92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 5,951–6,000 of 8,161 in High · page 120 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-3660 | CVE-2025-3660 CVSS 6.5petlibro | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains a broken access control vulnerability that allows authenticated users to access other users' … |
| CVE-2025-36593 | CVE-2025-36593 CVSS 8.8 | Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attac… |
| CVE-2025-36588 | CVE-2025-36588 CVSS 8.8 | Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabil… |
| CVE-2025-36574 | CVE-2025-36574 CVSS 8.2 | Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could p… |
| CVE-2025-36553 | CVE-2025-36553 CVSS 8.8 | A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47.… |
| CVE-2025-36546 | CVE-2025-36546 CVSS 8.1 | On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance Mode; acce… |
| CVE-2025-36528 | CVE-2025-36528 CVSS 8.3 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. |
| CVE-2025-36527 | CVE-2025-36527 CVSS 8.3 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. |
| CVE-2025-36521 | CVE-2025-36521 CVSS 8.8 | MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must ope… |
| CVE-2025-3646 | CVE-2025-3646 CVSS 7.3petlibro | Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unauthorized users to add users as shared o… |
| CVE-2025-3642 | CVE-2025-3642 CVSS 8.8 | A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers a… |
| CVE-2025-3641 | CVE-2025-3641 CVSS 8.8 | A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers a… |
| CVE-2025-3638 | CVE-2025-3638 CVSS 8.8 | A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSR… |
| CVE-2025-36377 | CVE-2025-36377 CVSS 8.8 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate anot… |
| CVE-2025-36376 | CVE-2025-36376 CVSS 8.8 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate anot… |
| CVE-2025-36375 | CVE-2025-36375 CVSS 8.8 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 th… |
| CVE-2025-36367 | CVE-2025-36367 CVSS 8.8 | IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use … |
| CVE-2025-36361 | CVE-2025-36361 CVSS 8.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on cust… |
| CVE-2025-36357 | CVE-2025-36357 CVSS 8.0ibm | IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a speci… |
| CVE-2025-36355 | CVE-2025-36355 CVSS 8.5 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated … |
| CVE-2025-36247 | CVE-2025-36247 CVSS 8.2 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injec… |
| CVE-2025-36245 | CVE-2025-36245 CVSS 8.8ibm | IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary commands with elevated privileges on the sys… |
| CVE-2025-36202 | CVE-2025-36202 CVSS 8.8 | IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the imprope… |
| CVE-2025-3620 | CVE-2025-3620 CVSS 8.8 | Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
| CVE-2025-3619 | CVE-2025-3619 CVSS 8.8 | Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafte… |
| CVE-2025-36174 | CVE-2025-36174 CVSS 8.0 | IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be executed by anot… |
| CVE-2025-3616 | CVE-2025-3616 CVSS 8.8 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb… |
| CVE-2025-36120 | CVE-2025-36120 CVSS 8.8 | IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization c… |
| CVE-2025-36119 | CVE-2025-36119 CVSS 8.8 | IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web s… |
| CVE-2025-36106 | CVE-2025-36106 CVSS 8.2 | IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which cou… |
| CVE-2025-3610 | CVE-2025-3610 CVSS 8.8 | The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to … |
| CVE-2025-36096 | CVE-2025-36096 CVSS 8.1 | IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access … |
| CVE-2025-36094 | CVE-2025-36094 CVSS 8.1 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 c… |
| CVE-2025-36072 | CVE-2025-36072 CVSS 8.8 | IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fix6 IBM webMethods Integration allow an … |
| CVE-2025-3607 | CVE-2025-3607 CVSS 8.8 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including… |
| CVE-2025-36049 | CVE-2025-36049 CVSS 8.8 | IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A rem… |
| CVE-2025-36016 | CVE-2025-36016 CVSS 8.2 | IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to vi… |
| CVE-2025-36004 | CVE-2025-36004 CVSS 8.8 | IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user to gain elevated privileges due to an unqualified library call in IBM Facsimile Support for i. A malicious acto… |
| CVE-2025-35984 | CVE-2025-35984 CVSS 8.8 | A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a… |
| CVE-2025-35975 | CVE-2025-35975 CVSS 8.8 | MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM file … |
| CVE-2025-35971 | CVE-2025-35971 CVSS 8.2 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of servi… |
| CVE-2025-35940 | CVE-2025-35940 CVSS 8.1 | The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to ac… |
| CVE-2025-3587 | CVE-2025-3587 CVSS 8.8 | A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /getTeacherLi… |
| CVE-2025-3585 | CVE-2025-3585 CVSS 8.8 | A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser.… |
| CVE-2025-3556 | CVE-2025-3556 CVSS 8.1 | A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality … |
| CVE-2025-3555 | CVE-2025-3555 CVSS 8.1 | A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php… |
| CVE-2025-3546 | CVE-2025-3546 CVSS 8.0 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affec… |
| CVE-2025-3545 | CVE-2025-3545 CVSS 8.0 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Aff… |
| CVE-2025-3544 | CVE-2025-3544 CVSS 8.0 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue a… |
| CVE-2025-35433 | CVE-2025-35433 CVSS 8.8 | CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log i… |