92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,701–5,750 of 8,161 in High · page 115 of 164

IDTitleSummary
CVE-2025-43586CVE-2025-43586
CVSS 8.1
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result…
CVE-2025-43585CVE-2025-43585
CVSS 8.2
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result …
CVE-2025-43565CVE-2025-43565
CVSS 8.4
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution i…
CVE-2025-43539CVE-2025-43539
CVSS 8.8apple
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS…
CVE-2025-43529CVE-2025-43529
KEVCVSS 8.8apple
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.…
CVE-2025-43524CVE-2025-43524
CVSS 8.8
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app …
CVE-2025-43515CVE-2025-43515
CVSS 8.8
The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same network as a…
CVE-2025-43510CVE-2025-43510
KEVCVSS 7.8apple
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS…
CVE-2025-43505CVE-2025-43505
CVSS 8.8
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to…
CVE-2025-43480CVE-2025-43480
CVSS 8.1
The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS…
CVE-2025-43433CVE-2025-43433
CVSS 8.8apple
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe …
CVE-2025-43431CVE-2025-43431
CVSS 8.8
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe …
CVE-2025-43419CVE-2025-43419
CVSS 8.8
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26…
CVE-2025-43371CVE-2025-43371
CVSS 8.2
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.
CVE-2025-43358CVE-2025-43358
CVSS 8.8
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15…
CVE-2025-4335CVE-2025-4335
CVSS 8.8
The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is due to ins…
CVE-2025-43330CVE-2025-43330
CVSS 8.2
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to break out of its san…
CVE-2025-43329CVE-2025-43329
CVSS 8.8
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be…
CVE-2025-43323CVE-2025-43323
CVSS 8.1
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An …
CVE-2025-43270CVE-2025-43270
CVSS 8.8
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An ap…
CVE-2025-43264CVE-2025-43264
CVSS 8.8apple
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process me…
CVE-2025-43257CVE-2025-43257
CVSS 8.7apple
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.
CVE-2025-43219CVE-2025-43219
CVSS 8.8apple
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process me…
CVE-2025-43202CVE-2025-43202
CVSS 8.8apple
This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memo…
CVE-2025-4317CVE-2025-4317
CVSS 8.8
The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all version…
CVE-2025-4315CVE-2025-4315
CVSS 8.8
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This…
CVE-2025-43010CVE-2025-43010
CVSS 8.3
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a cer…
CVE-2025-42983CVE-2025-42983
CVSS 8.5
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or…
CVE-2025-42982CVE-2025-42982
CVSS 8.8
SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. Thi…
CVE-2025-42976CVE-2025-42976
CVSS 8.1
SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, co…
CVE-2025-42959CVE-2025-42959
CVSS 8.1
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific secur…
CVE-2025-42953CVE-2025-42953
CVSS 8.1
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could…
CVE-2025-42951CVE-2025-42951
CVSS 8.8
Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the correspondi…
CVE-2025-42933CVE-2025-42933
CVSS 8.8
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of s…
CVE-2025-42929CVE-2025-42929
CVSS 8.1
Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables ar…
CVE-2025-42916CVE-2025-42916
CVSS 8.1
Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables ar…
CVE-2025-42878CVE-2025-42878
CVSS 8.2
SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit the…
CVE-2025-4282CVE-2025-4282
CVSS 8.8
A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code o…
CVE-2025-4279CVE-2025-4279
CVSS 8.8
The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_replace_get_…
CVE-2025-4278CVE-2025-4278
CVSS 8.7
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search pag…
CVE-2025-4260CVE-2025-4260
CVSS 8.3
A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web…
CVE-2025-4258CVE-2025-4258
CVSS 8.8
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master…
CVE-2025-4247CVE-2025-4247
CVSS 8.8
A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is an unknown function of the file /delet…
CVE-2025-4244CVE-2025-4244
CVSS 8.8
A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This affects an unknown part of the file /seat…
CVE-2025-4243CVE-2025-4243
CVSS 8.8
A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Affected by this issue is some unknown fu…
CVE-2025-4232CVE-2025-4232
CVSS 8.8
An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrati…
CVE-2025-4200CVE-2025-4200
CVSS 8.1
The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including…
CVE-2025-4197CVE-2025-4197
CVSS 8.8
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is an unknown function of the file /edit_…
CVE-2025-4196CVE-2025-4196
CVSS 8.8
A vulnerability was found in SourceCodester Patient Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …
CVE-2025-41766CVE-2025-41766
CVSS 8.8
A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full devic…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.