CVE-2025-48602CVE-2025-48602
CVSS 8.4
In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This…
CVE-2025-48593CVE-2025-48593
CVSS 8.0google
In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution …
CVE-2025-48582CVE-2025-48582
CVSS 8.4
In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. This could lead to loc…
CVE-2025-48581CVE-2025-48581
CVSS 8.4google
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the code. This could lead to local escalat…
CVE-2025-48579CVE-2025-48579
CVSS 8.4
In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confused deputy. This could lead to local es…
CVE-2025-48574CVE-2025-48574
CVSS 8.4
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission check. This c…
CVE-2025-48572CVE-2025-48572
KEVCVSS 7.8google
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of pri…
CVE-2025-48543Android Runtime Use-After-Free Vulnerability
KEVCVSS 8.8Android
Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.
CVE-2025-48539CVE-2025-48539
CVSS 8.0
In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead to remote (proximal/adjacent) code execu…
CVE-2025-48534CVE-2025-48534
CVSS 8.8
In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to loca…
CVE-2025-48530CVE-2025-48530
CVSS 8.1
In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This could lead to remote code execution in…
CVE-2025-48492CVE-2025-48492
CVSS 8.8
GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject ar…
CVE-2025-48477CVE-2025-48477
CVSS 8.1
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires the user to perform a correct sequence…
CVE-2025-48476CVE-2025-48476
CVSS 8.8
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user records using the fill() method, there is …
CVE-2025-48475CVE-2025-48475
CVSS 8.1
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a check on which "clients" of the System an…
CVE-2025-48474CVE-2025-48474
CVSS 8.1
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly checks user access rights for conversations…
CVE-2025-48472CVE-2025-48472
CVSS 8.1
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that the user is disabling notifications fo…
CVE-2025-48466CVE-2025-48466
CVSS 8.1
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentia…
CVE-2025-48446CVE-2025-48446
CVSS 8.8
Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.…
CVE-2025-48445CVE-2025-48445
CVSS 8.8
Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redirect): from …
CVE-2025-48416CVE-2025-48416
CVSS 8.1
An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image for the "root" user. However, in the defa…
CVE-2025-48396CVE-2025-48396
CVSS 8.3
Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the lates…
CVE-2025-4839CVE-2025-4839
CVSS 8.1
A vulnerability has been found in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functi…
CVE-2025-48384Git Link Following Vulnerability
KEVCVSS 8.0Git
Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.
CVE-2025-48383CVE-2025-48383
CVSS 8.2
Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and M…
CVE-2025-48371CVE-2025-48371
CVSS 8.8
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and doc…
CVE-2025-4835CVE-2025-4835
CVSS 8.8
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an un…
CVE-2025-4834CVE-2025-4834
CVSS 8.8
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of th…
CVE-2025-4833CVE-2025-4833
CVSS 8.8
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This issue affects some unknown processing of …
CVE-2025-4832CVE-2025-4832
CVSS 8.8
A vulnerability has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This vulnerability affects unknown code o…
CVE-2025-4831CVE-2025-4831
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the fi…
CVE-2025-4830CVE-2025-4830
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this issue is some un…
CVE-2025-48292CVE-2025-48292
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GoodLayers Tourmaster tourmaster allow…
CVE-2025-48290CVE-2025-48290
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in bslthemes Kinsley kinsley allows PHP L…
CVE-2025-4829CVE-2025-4829
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this vulnerability is the function sub…
CVE-2025-48278CVE-2025-48278
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.Thi…
CVE-2025-4827CVE-2025-4827
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the…
CVE-2025-4826CVE-2025-4826
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown p…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.