92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,751–5,800 of 8,161 in High · page 116 of 164

IDTitleSummary
CVE-2025-41758CVE-2025-41758
CVSS 8.8
A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to path traversal this can lead to overwri…
CVE-2025-41757CVE-2025-41757
CVSS 8.8
A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevated privileges and does not validate the …
CVE-2025-41756CVE-2025-41756
CVSS 8.1
A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API endpoint to write arbitrary files on the sys…
CVE-2025-41736CVE-2025-41736
CVSS 8.8
A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a…
CVE-2025-41735CVE-2025-41735
CVSS 8.8
A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.
CVE-2025-4173CVE-2025-4173
CVSS 8.8
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_cart of the f…
CVE-2025-41726CVE-2025-41726
CVSS 8.8
A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API a…
CVE-2025-41719CVE-2025-41719
CVSS 8.8
A low privileged remote attacker can corrupt the webserver users storage on the device by setting a sequence of unsupported characters which leads to deletion …
CVE-2025-41717CVE-2025-41717
CVSS 8.8
An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injectio…
CVE-2025-41714CVE-2025-41714
CVSS 8.8
The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the se…
CVE-2025-41699CVE-2025-41699
CVSS 8.8
An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resu…
CVE-2025-41684CVE-2025-41684
CVSS 8.8
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in th…
CVE-2025-41683CVE-2025-41683
CVSS 8.8
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in th…
CVE-2025-41682CVE-2025-41682
CVSS 8.8
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.
CVE-2025-41668CVE-2025-41668
CVSS 8.8
A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute acc…
CVE-2025-41667CVE-2025-41667
CVSS 8.8
A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file …
CVE-2025-41666CVE-2025-41666
CVSS 8.8
A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the dev…
CVE-2025-41661CVE-2025-41661
CVSS 8.8
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) pro…
CVE-2025-41660CVE-2025-41660
CVSS 8.8
A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
CVE-2025-41659CVE-2025-41659
CVSS 8.3
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allo…
CVE-2025-41654CVE-2025-41654
CVSS 8.2
An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by th…
CVE-2025-41645CVE-2025-41645
CVSS 8.6
An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake.
CVE-2025-4157CVE-2025-4157
CVSS 8.8
A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booki…
CVE-2025-4156CVE-2025-4156
CVSS 8.8
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/cha…
CVE-2025-4155CVE-2025-4155
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/edit-boat.p…
CVE-2025-4154CVE-2025-4154
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this issue is some unknown functi…
CVE-2025-41450CVE-2025-41450
CVSS 8.2
Improper Authentication vulnerability in Danfoss AKSM8xxA Series.This issue affects Danfoss AK-SM 8xxA Series prior to version 4.2
CVE-2025-41444CVE-2025-41444
CVSS 8.3
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.
CVE-2025-41427CVE-2025-41427
CVSS 8.8
WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability…
CVE-2025-41425CVE-2025-41425
CVSS 8.1
DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to prevent legitimate users from accessing the w…
CVE-2025-41407CVE-2025-41407
CVSS 8.3
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
CVE-2025-41403CVE-2025-41403
CVSS 8.3
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
CVE-2025-4139CVE-2025-4139
CVSS 8.8
A vulnerability classified as critical was found in Netgear EX6120 1.0.0.68. Affected by this vulnerability is the function fwAcosCgiInbound. The manipulation …
CVE-2025-41374CVE-2025-41374
CVSS 8.8
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated …
CVE-2025-41373CVE-2025-41373
CVSS 8.8
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated …
CVE-2025-41372CVE-2025-41372
CVSS 8.8
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated …
CVE-2025-41371CVE-2025-41371
CVSS 8.8
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated …
CVE-2025-41370CVE-2025-41370
CVSS 8.8
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated …
CVE-2025-41368CVE-2025-41368
CVSS 8.1
Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions…
CVE-2025-41258CVE-2025-41258
CVSS 8.0
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG A…
CVE-2025-41255CVE-2025-41255
CVSS 8.0
Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Window…
CVE-2025-41251CVE-2025-41251
CVSS 8.1
VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potenti…
CVE-2025-41250CVE-2025-41250
CVSS 8.5
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create sc…
CVE-2025-41244Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
KEVCVSS 7.8Broadcom
Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative…
CVE-2025-41235CVE-2025-41235
CVSS 8.6
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.
CVE-2025-41229CVE-2025-41229
CVSS 8.2
VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit …
CVE-2025-41225CVE-2025-41225
CVSS 8.8
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script actio…
CVE-2025-41224CVE-2025-41224
CVSS 8.8
A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.10.0), RUGGEDCOM RS416NCv2 …
CVE-2025-4122CVE-2025-4122
CVSS 8.8
A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been rated as critical. Affected by this issue is the function sub_435E04. The manipulation of…
CVE-2025-4113CVE-2025-4113
CVSS 8.8
A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the f…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.