92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,651–5,700 of 8,161 in High · page 114 of 164

IDTitleSummary
CVE-2025-45311CVE-2025-45311
CVSS 8.8
Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root. NOTE: this is disputed b…
CVE-2025-4531CVE-2025-4531
CVSS 8.8
A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected by this issue is the function postData o…
CVE-2025-4521CVE-2025-4521
CVSS 8.8
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check …
CVE-2025-4519CVE-2025-4519
CVSS 8.8themeatelier
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check …
CVE-2025-45081CVE-2025-45081
CVSS 8.8
Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.
CVE-2025-44963CVE-2025-44963
CVSS 8.1
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
CVE-2025-44961CVE-2025-44961
CVSS 8.8
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.
CVE-2025-44960CVE-2025-44960
CVSS 8.8
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
CVE-2025-44957CVE-2025-44957
CVSS 8.8
Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.
CVE-2025-44955CVE-2025-44955
CVSS 8.8
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
CVE-2025-44905CVE-2025-44905
CVSS 8.8
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.
CVE-2025-44904CVE-2025-44904
CVSS 8.8
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
CVE-2025-44823CVE-2025-44823
CVSS 9.9nagios
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_us…
CVE-2025-4474CVE-2025-4474
CVSS 8.8
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() fu…
CVE-2025-4473CVE-2025-4473
CVSS 8.8
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions …
CVE-2025-44643CVE-2025-44643
CVSS 8.6
Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the password pr…
CVE-2025-4462CVE-2025-4462
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. This issue affects some unknown processing of the file /b…
CVE-2025-4459CVE-2025-4459
CVSS 8.8
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown function…
CVE-2025-4458CVE-2025-4458
CVSS 8.8
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown…
CVE-2025-44557CVE-2025-44557
CVSS 8.1
A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypass the pairing process and authenticatio…
CVE-2025-4446CVE-2025-4446
CVSS 8.0
A vulnerability has been found in H3C GR-5400AX up to 100R008 and classified as critical. This vulnerability affects the function Edit_List_SSID of the file /g…
CVE-2025-4440CVE-2025-4440
CVSS 8.0
A vulnerability was found in H3C GR-1800AX up to 100R008 and classified as critical. Affected by this issue is the function EnableIpv6 of the file /goform/aspF…
CVE-2025-4433CVE-2025-4433
CVSS 8.8
Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Management" and …
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
KEVCVSS 8.8Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute ar…
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
KEVCVSS 7.5Ivanti
Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resource…
CVE-2025-4425CVE-2025-4425
CVSS 8.2
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for…
CVE-2025-4423CVE-2025-4423
CVSS 8.2
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for…
CVE-2025-4422CVE-2025-4422
CVSS 8.2
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for…
CVE-2025-4421CVE-2025-4421
CVSS 8.2
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Advisories and Announcements" webpage for…
CVE-2025-44177CVE-2025-44177
CVSS 8.2
A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint. An unauthenti…
CVE-2025-4414CVE-2025-4414
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer…
CVE-2025-44137CVE-2025-44137
CVSS 8.2
MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are s…
CVE-2025-4413CVE-2025-4413
CVSS 8.8
The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in all versi…
CVE-2025-44034CVE-2025-44034
CVSS 8.0
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/…
CVE-2025-44018CVE-2025-44018
CVSS 8.3
A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware dow…
CVE-2025-44016CVE-2025-44016
CVSS 8.8teamviewer
A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious a…
CVE-2025-44015CVE-2025-44015
CVSS 8.4
A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerab…
CVE-2025-44014CVE-2025-44014
CVSS 8.8
An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerabil…
CVE-2025-43960CVE-2025-43960
CVSS 8.6
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), lea…
CVE-2025-43953CVE-2025-43953
CVSS 8.8
In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or traceroute field on the TCP/IP screen.
CVE-2025-43922CVE-2025-43922
CVSS 8.1
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.
CVE-2025-43920CVE-2025-43920
CVSS 8.1
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS comma…
CVE-2025-43917CVE-2025-43917
CVSS 8.2
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an ad…
CVE-2025-4387CVE-2025-4387
CVSS 8.8
The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add…
CVE-2025-43865CVE-2025-43865
CVSS 8.2
React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the r…
CVE-2025-43813CVE-2025-43813
CVSS 8.2
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and …
CVE-2025-43790CVE-2025-43790
CVSS 8.1
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.6, 2024.Q1.1 through…
CVE-2025-4372CVE-2025-4372
CVSS 8.8
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (C…
CVE-2025-43715CVE-2025-43715
CVSS 8.1
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the tempor…
CVE-2025-43711CVE-2025-43711
CVSS 8.1
Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.