92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,851–5,900 of 8,161 in High · page 118 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-3968 | CVE-2025-3968 CVSS 8.8 | A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown code of the … |
| CVE-2025-39663 | CVE-2025-39663 CVSS 8.4 | Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service output… |
| CVE-2025-39586 | CVE-2025-39586 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-a… |
| CVE-2025-39570 | CVE-2025-39570 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member wpcom-member allows … |
| CVE-2025-39569 | CVE-2025-39569 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder taskbuilder allows Blind SQL Inje… |
| CVE-2025-39542 | CVE-2025-39542 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Jauhari Xelion Xelion Webchat xelion-webchat allows Privilege Escalation.This issue affects Xelion Webchat: fro… |
| CVE-2025-39536 | CVE-2025-39536 CVSS 8.2 | Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affec… |
| CVE-2025-39533 | CVE-2025-39533 CVSS 8.8 | Missing Authorization vulnerability in Starfish Reviews Starfish Review Generation & Marketing starfish-reviews allows Privilege Escalation.This issue affects … |
| CVE-2025-39527 | CVE-2025-39527 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in bestweblayout Rating by BestWebSoft rating-bws allows Object Injection.This issue affects Rating by BestWebS… |
| CVE-2025-39526 | CVE-2025-39526 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-booking allow… |
| CVE-2025-3952 | CVE-2025-3952 CVSS 8.1 | The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due… |
| CVE-2025-39510 | CVE-2025-39510 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic… |
| CVE-2025-39507 | CVE-2025-39507 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core nasa-core allows P… |
| CVE-2025-39506 | CVE-2025-39506 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core nasa-core allows P… |
| CVE-2025-39493 | CVE-2025-39493 CVSS 8.8 | Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a… |
| CVE-2025-39491 | CVE-2025-39491 CVSS 8.1 | Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through revision. |
| CVE-2025-39490 | CVE-2025-39490 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Backpack Traveler backpa… |
| CVE-2025-39486 | CVE-2025-39486 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Rankie valvepress-rankie allows SQL Injection.… |
| CVE-2025-39482 | CVE-2025-39482 CVSS 8.8 | Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eve… |
| CVE-2025-39475 | CVE-2025-39475 CVSS 8.1 | Path Traversal: '.../...//' vulnerability in Frenify Arlo arlo allows PHP Local File Inclusion.This issue affects Arlo: from n/a through <= 6.0.3. |
| CVE-2025-39473 | CVE-2025-39473 CVSS 8.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebGeniusLab Seofy Core seofy-core allows PHP Local File Inclus… |
| CVE-2025-39472 | CVE-2025-39472 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooComm… |
| CVE-2025-39470 | CVE-2025-39470 CVSS 8.1 | Path Traversal: '.../...//' vulnerability in ThimPress Ivy School ivy-school allows PHP Local File Inclusion.This issue affects Ivy School: from n/a through <=… |
| CVE-2025-3947 | CVE-2025-3947 CVSS 8.2 | The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit th… |
| CVE-2025-39468 | CVE-2025-39468 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pantherius Modal Survey modal-survey.T… |
| CVE-2025-39467 | CVE-2025-39467 CVSS 8.1 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a throug… |
| CVE-2025-39466 | CVE-2025-39466 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local… |
| CVE-2025-3946 | CVE-2025-3946 CVSS 8.2 | The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Control Data Access (CDA). An att… |
| CVE-2025-39458 | CVE-2025-39458 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Foton foton allows PHP L… |
| CVE-2025-39413 | CVE-2025-39413 CVSS 8.8 | Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This issue affects Simple Sitemap – Create … |
| CVE-2025-39405 | CVE-2025-39405 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in mojoomla WPAMS apartment-management allows Privilege Escalation.This issue affects WPAMS: from n/a through <= 4… |
| CVE-2025-39403 | CVE-2025-39403 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apartment-management allows SQL Injection.… |
| CVE-2025-39377 | CVE-2025-39377 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper appsero-helper allows SQL Injection… |
| CVE-2025-39366 | CVE-2025-39366 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0. |
| CVE-2025-39358 | CVE-2025-39358 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Posts Carouse… |
| CVE-2025-39357 | CVE-2025-39357 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System hospital-management a… |
| CVE-2025-39355 | CVE-2025-39355 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking fat-services-booking allows … |
| CVE-2025-39352 | CVE-2025-39352 CVSS 8.2 | Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This… |
| CVE-2025-39350 | CVE-2025-39350 CVSS 8.2 | Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0. |
| CVE-2025-3935 | ConnectWise ScreenConnect Improper Authentication Vulnerability KEVCVSS 7.2ConnectWise | ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allo… |
| CVE-2025-3928 | CVE-2025-3928 KEVCVSS 8.8commvault | Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webserve… |
| CVE-2025-39247 | CVE-2025-39247 CVSS 8.6 | There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission. |
| CVE-2025-3921 | CVE-2025-3921 CVSS 8.2 | The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handel… |
| CVE-2025-39202 | CVE-2025-39202 CVSS 8.1 | A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite file… |
| CVE-2025-3914 | CVE-2025-3914 CVSS 8.8 | The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_download… |
| CVE-2025-3909 | CVE-2025-3909 CVSS 8.1 | Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested ema… |
| CVE-2025-3906 | CVE-2025-3906 CVSS 8.8 | The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wep_… |
| CVE-2025-3887 | CVE-2025-3887 CVSS 8.8 | GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c… |
| CVE-2025-3886 | CVE-2025-3886 CVSS 8.1 | An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool c… |
| CVE-2025-3883 | CVE-2025-3883 CVSS 8.8 | eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbit… |