92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 5,951–6,000 of 8,161 in High · page 120 of 164

IDTitleSummary
CVE-2025-3660CVE-2025-3660
CVSS 6.5petlibro
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' …
CVE-2025-36593CVE-2025-36593
CVSS 8.8
Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attac…
CVE-2025-36588CVE-2025-36588
CVSS 8.8
Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabil…
CVE-2025-36574CVE-2025-36574
CVSS 8.2
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could p…
CVE-2025-36553CVE-2025-36553
CVSS 8.8
A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47.…
CVE-2025-36546CVE-2025-36546
CVSS 8.1
On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; acce…
CVE-2025-36528CVE-2025-36528
CVSS 8.3
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.
CVE-2025-36527CVE-2025-36527
CVSS 8.3
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
CVE-2025-36521CVE-2025-36521
CVSS 8.8
MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must ope…
CVE-2025-3646CVE-2025-3646
CVSS 7.3petlibro
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared o…
CVE-2025-3642CVE-2025-3642
CVSS 8.8
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers a…
CVE-2025-3641CVE-2025-3641
CVSS 8.8
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers a…
CVE-2025-3638CVE-2025-3638
CVSS 8.8
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSR…
CVE-2025-36377CVE-2025-36377
CVSS 8.8
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate anot…
CVE-2025-36376CVE-2025-36376
CVSS 8.8
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate anot…
CVE-2025-36375CVE-2025-36375
CVSS 8.8
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 th…
CVE-2025-36367CVE-2025-36367
CVSS 8.8
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use …
CVE-2025-36361CVE-2025-36361
CVSS 8.8
IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on cust…
CVE-2025-36357CVE-2025-36357
CVSS 8.0ibm
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a speci…
CVE-2025-36355CVE-2025-36355
CVSS 8.5
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated …
CVE-2025-36247CVE-2025-36247
CVSS 8.2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injec…
CVE-2025-36245CVE-2025-36245
CVSS 8.8ibm
IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the sys…
CVE-2025-36202CVE-2025-36202
CVSS 8.8
IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the imprope…
CVE-2025-3620CVE-2025-3620
CVSS 8.8
Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…
CVE-2025-3619CVE-2025-3619
CVSS 8.8
Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafte…
CVE-2025-36174CVE-2025-36174
CVSS 8.0
IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be executed by anot…
CVE-2025-3616CVE-2025-3616
CVSS 8.8
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb…
CVE-2025-36120CVE-2025-36120
CVSS 8.8
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization c…
CVE-2025-36119CVE-2025-36119
CVSS 8.8
IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web s…
CVE-2025-36106CVE-2025-36106
CVSS 8.2
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which cou…
CVE-2025-3610CVE-2025-3610
CVSS 8.8
The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to …
CVE-2025-36096CVE-2025-36096
CVSS 8.1
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access …
CVE-2025-36094CVE-2025-36094
CVSS 8.1
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 c…
CVE-2025-36072CVE-2025-36072
CVSS 8.8
IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an …
CVE-2025-3607CVE-2025-3607
CVSS 8.8
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including…
CVE-2025-36049CVE-2025-36049
CVSS 8.8
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A rem…
CVE-2025-36016CVE-2025-36016
CVSS 8.2
IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to vi…
CVE-2025-36004CVE-2025-36004
CVSS 8.8
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious acto…
CVE-2025-35984CVE-2025-35984
CVSS 8.8
A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a…
CVE-2025-35975CVE-2025-35975
CVSS 8.8
MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM file …
CVE-2025-35971CVE-2025-35971
CVSS 8.2
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of servi…
CVE-2025-35940CVE-2025-35940
CVSS 8.1
The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to ac…
CVE-2025-3587CVE-2025-3587
CVSS 8.8
A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /getTeacherLi…
CVE-2025-3585CVE-2025-3585
CVSS 8.8
A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser.…
CVE-2025-3556CVE-2025-3556
CVSS 8.1
A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality …
CVE-2025-3555CVE-2025-3555
CVSS 8.1
A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php…
CVE-2025-3546CVE-2025-3546
CVSS 8.0
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affec…
CVE-2025-3545CVE-2025-3545
CVSS 8.0
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Aff…
CVE-2025-3544CVE-2025-3544
CVSS 8.0
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue a…
CVE-2025-35433CVE-2025-35433
CVSS 8.8
CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log i…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.