92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,601–5,650 of 8,161 in High · page 113 of 164

IDTitleSummary
CVE-2025-46385CVE-2025-46385
CVSS 8.6
CWE-918 Server-Side Request Forgery (SSRF)
CVE-2025-46384CVE-2025-46384
CVSS 8.8
CWE-434 Unrestricted Upload of File with Dangerous Type
CVE-2025-46342CVE-2025-46342
CVSS 8.2
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using nam…
CVE-2025-46334CVE-2025-46334
CVSS 8.6
Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter prog…
CVE-2025-46281CVE-2025-46281
CVSS 8.8apple
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to bre…
CVE-2025-46268CVE-2025-46268
CVSS 8.8
Advantech WebAccess/SCADA  is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.
CVE-2025-46265CVE-2025-46265
CVSS 8.8
On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS…
CVE-2025-46251CVE-2025-46251
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forgery.This issue affects VikRestaurants: …
CVE-2025-46249CVE-2025-46249
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor allows Cross Site Request Forgery.This i…
CVE-2025-46246CVE-2025-46246
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers…
CVE-2025-46245CVE-2025-46245
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM A…
CVE-2025-46243CVE-2025-46243
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows Cross Site Request Forg…
CVE-2025-46241CVE-2025-46241
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects…
CVE-2025-46232CVE-2025-46232
CVSS 8.8
Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This i…
CVE-2025-46231CVE-2025-46231
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Cross Site Request Forgery.This…
CVE-2025-46205CVE-2025-46205
CVSS 8.1
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplyin…
CVE-2025-46198CVE-2025-46198
CVSS 8.8
Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img el…
CVE-2025-46183CVE-2025-46183
CVSS 8.2
The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file,…
CVE-2025-46154CVE-2025-46154
CVSS 8.4
Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.
CVE-2025-4613CVE-2025-4613
CVSS 8.8
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking…
CVE-2025-46116CVE-2025-46116
CVSS 8.8
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an a…
CVE-2025-46109CVE-2025-46109
CVSS 8.8
SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request
CVE-2025-46093CVE-2025-46093
CVSS 8.8
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging …
CVE-2025-46068CVE-2025-46068
CVSS 8.8
An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism
CVE-2025-46067CVE-2025-46067
CVSS 8.2
An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file
CVE-2025-46014CVE-2025-46014
CVSS 8.8
Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or …
CVE-2025-4601CVE-2025-4601
CVSS 8.8
The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to th…
CVE-2025-45997CVE-2025-45997
CVSS 8.6
Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by m…
CVE-2025-45956CVE-2025-45956
CVSS 8.8
A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arb…
CVE-2025-45846CVE-2025-45846
CVSS 8.8
ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSetting function.
CVE-2025-45845CVE-2025-45845
CVSS 8.8
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.
CVE-2025-45844CVE-2025-45844
CVSS 8.8
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.
CVE-2025-45843CVE-2025-45843
CVSS 8.8
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.
CVE-2025-45842CVE-2025-45842
CVSS 8.8
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.
CVE-2025-4581CVE-2025-4581
CVSS 8.6
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 throu…
CVE-2025-45786CVE-2025-45786
CVSS 8.1
Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php.
CVE-2025-45620CVE-2025-45620
CVSS 8.1averusa
An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
CVE-2025-4561CVE-2025-4561
CVSS 8.8
The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell backdoors, t…
CVE-2025-4552CVE-2025-4552
CVSS 8.1
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the f…
CVE-2025-45472CVE-2025-45472
CVSS 8.8
Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.
CVE-2025-45471CVE-2025-45471
CVSS 8.8
Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account.
CVE-2025-45468CVE-2025-45468
CVSS 8.8
Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.
CVE-2025-45466CVE-2025-45466
CVSS 8.8
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.
CVE-2025-4546CVE-2025-4546
CVSS 8.8
A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the…
CVE-2025-4545CVE-2025-4545
CVSS 8.1
A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\con…
CVE-2025-4541CVE-2025-4541
CVSS 8.8
A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\admin\ZtAction.class.php of the component…
CVE-2025-45379CVE-2025-45379
CVSS 8.4
Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell…
CVE-2025-45346CVE-2025-45346
CVSS 8.1
SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.
CVE-2025-45322CVE-2025-45322
CVSS 8.8
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.
CVE-2025-45321CVE-2025-45321
CVSS 8.8
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.