92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,801–5,850 of 8,161 in High · page 117 of 164

IDTitleSummary
CVE-2025-41110CVE-2025-41110
CVSS 8.8ghostrobotics
Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi…
CVE-2025-4111CVE-2025-4111
CVSS 8.8
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/v…
CVE-2025-4110CVE-2025-4110
CVSS 8.8
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of th…
CVE-2025-4109CVE-2025-4109
CVSS 8.8
A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown function…
CVE-2025-41078CVE-2025-41078
CVSS 8.1
Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, us…
CVE-2025-41077CVE-2025-41077
CVSS 8.1
IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access …
CVE-2025-4103CVE-2025-4103
CVSS 8.8
The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_ajax_wpgm_start_geojson_import() function…
CVE-2025-4096CVE-2025-4096
CVSS 8.8
Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …
CVE-2025-40946CVE-2025-40946
CVSS 8.3
A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All version…
CVE-2025-40937CVE-2025-40937
CVSS 8.3siemens
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST …
CVE-2025-40932CVE-2025-40932
CVSS 8.2
Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids insecurely. The default session id generato…
CVE-2025-4093CVE-2025-4093
CVSS 8.1mozilla
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort thi…
CVE-2025-40920CVE-2025-40920
CVSS 8.6
Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use …
CVE-2025-4091CVE-2025-4091
CVSS 8.1mozilla
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption a…
CVE-2025-40899CVE-2025-40899
CVSS 8.9
A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authentic…
CVE-2025-40898CVE-2025-40898
CVSS 8.1
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated u…
CVE-2025-40897CVE-2025-40897
CVSS 8.1
An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for us…
CVE-2025-40892CVE-2025-40892
CVSS 8.9
A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user…
CVE-2025-40889CVE-2025-40889
CVSS 8.1
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with l…
CVE-2025-40886CVE-2025-40886
CVSS 8.8
A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited pr…
CVE-2025-40837CVE-2025-40837
CVSS 8.8
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges …
CVE-2025-40801CVE-2025-40801
CVSS 8.1
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All v…
CVE-2025-4080CVE-2025-4080
CVSS 8.8
A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functional…
CVE-2025-40780CVE-2025-40780
CVSS 8.6
In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source po…
CVE-2025-40778CVE-2025-40778
CVSS 8.6
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue aff…
CVE-2025-40776CVE-2025-40776
CVSS 8.6
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9…
CVE-2025-40758CVE-2025-40758
CVSS 8.7
A vulnerability has been identified in Mendix SAML (Mendix 10.12 compatible) (All versions < V4.0.3), Mendix SAML (Mendix 10.21 compatible) (All versions < V4.…
CVE-2025-40755CVE-2025-40755
CVSS 8.8siemens
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCoun…
CVE-2025-40743CVE-2025-40743
CVSS 8.3
A vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINUMERIK 840D sl (All…
CVE-2025-40738CVE-2025-40738
CVSS 8.8
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded…
CVE-2025-40737CVE-2025-40737
CVSS 8.8
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded…
CVE-2025-40735CVE-2025-40735
CVSS 8.8
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticat…
CVE-2025-40728CVE-2025-40728
CVSS 8.8
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databas…
CVE-2025-4072CVE-2025-4072
CVSS 8.8
A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects some unknown processing of the file /admi…
CVE-2025-40670CVE-2025-40670
CVSS 8.8
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by …
CVE-2025-4050CVE-2025-4050
CVSS 8.8
Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gesture…
CVE-2025-4046CVE-2025-4046
CVSS 8.5
A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization
CVE-2025-4044CVE-2025-4044
CVSS 8.2
Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an ar…
CVE-2025-4032CVE-2025-4032
CVSS 8.1
A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the function …
CVE-2025-4022CVE-2025-4022
CVSS 8.8
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator o…
CVE-2025-4008Smartbedded Meteobridge Command Injection Vulnerability
KEVCVSS 8.8Smartbedded
Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with e…
CVE-2025-4007CVE-2025-4007
CVSS 8.8
A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgidhcpsCfgSe…
CVE-2025-3993CVE-2025-3993
CVSS 8.8
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWsc…
CVE-2025-3992CVE-2025-3992
CVSS 8.8
A vulnerability has been found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formW…
CVE-2025-3991CVE-2025-3991
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boafrm/formWdsEncryp…
CVE-2025-3990CVE-2025-3990
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this issue is some unknown functionality of t…
CVE-2025-3989CVE-2025-3989
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is an unknown functionality of the file /bo…
CVE-2025-3988CVE-2025-3988
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected is an unknown function of the file /boafrm/formPortFw. The m…
CVE-2025-3987CVE-2025-3987
CVSS 8.8
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/for…
CVE-2025-3982CVE-2025-3982
CVSS 8.8
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/node…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.