92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,901–5,950 of 8,161 in High · page 119 of 164

IDTitleSummary
CVE-2025-3882CVE-2025-3882
CVSS 8.8
eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to ex…
CVE-2025-3881CVE-2025-3881
CVSS 8.8
eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu…
CVE-2025-3879CVE-2025-3879
CVSS 8.8
Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the potential bypas…
CVE-2025-3876CVE-2025-3876
CVSS 8.8
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handl…
CVE-2025-3854CVE-2025-3854
CVSS 8.0
A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6…
CVE-2025-3852CVE-2025-3852
CVSS 8.8
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to the plugin…
CVE-2025-3839CVE-2025-3839
CVSS 8.0
A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused t…
CVE-2025-3836CVE-2025-3836
CVSS 8.3
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.
CVE-2025-38352Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
KEVCVSS 7.8Linux
Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability.
CVE-2025-3834CVE-2025-3834
CVSS 8.1
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.
CVE-2025-3833CVE-2025-3833
CVSS 8.1
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
CVE-2025-3820CVE-2025-3820
CVSS 8.8
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysUplinkCheck…
CVE-2025-3817CVE-2025-3817
CVSS 8.8
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the …
CVE-2025-3812CVE-2025-3812
CVSS 8.1
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the qcld_openai_delet…
CVE-2025-3803CVE-2025-3803
CVSS 8.8
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleReboot…
CVE-2025-3802CVE-2025-3802
CVSS 8.8
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSe…
CVE-2025-3796CVE-2025-3796
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us…
CVE-2025-3786CVE-2025-3786
CVSS 8.8
A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform…
CVE-2025-3785CVE-2025-3785
CVSS 8.8
A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP…
CVE-2025-3776CVE-2025-3776
CVSS 8.3
The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targ…
CVE-2025-37736CVE-2025-37736
CVSS 8.8elastic
Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. …
CVE-2025-3765CVE-2025-3765
CVSS 8.8
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some u…
CVE-2025-3764CVE-2025-3764
CVSS 8.8
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of…
CVE-2025-3761CVE-2025-3761
CVSS 8.8
The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is du…
CVE-2025-3740CVE-2025-3740
CVSS 8.8
The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'pag…
CVE-2025-3719CVE-2025-3719
CVSS 8.1
An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited…
CVE-2025-37162CVE-2025-37162
CVSS 6.5arubanetworks
A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successfu…
CVE-2025-37158CVE-2025-37158
CVSS 8.8
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remo…
CVE-2025-37157CVE-2025-37157
CVSS 8.8
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remo…
CVE-2025-37124CVE-2025-37124
CVSS 8.6
A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitat…
CVE-2025-37123CVE-2025-37123
CVSS 8.8
A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate priv…
CVE-2025-37101CVE-2025-37101
CVSS 8.7
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker wi…
CVE-2025-3697CVE-2025-3697
CVSS 8.8
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some u…
CVE-2025-3696CVE-2025-3696
CVSS 8.8
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of…
CVE-2025-36924CVE-2025-36924
CVSS 8.0google
In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remot…
CVE-2025-36923CVE-2025-36923
CVSS 8.0google
In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to re…
CVE-2025-36920CVE-2025-36920
CVSS 8.4
In hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation …
CVE-2025-36901CVE-2025-36901
CVSS 8.8
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.
CVE-2025-36899CVE-2025-36899
CVSS 8.4
There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no …
CVE-2025-36891CVE-2025-36891
CVSS 8.8
Elevation of privilege
CVE-2025-36855CVE-2025-36855
CVSS 8.8
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://c…
CVE-2025-36854CVE-2025-36854
CVSS 8.1
A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the r…
CVE-2025-3685CVE-2025-3685
CVSS 8.8
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. Affected is an unknown function of the file /edit_…
CVE-2025-36845CVE-2025-36845
CVSS 8.6
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint t…
CVE-2025-36728CVE-2025-36728
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.
CVE-2025-36727CVE-2025-36727
CVSS 8.8
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.
CVE-2025-3671CVE-2025-3671
CVSS 8.8
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'pa…
CVE-2025-36640CVE-2025-36640
CVSS 8.8
A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileg…
CVE-2025-3663CVE-2025-3663
CVSS 8.2
A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setW…
CVE-2025-36600CVE-2025-36600
CVSS 8.2
Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerability in an externally developed component.…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.