92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,501–5,550 of 8,161 in High · page 111 of 164

IDTitleSummary
CVE-2025-4781CVE-2025-4781
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an unknown function of the file /forgot-p…
CVE-2025-47809CVE-2025-47809
CVSS 8.2
Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have…
CVE-2025-47785CVE-2025-47785
CVSS 8.8
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/articl…
CVE-2025-4778CVE-2025-4778
CVSS 8.8
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the …
CVE-2025-47775CVE-2025-47775
CVSS 8.6
Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfilt…
CVE-2025-4777CVE-2025-4777
CVSS 8.8
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /vie…
CVE-2025-47713CVE-2025-47713
CVSS 8.8
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can …
CVE-2025-47708CVE-2025-47708
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA -…
CVE-2025-47701CVE-2025-47701
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from …
CVE-2025-4770CVE-2025-4770
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Park Ticketing Management System 2.0. This issue affects some unknown processin…
CVE-2025-47696CVE-2025-47696
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer…
CVE-2025-47690CVE-2025-47690
CVSS 8.8
Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This issue affec…
CVE-2025-47672CVE-2025-47672
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange miniOrange Discord Integrat…
CVE-2025-47670CVE-2025-47670
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and …
CVE-2025-47660CVE-2025-47660
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a t…
CVE-2025-47658CVE-2025-47658
CVSS 8.8
Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-suppor…
CVE-2025-47651CVE-2025-47651
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injec…
CVE-2025-47649CVE-2025-47649
CVSS 8.8
Path Traversal: '.../...//' vulnerability in StackWC Open Close WooCommerce Store woc-open-close allows PHP Local File Inclusion.This issue affects Open Close …
CVE-2025-47645CVE-2025-47645
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products…
CVE-2025-4764CVE-2025-4764
CVSS 8.0aida
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hot…
CVE-2025-47633CVE-2025-47633
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce awin-advertiser-tracking allows Cross Site Request Forgery.T…
CVE-2025-47631CVE-2025-47631
CVSS 8.8
Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This issue affects Hospital Management System:…
CVE-2025-47628CVE-2025-47628
CVSS 8.8
Missing Authorization vulnerability in quomodosoft QS Dark Mode qs-dark-mode allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…
CVE-2025-47624CVE-2025-47624
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross Site Request Forgery.This issue affects…
CVE-2025-47612CVE-2025-47612
CVSS 8.8
Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe…
CVE-2025-47601CVE-2025-47601
CVSS 8.8
Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <…
CVE-2025-47579CVE-2025-47579
CVSS 8.1
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through …
CVE-2025-47576CVE-2025-47576
CVSS 8.8
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bringthepixel Bimber - Viral Magazine …
CVE-2025-47575CVE-2025-47575
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This iss…
CVE-2025-47561CVE-2025-47561
CVSS 8.8
Incorrect Privilege Assignment vulnerability in RomanCode MapSVG mapsvg allows Privilege Escalation.This issue affects MapSVG: from n/a through < 8.6.13.
CVE-2025-47553CVE-2025-47553
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a…
CVE-2025-47546CVE-2025-47546
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross Site Request Forgery.This issue affects WP Compr…
CVE-2025-47545CVE-2025-47545
CVSS 8.1
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker poll-maker allows Leveraging Ra…
CVE-2025-47535CVE-2025-47535
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-custom-produc…
CVE-2025-47533CVE-2025-47533
CVSS 8.1
Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PHP Local File Inclusion.This issue affec…
CVE-2025-47531CVE-2025-47531
CVSS 8.8
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Socia…
CVE-2025-47512CVE-2025-47512
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan tainacan allows Path Traversal.This issue aff…
CVE-2025-47492CVE-2025-47492
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-…
CVE-2025-47490CVE-2025-47490
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows SQL I…
CVE-2025-47478CVE-2025-47478
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-a…
CVE-2025-47474CVE-2025-47474
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ninetheme Anarkali anarkali allows PHP…
CVE-2025-47462CVE-2025-47462
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue affects Chall…
CVE-2025-47461CVE-2025-47461
CVSS 8.8
Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subaccounts-for-woocommerce allows Authenticat…
CVE-2025-4743CVE-2025-4743
CVSS 8.8
A vulnerability classified as critical was found in code-projects Employee Record System 1.0. Affected by this vulnerability is an unknown functionality of the…
CVE-2025-47411CVE-2025-47411
CVSS 8.1apache
A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap…
CVE-2025-47410CVE-2025-47410
CVSS 8.8apache
Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user i…
CVE-2025-47392CVE-2025-47392
CVSS 8.8qualcomm
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47372CVE-2025-47372
CVSS 8.4
Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.
CVE-2025-4735CVE-2025-4735
CVSS 8.8
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionali…
CVE-2025-47345CVE-2025-47345
CVSS 8.4qualcomm
Cryptographic issue may occur while encrypting license data.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.