92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,701–5,750 of 8,161 in High · page 115 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-43586 | CVE-2025-43586 CVSS 8.1 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result… |
| CVE-2025-43585 | CVE-2025-43585 CVSS 8.2 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result … |
| CVE-2025-43565 | CVE-2025-43565 CVSS 8.4 | ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution i… |
| CVE-2025-43539 | CVE-2025-43539 CVSS 8.8apple | The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS… |
| CVE-2025-43529 | CVE-2025-43529 KEVCVSS 8.8apple | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.… |
| CVE-2025-43524 | CVE-2025-43524 CVSS 8.8 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app … |
| CVE-2025-43515 | CVE-2025-43515 CVSS 8.8 | The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same network as a… |
| CVE-2025-43510 | CVE-2025-43510 KEVCVSS 7.8apple | A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS… |
| CVE-2025-43505 | CVE-2025-43505 CVSS 8.8 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to… |
| CVE-2025-43480 | CVE-2025-43480 CVSS 8.1 | The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS… |
| CVE-2025-43433 | CVE-2025-43433 CVSS 8.8apple | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe … |
| CVE-2025-43431 | CVE-2025-43431 CVSS 8.8 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe … |
| CVE-2025-43419 | CVE-2025-43419 CVSS 8.8 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26… |
| CVE-2025-43371 | CVE-2025-43371 CVSS 8.2 | This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox. |
| CVE-2025-43358 | CVE-2025-43358 CVSS 8.8 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15… |
| CVE-2025-4335 | CVE-2025-4335 CVSS 8.8 | The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is due to ins… |
| CVE-2025-43330 | CVE-2025-43330 CVSS 8.2 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to break out of its san… |
| CVE-2025-43329 | CVE-2025-43329 CVSS 8.8 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be… |
| CVE-2025-43323 | CVE-2025-43323 CVSS 8.1 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An … |
| CVE-2025-43270 | CVE-2025-43270 CVSS 8.8 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An ap… |
| CVE-2025-43264 | CVE-2025-43264 CVSS 8.8apple | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process me… |
| CVE-2025-43257 | CVE-2025-43257 CVSS 8.7apple | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox. |
| CVE-2025-43219 | CVE-2025-43219 CVSS 8.8apple | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process me… |
| CVE-2025-43202 | CVE-2025-43202 CVSS 8.8apple | This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memo… |
| CVE-2025-4317 | CVE-2025-4317 CVSS 8.8 | The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all version… |
| CVE-2025-4315 | CVE-2025-4315 CVSS 8.8 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This… |
| CVE-2025-43010 | CVE-2025-43010 CVSS 8.3 | SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an authenticated attacker with SAP standard authorization to execute a cer… |
| CVE-2025-42983 | CVE-2025-42983 CVSS 8.5 | SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or… |
| CVE-2025-42982 | CVE-2025-42982 CVSS 8.8 | SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. Thi… |
| CVE-2025-42976 | CVE-2025-42976 CVSS 8.1 | SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, co… |
| CVE-2025-42959 | CVE-2025-42959 CVSS 8.1 | An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific secur… |
| CVE-2025-42953 | CVE-2025-42953 CVSS 8.1 | SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could… |
| CVE-2025-42951 | CVE-2025-42951 CVSS 8.8 | Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the correspondi… |
| CVE-2025-42933 | CVE-2025-42933 CVSS 8.8 | When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads to exposure of s… |
| CVE-2025-42929 | CVE-2025-42929 CVSS 8.1 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables ar… |
| CVE-2025-42916 | CVE-2025-42916 CVSS 8.1 | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables ar… |
| CVE-2025-42878 | CVE-2025-42878 CVSS 8.2 | SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit the… |
| CVE-2025-4282 | CVE-2025-4282 CVSS 8.8 | A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code o… |
| CVE-2025-4279 | CVE-2025-4279 CVSS 8.8 | The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_replace_get_… |
| CVE-2025-4278 | CVE-2025-4278 CVSS 8.7 | An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search pag… |
| CVE-2025-4260 | CVE-2025-4260 CVSS 8.3 | A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file m\web… |
| CVE-2025-4258 | CVE-2025-4258 CVSS 8.8 | A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master… |
| CVE-2025-4247 | CVE-2025-4247 CVSS 8.8 | A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is an unknown function of the file /delet… |
| CVE-2025-4244 | CVE-2025-4244 CVSS 8.8 | A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This affects an unknown part of the file /seat… |
| CVE-2025-4243 | CVE-2025-4243 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Affected by this issue is some unknown fu… |
| CVE-2025-4232 | CVE-2025-4232 CVSS 8.8 | An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrati… |
| CVE-2025-4200 | CVE-2025-4200 CVSS 8.1 | The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including… |
| CVE-2025-4197 | CVE-2025-4197 CVSS 8.8 | A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is an unknown function of the file /edit_… |
| CVE-2025-4196 | CVE-2025-4196 CVSS 8.8 | A vulnerability was found in SourceCodester Patient Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of … |
| CVE-2025-41766 | CVE-2025-41766 CVSS 8.8 | A low-privileged remote attacker can trigger a stack-based buffer overflow via a crafted HTTP POST request using the ubr-network method resulting in full devic… |