92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,901–5,950 of 8,161 in High · page 119 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-3882 | CVE-2025-3882 CVSS 8.8 | eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to ex… |
| CVE-2025-3881 | CVE-2025-3881 CVSS 8.8 | eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu… |
| CVE-2025-3879 | CVE-2025-3879 CVSS 8.8 | Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypas… |
| CVE-2025-3876 | CVE-2025-3876 CVSS 8.8 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handl… |
| CVE-2025-3854 | CVE-2025-3854 CVSS 8.0 | A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6… |
| CVE-2025-3852 | CVE-2025-3852 CVSS 8.8 | The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin… |
| CVE-2025-3839 | CVE-2025-3839 CVSS 8.0 | A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused t… |
| CVE-2025-3836 | CVE-2025-3836 CVSS 8.3 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report. |
| CVE-2025-38352 | Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability KEVCVSS 7.8Linux | Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. |
| CVE-2025-3834 | CVE-2025-3834 CVSS 8.1 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report. |
| CVE-2025-3833 | CVE-2025-3833 CVSS 8.1 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. |
| CVE-2025-3820 | CVE-2025-3820 CVSS 8.8 | A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysUplinkCheck… |
| CVE-2025-3817 | CVE-2025-3817 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the … |
| CVE-2025-3812 | CVE-2025-3812 CVSS 8.1 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the qcld_openai_delet… |
| CVE-2025-3803 | CVE-2025-3803 CVSS 8.8 | A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleReboot… |
| CVE-2025-3802 | CVE-2025-3802 CVSS 8.8 | A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSe… |
| CVE-2025-3796 | CVE-2025-3796 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us… |
| CVE-2025-3786 | CVE-2025-3786 CVSS 8.8 | A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform… |
| CVE-2025-3785 | CVE-2025-3785 CVSS 8.8 | A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP… |
| CVE-2025-3776 | CVE-2025-3776 CVSS 8.3 | The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targ… |
| CVE-2025-37736 | CVE-2025-37736 CVSS 8.8elastic | Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. … |
| CVE-2025-3765 | CVE-2025-3765 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some u… |
| CVE-2025-3764 | CVE-2025-3764 CVSS 8.8 | A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of… |
| CVE-2025-3761 | CVE-2025-3761 CVSS 8.8 | The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is du… |
| CVE-2025-3740 | CVE-2025-3740 CVSS 8.8 | The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'pag… |
| CVE-2025-3719 | CVE-2025-3719 CVSS 8.1 | An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited… |
| CVE-2025-37162 | CVE-2025-37162 CVSS 6.5arubanetworks | A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successfu… |
| CVE-2025-37158 | CVE-2025-37158 CVSS 8.8 | A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remo… |
| CVE-2025-37157 | CVE-2025-37157 CVSS 8.8 | A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remo… |
| CVE-2025-37124 | CVE-2025-37124 CVSS 8.6 | A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitat… |
| CVE-2025-37123 | CVE-2025-37123 CVSS 8.8 | A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate priv… |
| CVE-2025-37101 | CVE-2025-37101 CVSS 8.7 | A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker wi… |
| CVE-2025-3697 | CVE-2025-3697 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some u… |
| CVE-2025-3696 | CVE-2025-3696 CVSS 8.8 | A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of… |
| CVE-2025-36924 | CVE-2025-36924 CVSS 8.0google | In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remot… |
| CVE-2025-36923 | CVE-2025-36923 CVSS 8.0google | In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to re… |
| CVE-2025-36920 | CVE-2025-36920 CVSS 8.4 | In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation … |
| CVE-2025-36901 | CVE-2025-36901 CVSS 8.8 | WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223. |
| CVE-2025-36899 | CVE-2025-36899 CVSS 8.4 | There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no … |
| CVE-2025-36891 | CVE-2025-36891 CVSS 8.8 | Elevation of privilege |
| CVE-2025-36855 | CVE-2025-36855 CVSS 8.8 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://c… |
| CVE-2025-36854 | CVE-2025-36854 CVSS 8.1 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the r… |
| CVE-2025-3685 | CVE-2025-3685 CVSS 8.8 | A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is an unknown function of the file /edit_… |
| CVE-2025-36845 | CVE-2025-36845 CVSS 8.6 | An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint t… |
| CVE-2025-36728 | CVE-2025-36728 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11. |
| CVE-2025-36727 | CVE-2025-36727 CVSS 8.8 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12. |
| CVE-2025-3671 | CVE-2025-3671 CVSS 8.8 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'pa… |
| CVE-2025-36640 | CVE-2025-36640 CVSS 8.8 | A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileg… |
| CVE-2025-3663 | CVE-2025-3663 CVSS 8.2 | A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setW… |
| CVE-2025-36600 | CVE-2025-36600 CVSS 8.2 | Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component.… |