92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,001–6,050 of 8,161 in High · page 121 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-3543 | CVE-2025-3543 CVSS 8.0 | A vulnerability has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014 and classified as critical. This vulnerability aff… |
| CVE-2025-3542 | CVE-2025-3542 CVSS 8.0 | A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGI_Wiza… |
| CVE-2025-3541 | CVE-2025-3541 CVSS 8.0 | A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by th… |
| CVE-2025-3540 | CVE-2025-3540 CVSS 8.0 | A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this vulnerability … |
| CVE-2025-3539 | CVE-2025-3539 CVSS 8.0 | A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected is… |
| CVE-2025-3538 | CVE-2025-3538 CVSS 8.8 | A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function auth_asp of the file /auth.asp of the co… |
| CVE-2025-3529 | CVE-2025-3529 CVSS 8.2 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'fi… |
| CVE-2025-3528 | CVE-2025-3528 CVSS 8.2 | A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. Thi… |
| CVE-2025-3520 | CVE-2025-3520 CVSS 8.1 | The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and incl… |
| CVE-2025-35115 | CVE-2025-35115 CVSS 8.1 | Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the… |
| CVE-2025-35055 | CVE-2025-35055 CVSS 8.8newforma | Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the … |
| CVE-2025-35030 | CVE-2025-35030 CVSS 8.1mieweb | Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrativ… |
| CVE-2025-3501 | CVE-2025-3501 CVSS 8.2 | A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended. |
| CVE-2025-3497 | CVE-2025-3497 CVSS 8.7 | The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus,… |
| CVE-2025-3486 | CVE-2025-3486 CVSS 8.8 | Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec… |
| CVE-2025-3485 | CVE-2025-3485 CVSS 8.8 | Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff… |
| CVE-2025-3455 | CVE-2025-3455 CVSS 8.8 | The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … |
| CVE-2025-34514 | CVE-2025-34514 CVSS 8.8ilevia | Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that c… |
| CVE-2025-34511 | CVE-2025-34511 CVSS 8.8 | Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricte… |
| CVE-2025-34510 | CVE-2025-34510 CVSS 8.8 | Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip S… |
| CVE-2025-34506 | CVE-2025-34506 CVSS 8.8wbce | WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attacker… |
| CVE-2025-34491 | CVE-2025-34491 CVSS 8.8 | GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sendi… |
| CVE-2025-3445 | CVE-2025-3445 CVSS 8.1 | A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path trave… |
| CVE-2025-34438 | CVE-2025-34438 CVSS 8.1wwbn | AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata … |
| CVE-2025-34437 | CVE-2025-34437 CVSS 8.8wwbn | AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but … |
| CVE-2025-34436 | CVE-2025-34436 CVSS 8.8 | AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference… |
| CVE-2025-34335 | CVE-2025-34335 CVSS 8.8 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the lice… |
| CVE-2025-34334 | CVE-2025-34334 CVSS 8.8 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax tes… |
| CVE-2025-34312 | CVE-2025-34312 CVSS 8.8ipfire | IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands a… |
| CVE-2025-34311 | CVE-2025-34311 CVSS 8.8ipfire | IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands a… |
| CVE-2025-34298 | CVE-2025-34298 CVSS 8.8nagios | Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own em… |
| CVE-2025-34291 | CVE-2025-34291 KEVCVSS 8.8langflow | Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS … |
| CVE-2025-34284 | CVE-2025-34284 CVSS 8.8nagios | Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an… |
| CVE-2025-34231 | CVE-2025-34231 CVSS 8.6 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain … |
| CVE-2025-34228 | CVE-2025-34228 CVSS 8.6 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain … |
| CVE-2025-34227 | CVE-2025-34227 CVSS 8.8 | Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, a… |
| CVE-2025-34225 | CVE-2025-34225 CVSS 8.6 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain … |
| CVE-2025-34202 | CVE-2025-34202 CVSS 8.8 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker intern… |
| CVE-2025-34199 | CVE-2025-34199 CVSS 8.1 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 (VA and SaaS deployments) c… |
| CVE-2025-34191 | CVE-2025-34191 CVSS 8.4 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deployments) cont… |
| CVE-2025-34187 | CVE-2025-34187 CVSS 8.8 | Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If … |
| CVE-2025-3418 | CVE-2025-3418 CVSS 8.8 | The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting… |
| CVE-2025-3417 | CVE-2025-3417 CVSS 8.8 | The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on… |
| CVE-2025-34161 | CVE-2025-34161 CVSS 8.8coollabs | Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows aut… |
| CVE-2025-34159 | CVE-2025-34159 CVSS 8.8coollabs | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows… |
| CVE-2025-34158 | CVE-2025-34158 CVSS 8.5 | Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the… |
| CVE-2025-3413 | CVE-2025-3413 CVSS 8.8 | A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerabi… |
| CVE-2025-3410 | CVE-2025-3410 CVSS 8.8 | A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-pla… |
| CVE-2025-3409 | CVE-2025-3409 CVSS 8.8 | A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argu… |
| CVE-2025-34088 | CVE-2025-34088 CVSS 8.8pandorafms | An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated user… |