92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,551–5,600 of 8,161 in High · page 112 of 164

IDTitleSummary
CVE-2025-4733CVE-2025-4733
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processi…
CVE-2025-4732CVE-2025-4732
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boaf…
CVE-2025-4731CVE-2025-4731
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/for…
CVE-2025-4730CVE-2025-4730
CVSS 8.8
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functional…
CVE-2025-47273CVE-2025-47273
CVSS 8.8
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex`…
CVE-2025-47269CVE-2025-47269
CVSS 8.3
code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result …
CVE-2025-47245CVE-2025-47245
CVSS 8.1
In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.
CVE-2025-47219CVE-2025-47219
CVSS 8.1
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading…
CVE-2025-47206CVE-2025-47206
CVSS 8.1
An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerabi…
CVE-2025-47181CVE-2025-47181
CVSS 8.8
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
CVE-2025-47178CVE-2025-47178
CVSS 8.0
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execut…
CVE-2025-47172CVE-2025-47172
CVSS 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute co…
CVE-2025-47167CVE-2025-47167
CVSS 8.4
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47166CVE-2025-47166
CVSS 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-47164CVE-2025-47164
CVSS 8.4
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47163CVE-2025-47163
CVSS 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-47162CVE-2025-47162
CVSS 8.4
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47110CVE-2025-47110
CVSS 8.4
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that cou…
CVE-2025-4696CVE-2025-4696
CVSS 8.8
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unkn…
CVE-2025-4695CVE-2025-4695
CVSS 8.8
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the …
CVE-2025-4686CVE-2025-4686
CVSS 8.6
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry …
CVE-2025-46840CVE-2025-46840
CVSS 8.7
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low p…
CVE-2025-46837CVE-2025-46837
CVSS 8.7
Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by a low privile…
CVE-2025-46835CVE-2025-46835
CVSS 8.5
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file loca…
CVE-2025-46817CVE-2025-46817
CVSS 8.8
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script t…
CVE-2025-46815CVE-2025-46815
CVSS 8.0
The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for …
CVE-2025-46762CVE-2025-46762
CVSS 8.1
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 introduced …
CVE-2025-4676CVE-2025-4676
CVSS 8.8
Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects We…
CVE-2025-4674CVE-2025-4674
CVSS 8.6
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present i…
CVE-2025-46739CVE-2025-46739
CVSS 8.1
An unauthenticated user could discover account credentials via a brute-force attack without rate limiting
CVE-2025-4672CVE-2025-4672
CVSS 8.8
The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback() functio…
CVE-2025-46690CVE-2025-46690
CVSS 8.8
Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.
CVE-2025-46688CVE-2025-46688
CVSS 8.4
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is…
CVE-2025-46672CVE-2025-46672
CVSS 8.8
NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.
CVE-2025-46634CVE-2025-46634
CVSS 8.2
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenti…
CVE-2025-46633CVE-2025-46633
CVSS 8.2
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the…
CVE-2025-46627CVE-2025-46627
CVSS 8.2
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root passw…
CVE-2025-46625CVE-2025-46625
CVSS 8.8
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to …
CVE-2025-46610CVE-2025-46610
CVSS 8.8
ARTEC EMA Mail 6.92 allows CSRF.
CVE-2025-46546CVE-2025-46546
CVSS 8.8
In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/fi…
CVE-2025-46474CVE-2025-46474
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SEUR OFICIAL SEUR Oficial seur allows …
CVE-2025-46463CVE-2025-46463
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group all…
CVE-2025-46458CVE-2025-46458
CVSS 8.2
Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan occupancyplan allows SQL Injection.This issue affects occupancyplan: from n/a through <=…
CVE-2025-46444CVE-2025-46444
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scripteo Ads Pro ap-plugin-scripteo al…
CVE-2025-46428CVE-2025-46428
CVSS 8.8
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vul…
CVE-2025-46427CVE-2025-46427
CVSS 8.8
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vuln…
CVE-2025-46414CVE-2025-46414
CVSS 8.1
The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, which may allow an attacker to gain unauth…
CVE-2025-46407CVE-2025-46407
CVSS 8.8
A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafte…
CVE-2025-46387CVE-2025-46387
CVSS 8.8
CWE-639 Authorization Bypass Through User-Controlled Key
CVE-2025-46386CVE-2025-46386
CVSS 8.8
CWE-639 Authorization Bypass Through User-Controlled Key
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.