92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,201–6,250 of 8,161 in High · page 125 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-32475 | CVE-2025-32475 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-32468 | CVE-2025-32468 CVSS 8.8 | A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted … |
| CVE-2025-32463 | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability KEVCVSS 7.8Sudo | Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (-… |
| CVE-2025-32462 | CVE-2025-32462 CVSS 2.8sudo_project | Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on … |
| CVE-2025-32451 | CVE-2025-32451 CVSS 8.8 | A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside … |
| CVE-2025-3244 | CVE-2025-3244 CVSS 8.8 | A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability … |
| CVE-2025-32438 | CVE-2025-32438 CVSS 8.8 | make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable e… |
| CVE-2025-3243 | CVE-2025-3243 CVSS 8.8 | A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the f… |
| CVE-2025-32409 | CVE-2025-32409 CVSS 8.1 | Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP p… |
| CVE-2025-32406 | CVE-2025-32406 CVSS 8.6 | An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML r… |
| CVE-2025-32390 | CVE-2025-32390 CVSS 8.5 | EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to compl… |
| CVE-2025-32367 | CVE-2025-32367 CVSS 8.6 | The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure Direct Object Reference. NOTE: the numbe… |
| CVE-2025-32360 | CVE-2025-32360 CVSS 8.1 | In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer… |
| CVE-2025-32359 | CVE-2025-32359 CVSS 8.8 | In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need… |
| CVE-2025-32354 | CVE-2025-32354 CVSS 8.8 | In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) o… |
| CVE-2025-32353 | CVE-2025-32353 CVSS 8.2 | Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file. |
| CVE-2025-32318 | CVE-2025-32318 CVSS 8.8 | In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution … |
| CVE-2025-32313 | CVE-2025-32313 CVSS 8.4 | In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege … |
| CVE-2025-32310 | CVE-2025-32310 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quickcal allows Privilege Escalation.This is… |
| CVE-2025-32309 | CVE-2025-32309 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Healsoul healsoul allows PHP… |
| CVE-2025-32307 | CVE-2025-32307 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Chameleon HTML5 Audio Player With/Without Pl… |
| CVE-2025-32306 | CVE-2025-32306 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Radio Player Shoutcast & Icecast WordPress P… |
| CVE-2025-32304 | CVE-2025-32304 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP Local Fil… |
| CVE-2025-32302 | CVE-2025-32302 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Winnex winnex allows PHP Local … |
| CVE-2025-32301 | CVE-2025-32301 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown Pro WP Plugin circular_countdown a… |
| CVE-2025-32297 | CVE-2025-32297 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directo… |
| CVE-2025-32294 | CVE-2025-32294 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Oxpitan oxpitan allows PHP Loca… |
| CVE-2025-32293 | CVE-2025-32293 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Finance Consultant finance allows Object Injection.This issue affects Finance Consultant: from … |
| CVE-2025-32290 | CVE-2025-32290 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky HTML5 Music Player lbg-audio3-html5 a… |
| CVE-2025-32289 | CVE-2025-32289 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Yozi yozi allows PHP Local F… |
| CVE-2025-32287 | CVE-2025-32287 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playl… |
| CVE-2025-32286 | CVE-2025-32286 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Butcher butcher allows PHP L… |
| CVE-2025-32284 | CVE-2025-32284 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Pet World petsworld allows Object Injection.This issue affects Pet World: from n/a through <= 2… |
| CVE-2025-32283 | CVE-2025-32283 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue affects Solar Energy: from n/a through <=… |
| CVE-2025-32280 | CVE-2025-32280 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Pro… |
| CVE-2025-32220 | CVE-2025-32220 CVSS 5.4salonbookingsystem | Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Securit… |
| CVE-2025-32158 | CVE-2025-32158 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Syed Balkhi aThemes Addons for Element… |
| CVE-2025-32154 | CVE-2025-32154 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Catch Themes Catch Dark Mode catch-dar… |
| CVE-2025-32151 | CVE-2025-32151 CVSS 7.5themekraft | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themekraft BuddyForms buddyforms allow… |
| CVE-2025-3215 | CVE-2025-3215 CVSS 8.8 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of… |
| CVE-2025-32149 | CVE-2025-32149 CVSS 8.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in winkm89 teachPress teachpress allows SQL Injection.This i… |
| CVE-2025-32148 | CVE-2025-32148 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daisycon Daisycon prijsvergelijkers daisycon allows SQL I… |
| CVE-2025-32147 | CVE-2025-32147 CVSS 8.8 | Missing Authorization vulnerability in coothemes Easy WP Optimizer easy-wp-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.Th… |
| CVE-2025-32146 | CVE-2025-32146 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager js-jobs allows … |
| CVE-2025-32145 | CVE-2025-32145 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a thro… |
| CVE-2025-32144 | CVE-2025-32144 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Board Manager… |
| CVE-2025-32143 | CVE-2025-32143 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in PickPlugins Accordion accordions allows Object Injection.This issue affects Accordion: from n/a through <= 2… |
| CVE-2025-32142 | CVE-2025-32142 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors motors-car-dealership-… |
| CVE-2025-32141 | CVE-2025-32141 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix MasterStudy LMS masterstudy-l… |
| CVE-2025-32119 | CVE-2025-32119 CVSS 8.2 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate Payments for WooCommerce cardgate allow… |