92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,051–6,100 of 8,161 in High · page 122 of 164

IDTitleSummary
CVE-2025-34087CVE-2025-34087
CVSS 8.8
An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain …
CVE-2025-34086CVE-2025-34086
CVSS 8.8boltcms
Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with …
CVE-2025-3408CVE-2025-3408
CVSS 8.8
A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation…
CVE-2025-3407CVE-2025-3407
CVSS 8.8
A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerability is the function stbhw_build_tileset_f…
CVE-2025-3404CVE-2025-3404
CVSS 8.8
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all …
CVE-2025-34034CVE-2025-34034
CVSS 8.8
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known defaul…
CVE-2025-34033CVE-2025-34033
CVSS 8.8
An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi …
CVE-2025-34029CVE-2025-34029
CVSS 8.8
An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSys…
CVE-2025-34026Versa Concerto Improper Authentication Vulnerability
KEVCVSS 7.5Versa
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker…
CVE-2025-34024CVE-2025-34024
CVSS 8.8
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint impr…
CVE-2025-3348CVE-2025-3348
CVSS 8.8
A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerability affects unknown code of the file /ed…
CVE-2025-3347CVE-2025-3347
CVSS 8.8
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_p…
CVE-2025-3346CVE-2025-3346
CVSS 8.8
A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform…
CVE-2025-3328CVE-2025-3328
CVSS 8.8
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file /gof…
CVE-2025-33245CVE-2025-33245
CVSS 8.8
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to…
CVE-2025-3324CVE-2025-3324
CVSS 8.8
A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality o…
CVE-2025-3323CVE-2025-3323
CVSS 8.8
A vulnerability classified as critical was found in godcheese/code-projects Nimrod 0.8. Affected by this vulnerability is the function searchAllByName of the f…
CVE-2025-33225CVE-2025-33225
CVSS 8.4
NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names. A successful explo…
CVE-2025-33214CVE-2025-33214
CVSS 8.8
NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successful exploit of this v…
CVE-2025-33213CVE-2025-33213
CVSS 8.8
NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful expl…
CVE-2025-33208CVE-2025-33208
CVSS 8.8
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploit of this vulnerabi…
CVE-2025-33186CVE-2025-33186
CVSS 8.8
NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, an…
CVE-2025-33181CVE-2025-33181
CVSS 8.8
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit …
CVE-2025-33180CVE-2025-33180
CVSS 8.8
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit …
CVE-2025-33179CVE-2025-33179
CVSS 8.8
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successf…
CVE-2025-33137CVE-2025-33137
CVSS 8.8
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another u…
CVE-2025-33136CVE-2025-33136
CVSS 8.8
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another u…
CVE-2025-33112CVE-2025-33112
CVSS 8.4
IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper…
CVE-2025-33109CVE-2025-33109
CVSS 8.8
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database …
CVE-2025-33108CVE-2025-33108
CVSS 8.8
IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges du…
CVE-2025-33103CVE-2025-33103
CVSS 8.8
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command…
CVE-2025-33077CVE-2025-33077
CVSS 8.8
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local use…
CVE-2025-33076CVE-2025-33076
CVSS 8.8
IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local use…
CVE-2025-33074CVE-2025-33074
CVSS 8.8
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.
CVE-2025-33073Microsoft Windows SMB Client Improper Access Control Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially…
CVE-2025-33071CVE-2025-33071
CVSS 8.1
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2025-33070CVE-2025-33070
CVSS 8.1
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-33067CVE-2025-33067
CVSS 8.4
Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2025-33066CVE-2025-33066
CVSS 8.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-33064CVE-2025-33064
CVSS 8.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
CVE-2025-33054CVE-2025-33054
CVSS 8.1
Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-33053 Microsoft Windows External Control of File Name or Path Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location sp…
CVE-2025-3304CVE-2025-3304
CVSS 8.8
A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /d…
CVE-2025-33031CVE-2025-33031
CVSS 8.8
An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit t…
CVE-2025-33015CVE-2025-33015
CVSS 8.8
IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.
CVE-2025-33012CVE-2025-33012
CVSS 6.3ibm
IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain…
CVE-2025-33005CVE-2025-33005
CVSS 8.8
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the …
CVE-2025-33000CVE-2025-33000
CVSS 8.8
Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. Sys…
CVE-2025-32992CVE-2025-32992
CVSS 8.5
Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.
CVE-2025-32990CVE-2025-32990
CVSS 6.5gnu
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain sett…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.