92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,251–6,300 of 8,161 in High · page 126 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-32111 | CVE-2025-32111 CVSS 8.7 | The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout. |
| CVE-2025-32107 | CVE-2025-32107 CVSS 8.0 | OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exp… |
| CVE-2025-32091 | CVE-2025-32091 CVSS 8.2 | Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privilege. Syste… |
| CVE-2025-32089 | CVE-2025-32089 CVSS 8.8 | A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36… |
| CVE-2025-32062 | CVE-2025-32062 CVSS 8.8 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of … |
| CVE-2025-32061 | CVE-2025-32061 CVSS 8.8 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of … |
| CVE-2025-32059 | CVE-2025-32059 CVSS 8.8 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of … |
| CVE-2025-3205 | CVE-2025-3205 CVSS 8.8 | A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.p… |
| CVE-2025-32018 | CVE-2025-32018 CVSS 8.0 | Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a regression affecting the set of file path… |
| CVE-2025-32017 | CVE-2025-32017 CVSS 8.8 | Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that e… |
| CVE-2025-32008 | CVE-2025-32008 CVSS 8.6 | Out-of-bounds write in the firmware for the Intel(R) AMT and Intel(R) Standard Manageability within Ring 3: User Applications may allow a denial of service. Ne… |
| CVE-2025-31965 | CVE-2025-31965 CVSS 8.2 | Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information … |
| CVE-2025-31958 | CVE-2025-31958 CVSS 3.7hcltech | HCL BigFix Service Management is susceptible to HTTP Request Smuggling. HTTP request smuggling vulnerabilities arise when websites route HTTP requests through… |
| CVE-2025-31951 | CVE-2025-31951 CVSS 8.8 | HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identif… |
| CVE-2025-31932 | CVE-2025-31932 CVSS 8.8 | Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Co… |
| CVE-2025-31930 | CVE-2025-31930 CVSS 8.8 | A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2E… |
| CVE-2025-31928 | CVE-2025-31928 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multimedia Responsive Carousel with Image Vi… |
| CVE-2025-31926 | CVE-2025-31926 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player lbg-audio5-html5-shoutca… |
| CVE-2025-31924 | CVE-2025-31924 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts crafts-and-arts allows Object Injection.This issue affects Crafts & Arts: from n/… |
| CVE-2025-31920 | CVE-2025-31920 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech WP Guppy wp-guppy allows SQL Injection.This is… |
| CVE-2025-3192 | CVE-2025-3192 CVSS 8.2 | Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restrictio… |
| CVE-2025-31913 | CVE-2025-31913 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Ogami ogami allows PHP Local… |
| CVE-2025-31912 | CVE-2025-31912 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Enzio - Responsive Business Wor… |
| CVE-2025-31828 | CVE-2025-31828 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!… |
| CVE-2025-3177 | CVE-2025-3177 CVSS 8.1 | A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipul… |
| CVE-2025-31722 | CVE-2025-31722 CVSS 8.8 | In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configu… |
| CVE-2025-31713 | CVE-2025-31713 CVSS 8.4 | In engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no addi… |
| CVE-2025-31710 | CVE-2025-31710 CVSS 8.4 | In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no addit… |
| CVE-2025-31701 | CVE-2025-31701 CVSS 8.1 | A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, pote… |
| CVE-2025-31700 | CVE-2025-31700 CVSS 8.1 | A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, pote… |
| CVE-2025-31694 | CVE-2025-31694 CVSS 8.1 | Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): fr… |
| CVE-2025-31690 | CVE-2025-31690 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1… |
| CVE-2025-31689 | CVE-2025-31689 CVSS 8.1 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data … |
| CVE-2025-31686 | CVE-2025-31686 CVSS 8.1 | Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 befor… |
| CVE-2025-31678 | CVE-2025-31678 CVSS 8.2 | Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0… |
| CVE-2025-31677 | CVE-2025-31677 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal AI (Artificial Intelligence) allows Cross Site Request Forgery.This issue affects AI (Artificial Inte… |
| CVE-2025-31676 | CVE-2025-31676 CVSS 8.8 | Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3. |
| CVE-2025-31649 | CVE-2025-31649 CVSS 8.7 | A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus … |
| CVE-2025-31644 | CVE-2025-31644 CVSS 8.7 | When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow a… |
| CVE-2025-31643 | CVE-2025-31643 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPCHURCH: from n/a through 2.7.0. |
| CVE-2025-31641 | CVE-2025-31641 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberSlider uber-classic allows SQL Injection… |
| CVE-2025-31640 | CVE-2025-31640 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic Responsive Slider and Carousel WordPre… |
| CVE-2025-31637 | CVE-2025-31637 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT lbg-audio8-html5-radio_ads allows SQL … |
| CVE-2025-31634 | CVE-2025-31634 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Insurance insurance allows Object Injection.This issue affects Insurance: from n/a through <= 3… |
| CVE-2025-31633 | CVE-2025-31633 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kiamo - Responsive Business Ser… |
| CVE-2025-31632 | CVE-2025-31632 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SpyroPress La Boom allows PHP Local Fi… |
| CVE-2025-31619 | CVE-2025-31619 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in marcoingraiti Actionwear products sync actionwear-product… |
| CVE-2025-3161 | CVE-2025-3161 CVSS 8.8 | A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function ShutdownSetAdd of the file /goform/ShutdownSetA… |
| CVE-2025-31564 | CVE-2025-31564 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Wri… |
| CVE-2025-31561 | CVE-2025-31561 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Ultimate Push Notifications ultimate-push-notifi… |