92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,451–5,500 of 8,161 in High · page 110 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-48255 | CVE-2025-48255 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Request Forgery.… |
| CVE-2025-4825 | CVE-2025-4825 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the fil… |
| CVE-2025-4824 | CVE-2025-4824 CVSS 8.8 | A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boa… |
| CVE-2025-48236 | CVE-2025-48236 CVSS 8.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.net bunnycdn allows Stored XSS.This issue… |
| CVE-2025-4823 | CVE-2025-4823 CVSS 8.8 | A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function sub… |
| CVE-2025-48208 | CVE-2025-48208 CVSS 8.8 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have… |
| CVE-2025-48207 | CVE-2025-48207 CVSS 8.6 | The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2025-48205 | CVE-2025-48205 CVSS 8.6 | The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference. |
| CVE-2025-48201 | CVE-2025-48201 CVSS 8.6 | The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location. |
| CVE-2025-48171 | CVE-2025-48171 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Cena Store cena allows PHP Loc… |
| CVE-2025-48165 | CVE-2025-48165 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a through <=… |
| CVE-2025-48164 | CVE-2025-48164 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash suredash allows Privilege Escalation.This issue affects SureDash: from n/a through <=… |
| CVE-2025-48160 | CVE-2025-48160 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris caliris-wp allows PH… |
| CVE-2025-48158 | CVE-2025-48158 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field buddypress-… |
| CVE-2025-48157 | CVE-2025-48157 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality formality all… |
| CVE-2025-48149 | CVE-2025-48149 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Cook&Meal cookandmeal allows PH… |
| CVE-2025-48142 | CVE-2025-48142 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affects Bookify: from n/a through <= 1.0.9. |
| CVE-2025-48138 | CVE-2025-48138 CVSS 8.8 | Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Security Leve… |
| CVE-2025-48136 | CVE-2025-48136 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik es… |
| CVE-2025-48125 | CVE-2025-48125 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager wp-e… |
| CVE-2025-48118 | CVE-2025-48118 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpExperts Hub Woocommerce Partial Shipment wc-partial-shi… |
| CVE-2025-48101 | CVE-2025-48101 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact fo… |
| CVE-2025-4810 | CVE-2025-4810 CVSS 8.8 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. Affected by this vulnerability is the function formSetRebootTimer of the … |
| CVE-2025-48091 | CVE-2025-48091 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injection.This… |
| CVE-2025-48090 | CVE-2025-48090 CVSS 8.1 | Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - … |
| CVE-2025-4809 | CVE-2025-4809 CVSS 8.8 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function fromSafeSetMacFilter of the file /goform/setMa… |
| CVE-2025-48082 | CVE-2025-48082 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Progress Plan… |
| CVE-2025-4808 | CVE-2025-4808 CVSS 8.8 | A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0 and classified as critical. This issue affects some unknown processing of the file… |
| CVE-2025-48063 | CVE-2025-48063 CVSS 8.8 | XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the security mo… |
| CVE-2025-4806 | CVE-2025-4806 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected by this issue is some unkno… |
| CVE-2025-4800 | CVE-2025-4800 CVSS 8.8 | The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attach… |
| CVE-2025-47998 | CVE-2025-47998 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-47995 | CVE-2025-47995 CVSS 8.8 | Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-47994 | CVE-2025-47994 CVSS 8.6 | Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47986 | CVE-2025-47986 CVSS 8.8 | Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47977 | CVE-2025-47977 CVSS 8.2 | Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to p… |
| CVE-2025-47972 | CVE-2025-47972 CVSS 8.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacke… |
| CVE-2025-4796 | CVE-2025-4796 CVSS 8.8 | The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the pl… |
| CVE-2025-47957 | CVE-2025-47957 CVSS 8.4 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-47954 | CVE-2025-47954 CVSS 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n… |
| CVE-2025-47953 | CVE-2025-47953 CVSS 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47902 | CVE-2025-47902 CVSS 8.8microchip | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This is… |
| CVE-2025-47901 | CVE-2025-47901 CVSS 8.8microchip | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Inje… |
| CVE-2025-47900 | CVE-2025-47900 CVSS 8.8microchip | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Inje… |
| CVE-2025-47885 | CVE-2025-47885 CVSS 8.8 | Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stor… |
| CVE-2025-4787 | CVE-2025-4787 CVSS 8.8 | A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected is an unknown function of the file /adm… |
| CVE-2025-4786 | CVE-2025-4786 CVSS 8.8 | A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This issue affects some unknown processing of… |
| CVE-2025-47849 | CVE-2025-47849 CVSS 8.8 | A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can … |
| CVE-2025-4782 | CVE-2025-4782 CVSS 8.8 | A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of t… |
| CVE-2025-47817 | CVE-2025-47817 CVSS 8.8 | In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter. |