92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,601–5,650 of 8,161 in High · page 113 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-46385 | CVE-2025-46385 CVSS 8.6 | CWE-918 Server-Side Request Forgery (SSRF) |
| CVE-2025-46384 | CVE-2025-46384 CVSS 8.8 | CWE-434 Unrestricted Upload of File with Dangerous Type |
| CVE-2025-46342 | CVE-2025-46342 CVSS 8.2 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using nam… |
| CVE-2025-46334 | CVE-2025-46334 CVSS 8.6 | Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter prog… |
| CVE-2025-46281 | CVE-2025-46281 CVSS 8.8apple | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to bre… |
| CVE-2025-46268 | CVE-2025-46268 CVSS 8.8 | Advantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands. |
| CVE-2025-46265 | CVE-2025-46265 CVSS 8.8 | On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS… |
| CVE-2025-46251 | CVE-2025-46251 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forgery.This issue affects VikRestaurants: … |
| CVE-2025-46249 | CVE-2025-46249 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor allows Cross Site Request Forgery.This i… |
| CVE-2025-46246 | CVE-2025-46246 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers cm-answers allows Cross Site Request Forgery.This issue affects CM Answers… |
| CVE-2025-46245 | CVE-2025-46245 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer cm-ad-changer allows Cross Site Request Forgery.This issue affects CM A… |
| CVE-2025-46243 | CVE-2025-46243 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows Cross Site Request Forg… |
| CVE-2025-46241 | CVE-2025-46241 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows SQL Injection.This issue affects… |
| CVE-2025-46232 | CVE-2025-46232 CVSS 8.8 | Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This i… |
| CVE-2025-46231 | CVE-2025-46231 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Cross Site Request Forgery.This… |
| CVE-2025-46205 | CVE-2025-46205 CVSS 8.1 | A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplyin… |
| CVE-2025-46198 | CVE-2025-46198 CVSS 8.8 | Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img el… |
| CVE-2025-46183 | CVE-2025-46183 CVSS 8.2 | The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file,… |
| CVE-2025-46154 | CVE-2025-46154 CVSS 8.4 | Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php. |
| CVE-2025-4613 | CVE-2025-4613 CVSS 8.8 | Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking… |
| CVE-2025-46116 | CVE-2025-46116 CVSS 8.8 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an a… |
| CVE-2025-46109 | CVE-2025-46109 CVSS 8.8 | SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request |
| CVE-2025-46093 | CVE-2025-46093 CVSS 8.8 | LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging … |
| CVE-2025-46068 | CVE-2025-46068 CVSS 8.8 | An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism |
| CVE-2025-46067 | CVE-2025-46067 CVSS 8.2 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file |
| CVE-2025-46014 | CVE-2025-46014 CVSS 8.8 | Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or … |
| CVE-2025-4601 | CVE-2025-4601 CVSS 8.8 | The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to th… |
| CVE-2025-45997 | CVE-2025-45997 CVSS 8.6 | Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by m… |
| CVE-2025-45956 | CVE-2025-45956 CVSS 8.8 | A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arb… |
| CVE-2025-45846 | CVE-2025-45846 CVSS 8.8 | ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSetting function. |
| CVE-2025-45845 | CVE-2025-45845 CVSS 8.8 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function. |
| CVE-2025-45844 | CVE-2025-45844 CVSS 8.8 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function. |
| CVE-2025-45843 | CVE-2025-45843 CVSS 8.8 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function. |
| CVE-2025-45842 | CVE-2025-45842 CVSS 8.8 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function. |
| CVE-2025-4581 | CVE-2025-4581 CVSS 8.6 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 throu… |
| CVE-2025-45786 | CVE-2025-45786 CVSS 8.1 | Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php. |
| CVE-2025-45620 | CVE-2025-45620 CVSS 8.1averusa | An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request |
| CVE-2025-4561 | CVE-2025-4561 CVSS 8.8 | The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell backdoors, t… |
| CVE-2025-4552 | CVE-2025-4552 CVSS 8.1 | A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the f… |
| CVE-2025-45472 | CVE-2025-45472 CVSS 8.8 | Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account. |
| CVE-2025-45471 | CVE-2025-45471 CVSS 8.8 | Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account. |
| CVE-2025-45468 | CVE-2025-45468 CVSS 8.8 | Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account. |
| CVE-2025-45466 | CVE-2025-45466 CVSS 8.8 | Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext. |
| CVE-2025-4546 | CVE-2025-4546 CVSS 8.8 | A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the… |
| CVE-2025-4545 | CVE-2025-4545 CVSS 8.1 | A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\con… |
| CVE-2025-4541 | CVE-2025-4541 CVSS 8.8 | A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\admin\ZtAction.class.php of the component… |
| CVE-2025-45379 | CVE-2025-45379 CVSS 8.4 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell… |
| CVE-2025-45346 | CVE-2025-45346 CVSS 8.1 | SQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request. |
| CVE-2025-45322 | CVE-2025-45322 CVSS 8.8 | kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter. |
| CVE-2025-45321 | CVE-2025-45321 CVSS 8.8 | kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword. |