92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,501–5,550 of 8,161 in High · page 111 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-4781 | CVE-2025-4781 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Park Ticketing Management System 2.0. Affected is an unknown function of the file /forgot-p… |
| CVE-2025-47809 | CVE-2025-47809 CVSS 8.2 | Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have… |
| CVE-2025-47785 | CVE-2025-47785 CVSS 8.8 | Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/articl… |
| CVE-2025-4778 | CVE-2025-4778 CVSS 8.8 | A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the … |
| CVE-2025-47775 | CVE-2025-47775 CVSS 8.6 | Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfilt… |
| CVE-2025-4777 | CVE-2025-4777 CVSS 8.8 | A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /vie… |
| CVE-2025-47713 | CVE-2025-47713 CVSS 8.8 | A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can … |
| CVE-2025-47708 | CVE-2025-47708 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterprise MFA -… |
| CVE-2025-47701 | CVE-2025-47701 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by IP: from … |
| CVE-2025-4770 | CVE-2025-4770 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Park Ticketing Management System 2.0. This issue affects some unknown processin… |
| CVE-2025-47696 | CVE-2025-47696 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer… |
| CVE-2025-47690 | CVE-2025-47690 CVSS 8.8 | Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This issue affec… |
| CVE-2025-47672 | CVE-2025-47672 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange miniOrange Discord Integrat… |
| CVE-2025-47670 | CVE-2025-47670 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and … |
| CVE-2025-47660 | CVE-2025-47660 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This issue affects WC Affiliate: from n/a t… |
| CVE-2025-47658 | CVE-2025-47658 CVSS 8.8 | Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-suppor… |
| CVE-2025-47651 | CVE-2025-47651 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injec… |
| CVE-2025-47649 | CVE-2025-47649 CVSS 8.8 | Path Traversal: '.../...//' vulnerability in StackWC Open Close WooCommerce Store woc-open-close allows PHP Local File Inclusion.This issue affects Open Close … |
| CVE-2025-47645 | CVE-2025-47645 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ELEXtensions ELEX WooCommerce Advanced Bulk Edit Products… |
| CVE-2025-4764 | CVE-2025-4764 CVSS 8.0aida | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Information Technology Inc. Hotel Guest Hot… |
| CVE-2025-47633 | CVE-2025-47633 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce awin-advertiser-tracking allows Cross Site Request Forgery.T… |
| CVE-2025-47631 | CVE-2025-47631 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This issue affects Hospital Management System:… |
| CVE-2025-47628 | CVE-2025-47628 CVSS 8.8 | Missing Authorization vulnerability in quomodosoft QS Dark Mode qs-dark-mode allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… |
| CVE-2025-47624 | CVE-2025-47624 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross Site Request Forgery.This issue affects… |
| CVE-2025-47612 | CVE-2025-47612 CVSS 8.8 | Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affe… |
| CVE-2025-47601 | CVE-2025-47601 CVSS 8.8 | Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <… |
| CVE-2025-47579 | CVE-2025-47579 CVSS 8.1 | Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through … |
| CVE-2025-47576 | CVE-2025-47576 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bringthepixel Bimber - Viral Magazine … |
| CVE-2025-47575 | CVE-2025-47575 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This iss… |
| CVE-2025-47561 | CVE-2025-47561 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in RomanCode MapSVG mapsvg allows Privilege Escalation.This issue affects MapSVG: from n/a through < 8.6.13. |
| CVE-2025-47553 | CVE-2025-47553 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a… |
| CVE-2025-47546 | CVE-2025-47546 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross Site Request Forgery.This issue affects WP Compr… |
| CVE-2025-47545 | CVE-2025-47545 CVSS 8.1 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker poll-maker allows Leveraging Ra… |
| CVE-2025-47535 | CVE-2025-47535 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-custom-produc… |
| CVE-2025-47533 | CVE-2025-47533 CVSS 8.1 | Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PHP Local File Inclusion.This issue affec… |
| CVE-2025-47531 | CVE-2025-47531 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes XT Event Widget for Socia… |
| CVE-2025-47512 | CVE-2025-47512 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan tainacan allows Path Traversal.This issue aff… |
| CVE-2025-47492 | CVE-2025-47492 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-… |
| CVE-2025-47490 | CVE-2025-47490 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows SQL I… |
| CVE-2025-47478 | CVE-2025-47478 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-a… |
| CVE-2025-47474 | CVE-2025-47474 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ninetheme Anarkali anarkali allows PHP… |
| CVE-2025-47462 | CVE-2025-47462 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue affects Chall… |
| CVE-2025-47461 | CVE-2025-47461 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subaccounts-for-woocommerce allows Authenticat… |
| CVE-2025-4743 | CVE-2025-4743 CVSS 8.8 | A vulnerability classified as critical was found in code-projects Employee Record System 1.0. Affected by this vulnerability is an unknown functionality of the… |
| CVE-2025-47411 | CVE-2025-47411 CVSS 8.1apache | A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap… |
| CVE-2025-47410 | CVE-2025-47410 CVSS 8.8apache | Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user i… |
| CVE-2025-47392 | CVE-2025-47392 CVSS 8.8qualcomm | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. |
| CVE-2025-47372 | CVE-2025-47372 CVSS 8.4 | Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication. |
| CVE-2025-4735 | CVE-2025-4735 CVSS 8.8 | A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionali… |
| CVE-2025-47345 | CVE-2025-47345 CVSS 8.4qualcomm | Cryptographic issue may occur while encrypting license data. |