92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,051–6,100 of 8,161 in High · page 122 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-34087 | CVE-2025-34087 CVSS 8.8 | An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain … |
| CVE-2025-34086 | CVE-2025-34086 CVSS 8.8boltcms | Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with … |
| CVE-2025-3408 | CVE-2025-3408 CVSS 8.8 | A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation… |
| CVE-2025-3407 | CVE-2025-3407 CVSS 8.8 | A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerability is the function stbhw_build_tileset_f… |
| CVE-2025-3404 | CVE-2025-3404 CVSS 8.8 | The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the savePackage function in all … |
| CVE-2025-34034 | CVE-2025-34034 CVSS 8.8 | A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known defaul… |
| CVE-2025-34033 | CVE-2025-34033 CVSS 8.8 | An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi … |
| CVE-2025-34029 | CVE-2025-34029 CVSS 8.8 | An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSys… |
| CVE-2025-34026 | Versa Concerto Improper Authentication Vulnerability KEVCVSS 7.5Versa | Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker… |
| CVE-2025-34024 | CVE-2025-34024 CVSS 8.8 | An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp form handler. The /goform/mp endpoint impr… |
| CVE-2025-3348 | CVE-2025-3348 CVSS 8.8 | A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. This vulnerability affects unknown code of the file /ed… |
| CVE-2025-3347 | CVE-2025-3347 CVSS 8.8 | A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /dental_p… |
| CVE-2025-3346 | CVE-2025-3346 CVSS 8.8 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the function formSetPPTPServer of the file /goform… |
| CVE-2025-3328 | CVE-2025-3328 CVSS 8.8 | A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form_fast_setting_wifi_set of the file /gof… |
| CVE-2025-33245 | CVE-2025-33245 CVSS 8.8 | NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to… |
| CVE-2025-3324 | CVE-2025-3324 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality o… |
| CVE-2025-3323 | CVE-2025-3323 CVSS 8.8 | A vulnerability classified as critical was found in godcheese/code-projects Nimrod 0.8. Affected by this vulnerability is the function searchAllByName of the f… |
| CVE-2025-33225 | CVE-2025-33225 CVSS 8.4 | NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names. A successful explo… |
| CVE-2025-33214 | CVE-2025-33214 CVSS 8.8 | NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successful exploit of this v… |
| CVE-2025-33213 | CVE-2025-33213 CVSS 8.8 | NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful expl… |
| CVE-2025-33208 | CVE-2025-33208 CVSS 8.8 | NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploit of this vulnerabi… |
| CVE-2025-33186 | CVE-2025-33186 CVSS 8.8 | NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, an… |
| CVE-2025-33181 | CVE-2025-33181 CVSS 8.8 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit … |
| CVE-2025-33180 | CVE-2025-33180 CVSS 8.8 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit … |
| CVE-2025-33179 | CVE-2025-33179 CVSS 8.8 | NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successf… |
| CVE-2025-33137 | CVE-2025-33137 CVSS 8.8 | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another u… |
| CVE-2025-33136 | CVE-2025-33136 CVSS 8.8 | IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another u… |
| CVE-2025-33112 | CVE-2025-33112 CVSS 8.4 | IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper… |
| CVE-2025-33109 | CVE-2025-33109 CVSS 8.8 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database … |
| CVE-2025-33108 | CVE-2025-33108 CVSS 8.8 | IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges du… |
| CVE-2025-33103 | CVE-2025-33103 CVSS 8.8 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command… |
| CVE-2025-33077 | CVE-2025-33077 CVSS 8.8 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local use… |
| CVE-2025-33076 | CVE-2025-33076 CVSS 8.8 | IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local use… |
| CVE-2025-33074 | CVE-2025-33074 CVSS 8.8 | Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network. |
| CVE-2025-33073 | Microsoft Windows SMB Client Improper Access Control Vulnerability KEVCVSS 8.8Microsoft | Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially… |
| CVE-2025-33071 | CVE-2025-33071 CVSS 8.1 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-33070 | CVE-2025-33070 CVSS 8.1 | Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-33067 | CVE-2025-33067 CVSS 8.4 | Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-33066 | CVE-2025-33066 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-33064 | CVE-2025-33064 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2025-33054 | CVE-2025-33054 CVSS 8.1 | Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-33053 | Microsoft Windows External Control of File Name or Path Vulnerability KEVCVSS 8.8Microsoft | Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location sp… |
| CVE-2025-3304 | CVE-2025-3304 CVSS 8.8 | A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /d… |
| CVE-2025-33031 | CVE-2025-33031 CVSS 8.8 | An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit t… |
| CVE-2025-33015 | CVE-2025-33015 CVSS 8.8 | IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. |
| CVE-2025-33012 | CVE-2025-33012 CVSS 6.3ibm | IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain… |
| CVE-2025-33005 | CVE-2025-33005 CVSS 8.8 | IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the … |
| CVE-2025-33000 | CVE-2025-33000 CVSS 8.8 | Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. Sys… |
| CVE-2025-32992 | CVE-2025-32992 CVSS 8.5 | Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control. |
| CVE-2025-32990 | CVE-2025-32990 CVSS 6.5gnu | A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain sett… |