92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,001–6,050 of 8,161 in High · page 121 of 164

IDTitleSummary
CVE-2025-3543CVE-2025-3543
CVSS 8.0
A vulnerability has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014 and classified as critical. This vulnerability aff…
CVE-2025-3542CVE-2025-3542
CVSS 8.0
A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGI_Wiza…
CVE-2025-3541CVE-2025-3541
CVSS 8.0
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by th…
CVE-2025-3540CVE-2025-3540
CVSS 8.0
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this vulnerability …
CVE-2025-3539CVE-2025-3539
CVSS 8.0
A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected is…
CVE-2025-3538CVE-2025-3538
CVSS 8.8
A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function auth_asp of the file /auth.asp of the co…
CVE-2025-3529CVE-2025-3529
CVSS 8.2
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'fi…
CVE-2025-3528CVE-2025-3528
CVSS 8.2
A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. Thi…
CVE-2025-3520CVE-2025-3520
CVSS 8.1
The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and incl…
CVE-2025-35115CVE-2025-35115
CVSS 8.1
Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the…
CVE-2025-35055CVE-2025-35055
CVSS 8.8newforma
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writable by the …
CVE-2025-35030CVE-2025-35030
CVSS 8.1mieweb
Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrativ…
CVE-2025-3501CVE-2025-3501
CVSS 8.2
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
CVE-2025-3497CVE-2025-3497
CVSS 8.7
The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus,…
CVE-2025-3486CVE-2025-3486
CVSS 8.8
Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec…
CVE-2025-3485CVE-2025-3485
CVSS 8.8
Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…
CVE-2025-3455CVE-2025-3455
CVSS 8.8
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …
CVE-2025-34514CVE-2025-34514
CVSS 8.8ilevia
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that c…
CVE-2025-34511CVE-2025-34511
CVSS 8.8
Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricte…
CVE-2025-34510CVE-2025-34510
CVSS 8.8
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip S…
CVE-2025-34506CVE-2025-34506
CVSS 8.8wbce
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attacker…
CVE-2025-34491CVE-2025-34491
CVSS 8.8
GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sendi…
CVE-2025-3445CVE-2025-3445
CVSS 8.1
A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path trave…
CVE-2025-34438CVE-2025-34438
CVSS 8.1wwbn
AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata …
CVE-2025-34437CVE-2025-34437
CVSS 8.8wwbn
AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but …
CVE-2025-34436CVE-2025-34436
CVSS 8.8
AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference…
CVE-2025-34335CVE-2025-34335
CVSS 8.8
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the lice…
CVE-2025-34334CVE-2025-34334
CVSS 8.8
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax tes…
CVE-2025-34312CVE-2025-34312
CVSS 8.8ipfire
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands a…
CVE-2025-34311CVE-2025-34311
CVSS 8.8ipfire
IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands a…
CVE-2025-34298CVE-2025-34298
CVSS 8.8nagios
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own em…
CVE-2025-34291CVE-2025-34291
KEVCVSS 8.8langflow
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS …
CVE-2025-34284CVE-2025-34284
CVSS 8.8nagios
Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an…
CVE-2025-34231CVE-2025-34231
CVSS 8.6
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain …
CVE-2025-34228CVE-2025-34228
CVSS 8.6
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain …
CVE-2025-34227CVE-2025-34227
CVSS 8.8
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, a…
CVE-2025-34225CVE-2025-34225
CVSS 8.6
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain …
CVE-2025-34202CVE-2025-34202
CVSS 8.8
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and SaaS deployments) expose Docker intern…
CVE-2025-34199CVE-2025-34199
CVSS 8.1
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior to 20.0.2786 (VA and SaaS deployments) c…
CVE-2025-34191CVE-2025-34191
CVSS 8.4
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deployments) cont…
CVE-2025-34187CVE-2025-34187
CVSS 8.8
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If …
CVE-2025-3418CVE-2025-3418
CVSS 8.8
The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly restricting…
CVE-2025-3417CVE-2025-3417
CVSS 8.8
The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on…
CVE-2025-34161CVE-2025-34161
CVSS 8.8coollabs
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows aut…
CVE-2025-34159CVE-2025-34159
CVSS 8.8coollabs
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows…
CVE-2025-34158CVE-2025-34158
CVSS 8.5
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the…
CVE-2025-3413CVE-2025-3413
CVSS 8.8
A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerabi…
CVE-2025-3410CVE-2025-3410
CVSS 8.8
A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-pla…
CVE-2025-3409CVE-2025-3409
CVSS 8.8
A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argu…
CVE-2025-34088CVE-2025-34088
CVSS 8.8pandorafms
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated user…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.