92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,451–5,500 of 8,161 in High · page 110 of 164

IDTitleSummary
CVE-2025-48255CVE-2025-48255
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Request Forgery.…
CVE-2025-4825CVE-2025-4825
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the fil…
CVE-2025-4824CVE-2025-4824
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boa…
CVE-2025-48236CVE-2025-48236
CVSS 8.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.net bunnycdn allows Stored XSS.This issue…
CVE-2025-4823CVE-2025-4823
CVSS 8.8
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function sub…
CVE-2025-48208CVE-2025-48208
CVSS 8.8
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have…
CVE-2025-48207CVE-2025-48207
CVSS 8.6
The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-48205CVE-2025-48205
CVSS 8.6
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
CVE-2025-48201CVE-2025-48201
CVSS 8.6
The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
CVE-2025-48171CVE-2025-48171
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Cena Store cena allows PHP Loc…
CVE-2025-48165CVE-2025-48165
CVSS 8.8
Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a through <=…
CVE-2025-48164CVE-2025-48164
CVSS 8.8
Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash suredash allows Privilege Escalation.This issue affects SureDash: from n/a through <=…
CVE-2025-48160CVE-2025-48160
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CocoBasic Caliris caliris-wp allows PH…
CVE-2025-48158CVE-2025-48158
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field buddypress-…
CVE-2025-48157CVE-2025-48157
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality formality all…
CVE-2025-48149CVE-2025-48149
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Cook&Meal cookandmeal allows PH…
CVE-2025-48142CVE-2025-48142
CVSS 8.8
Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affects Bookify: from n/a through <= 1.0.9.
CVE-2025-48138CVE-2025-48138
CVSS 8.8
Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Security Leve…
CVE-2025-48136CVE-2025-48136
CVSS 8.8
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik es…
CVE-2025-48125CVE-2025-48125
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager wp-e…
CVE-2025-48118CVE-2025-48118
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpExperts Hub Woocommerce Partial Shipment wc-partial-shi…
CVE-2025-48101CVE-2025-48101
CVSS 8.8
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact fo…
CVE-2025-4810CVE-2025-4810
CVSS 8.8
A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. Affected by this vulnerability is the function formSetRebootTimer of the …
CVE-2025-48091CVE-2025-48091
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alexander AnyComment anycomment allows SQL Injection.This…
CVE-2025-48090CVE-2025-48090
CVSS 8.1
Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - …
CVE-2025-4809CVE-2025-4809
CVSS 8.8
A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function fromSafeSetMacFilter of the file /goform/setMa…
CVE-2025-48082CVE-2025-48082
CVSS 8.8
Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Progress Plan…
CVE-2025-4808CVE-2025-4808
CVSS 8.8
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0 and classified as critical. This issue affects some unknown processing of the file…
CVE-2025-48063CVE-2025-48063
CVSS 8.8
XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the security mo…
CVE-2025-4806CVE-2025-4806
CVSS 8.8
A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected by this issue is some unkno…
CVE-2025-4800CVE-2025-4800
CVSS 8.8
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attach…
CVE-2025-47998CVE-2025-47998
CVSS 8.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-47995CVE-2025-47995
CVSS 8.8
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
CVE-2025-47994CVE-2025-47994
CVSS 8.6
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47986CVE-2025-47986
CVSS 8.8
Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47977CVE-2025-47977
CVSS 8.2
Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to p…
CVE-2025-47972CVE-2025-47972
CVSS 8.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacke…
CVE-2025-4796CVE-2025-4796
CVSS 8.8
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due to the pl…
CVE-2025-47957CVE-2025-47957
CVSS 8.4
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47954CVE-2025-47954
CVSS 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n…
CVE-2025-47953CVE-2025-47953
CVSS 8.4
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47902CVE-2025-47902
CVSS 8.8microchip
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Provider 4100 allows SQL Injection.This is…
CVE-2025-47901CVE-2025-47901
CVSS 8.8microchip
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Inje…
CVE-2025-47900CVE-2025-47900
CVSS 8.8microchip
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Time Provider 4100 allows OS Command Inje…
CVE-2025-47885CVE-2025-47885
CVSS 8.8
Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stor…
CVE-2025-4787CVE-2025-4787
CVSS 8.8
A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected is an unknown function of the file /adm…
CVE-2025-4786CVE-2025-4786
CVSS 8.8
A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This issue affects some unknown processing of…
CVE-2025-47849CVE-2025-47849
CVSS 8.8
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can …
CVE-2025-4782CVE-2025-4782
CVSS 8.8
A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of t…
CVE-2025-47817CVE-2025-47817
CVSS 8.8
In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.