92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,251–6,300 of 8,161 in High · page 126 of 164

IDTitleSummary
CVE-2025-32111CVE-2025-32111
CVSS 8.7
The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.
CVE-2025-32107CVE-2025-32107
CVSS 8.0
OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exp…
CVE-2025-32091CVE-2025-32091
CVSS 8.2
Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privilege. Syste…
CVE-2025-32089CVE-2025-32089
CVSS 8.8
A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36…
CVE-2025-32062CVE-2025-32062
CVSS 8.8
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of …
CVE-2025-32061CVE-2025-32061
CVSS 8.8
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of …
CVE-2025-32059CVE-2025-32059
CVSS 8.8
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of …
CVE-2025-3205CVE-2025-3205
CVSS 8.8
A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.p…
CVE-2025-32018CVE-2025-32018
CVSS 8.0
Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a regression affecting the set of file path…
CVE-2025-32017CVE-2025-32017
CVSS 8.8
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that e…
CVE-2025-32008CVE-2025-32008
CVSS 8.6
Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of service. Ne…
CVE-2025-31965CVE-2025-31965
CVSS 8.2
Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information …
CVE-2025-31958CVE-2025-31958
CVSS 3.7hcltech
HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through…
CVE-2025-31951CVE-2025-31951
CVSS 8.8
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identif…
CVE-2025-31932CVE-2025-31932
CVSS 8.8
Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Co…
CVE-2025-31930CVE-2025-31930
CVSS 8.8
A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2E…
CVE-2025-31928CVE-2025-31928
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multimedia Responsive Carousel with Image Vi…
CVE-2025-31926CVE-2025-31926
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player lbg-audio5-html5-shoutca…
CVE-2025-31924CVE-2025-31924
CVSS 8.8
Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Arts: from n/…
CVE-2025-31920CVE-2025-31920
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech WP Guppy wp-guppy allows SQL Injection.This is…
CVE-2025-3192CVE-2025-3192
CVSS 8.2
Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restrictio…
CVE-2025-31913CVE-2025-31913
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Ogami ogami allows PHP Local…
CVE-2025-31912CVE-2025-31912
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Enzio - Responsive Business Wor…
CVE-2025-31828CVE-2025-31828
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!…
CVE-2025-3177CVE-2025-3177
CVSS 8.1
A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipul…
CVE-2025-31722CVE-2025-31722
CVSS 8.8
In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configu…
CVE-2025-31713CVE-2025-31713
CVSS 8.4
In engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no addi…
CVE-2025-31710CVE-2025-31710
CVSS 8.4
In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no addit…
CVE-2025-31701CVE-2025-31701
CVSS 8.1
A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, pote…
CVE-2025-31700CVE-2025-31700
CVSS 8.1
A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, pote…
CVE-2025-31694CVE-2025-31694
CVSS 8.1
Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): fr…
CVE-2025-31690CVE-2025-31690
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1…
CVE-2025-31689CVE-2025-31689
CVSS 8.1
Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data …
CVE-2025-31686CVE-2025-31686
CVSS 8.1
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 befor…
CVE-2025-31678CVE-2025-31678
CVSS 8.2
Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0…
CVE-2025-31677CVE-2025-31677
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Inte…
CVE-2025-31676CVE-2025-31676
CVSS 8.8
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.
CVE-2025-31649CVE-2025-31649
CVSS 8.7
A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus …
CVE-2025-31644CVE-2025-31644
CVSS 8.7
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow a…
CVE-2025-31643CVE-2025-31643
CVSS 8.8
Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPCHURCH: from n/a through 2.7.0.
CVE-2025-31641CVE-2025-31641
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberSlider uber-classic allows SQL Injection…
CVE-2025-31640CVE-2025-31640
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic Responsive Slider and Carousel WordPre…
CVE-2025-31637CVE-2025-31637
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT lbg-audio8-html5-radio_ads allows SQL …
CVE-2025-31634CVE-2025-31634
CVSS 8.8
Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue affects Insurance: from n/a through <= 3…
CVE-2025-31633CVE-2025-31633
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kiamo - Responsive Business Ser…
CVE-2025-31632CVE-2025-31632
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SpyroPress La Boom allows PHP Local Fi…
CVE-2025-31619CVE-2025-31619
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync actionwear-product…
CVE-2025-3161CVE-2025-3161
CVSS 8.8
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function ShutdownSetAdd of the file /goform/ShutdownSetA…
CVE-2025-31564CVE-2025-31564
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Wri…
CVE-2025-31561CVE-2025-31561
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifi…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.