92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,551–5,600 of 8,161 in High · page 112 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-4733 | CVE-2025-4733 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processi… |
| CVE-2025-4732 | CVE-2025-4732 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boaf… |
| CVE-2025-4731 | CVE-2025-4731 CVSS 8.8 | A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/for… |
| CVE-2025-4730 | CVE-2025-4730 CVSS 8.8 | A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functional… |
| CVE-2025-47273 | CVE-2025-47273 CVSS 8.8 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex`… |
| CVE-2025-47269 | CVE-2025-47269 CVSS 8.3 | code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result … |
| CVE-2025-47245 | CVE-2025-47245 CVSS 8.1 | In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role. |
| CVE-2025-47219 | CVE-2025-47219 CVSS 8.1 | In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading… |
| CVE-2025-47206 | CVE-2025-47206 CVSS 8.1 | An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerabi… |
| CVE-2025-47181 | CVE-2025-47181 CVSS 8.8 | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47178 | CVE-2025-47178 CVSS 8.0 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execut… |
| CVE-2025-47172 | CVE-2025-47172 CVSS 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute co… |
| CVE-2025-47167 | CVE-2025-47167 CVSS 8.4 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47166 | CVE-2025-47166 CVSS 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-47164 | CVE-2025-47164 CVSS 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47163 | CVE-2025-47163 CVSS 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-47162 | CVE-2025-47162 CVSS 8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-47110 | CVE-2025-47110 CVSS 8.4 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that cou… |
| CVE-2025-4696 | CVE-2025-4696 CVSS 8.8 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unkn… |
| CVE-2025-4695 | CVE-2025-4695 CVSS 8.8 | A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the … |
| CVE-2025-4686 | CVE-2025-4686 CVSS 8.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry … |
| CVE-2025-46840 | CVE-2025-46840 CVSS 8.7 | Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low p… |
| CVE-2025-46837 | CVE-2025-46837 CVSS 8.7 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by a low privile… |
| CVE-2025-46835 | CVE-2025-46835 CVSS 8.5 | Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file loca… |
| CVE-2025-46817 | CVE-2025-46817 CVSS 8.8 | Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script t… |
| CVE-2025-46815 | CVE-2025-46815 CVSS 8.0 | The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for … |
| CVE-2025-46762 | CVE-2025-46762 CVSS 8.1 | Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 introduced … |
| CVE-2025-4676 | CVE-2025-4676 CVSS 8.8 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects We… |
| CVE-2025-4674 | CVE-2025-4674 CVSS 8.6 | The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present i… |
| CVE-2025-46739 | CVE-2025-46739 CVSS 8.1 | An unauthenticated user could discover account credentials via a brute-force attack without rate limiting |
| CVE-2025-4672 | CVE-2025-4672 CVSS 8.8 | The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback() functio… |
| CVE-2025-46690 | CVE-2025-46690 CVSS 8.8 | Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request. |
| CVE-2025-46688 | CVE-2025-46688 CVSS 8.4 | quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is… |
| CVE-2025-46672 | CVE-2025-46672 CVSS 8.8 | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking. |
| CVE-2025-46634 | CVE-2025-46634 CVSS 8.2 | Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenti… |
| CVE-2025-46633 | CVE-2025-46633 CVSS 8.2 | Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the… |
| CVE-2025-46627 | CVE-2025-46627 CVSS 8.2 | Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root passw… |
| CVE-2025-46625 | CVE-2025-46625 CVSS 8.8 | Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to … |
| CVE-2025-46610 | CVE-2025-46610 CVSS 8.8 | ARTEC EMA Mail 6.92 allows CSRF. |
| CVE-2025-46546 | CVE-2025-46546 CVSS 8.8 | In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/fi… |
| CVE-2025-46474 | CVE-2025-46474 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SEUR OFICIAL SEUR Oficial seur allows … |
| CVE-2025-46463 | CVE-2025-46463 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group all… |
| CVE-2025-46458 | CVE-2025-46458 CVSS 8.2 | Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan occupancyplan allows SQL Injection.This issue affects occupancyplan: from n/a through <=… |
| CVE-2025-46444 | CVE-2025-46444 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scripteo Ads Pro ap-plugin-scripteo al… |
| CVE-2025-46428 | CVE-2025-46428 CVSS 8.8 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vul… |
| CVE-2025-46427 | CVE-2025-46427 CVSS 8.8 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vuln… |
| CVE-2025-46414 | CVE-2025-46414 CVSS 8.1 | The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauth… |
| CVE-2025-46407 | CVE-2025-46407 CVSS 8.8 | A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafte… |
| CVE-2025-46387 | CVE-2025-46387 CVSS 8.8 | CWE-639 Authorization Bypass Through User-Controlled Key |
| CVE-2025-46386 | CVE-2025-46386 CVSS 8.8 | CWE-639 Authorization Bypass Through User-Controlled Key |