92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,301–6,350 of 8,161 in High · page 127 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-31547 | CVE-2025-31547 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aphotrax Uptime Robot Plugin for WordPress uptime-robot-m… |
| CVE-2025-31542 | CVE-2025-31542 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edit… |
| CVE-2025-31526 | CVE-2025-31526 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powe… |
| CVE-2025-31524 | CVE-2025-31524 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Escalation.This issue affects WP User Pro… |
| CVE-2025-31499 | CVE-2025-31499 CVSS 8.8 | Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to possibly … |
| CVE-2025-31491 | CVE-2025-31491 CVSS 8.6 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.1… |
| CVE-2025-31479 | CVE-2025-31479 CVSS 8.2 | canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if … |
| CVE-2025-31478 | CVE-2025-31478 CVSS 8.2 | Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a s… |
| CVE-2025-31466 | CVE-2025-31466 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post duplicate-post-a… |
| CVE-2025-3143 | CVE-2025-3143 CVSS 8.8 | A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /v… |
| CVE-2025-31422 | CVE-2025-31422 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme visual-arts allows Object Injection.This issue affects Vis… |
| CVE-2025-3142 | CVE-2025-3142 CVSS 8.8 | A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing … |
| CVE-2025-31361 | CVE-2025-31361 CVSS 8.7 | A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5.15.14.19 and Del… |
| CVE-2025-31359 | CVE-2025-31359 CVSS 8.8 | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability … |
| CVE-2025-31353 | CVE-2025-31353 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-31352 | CVE-2025-31352 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-31351 | CVE-2025-31351 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-31350 | CVE-2025-31350 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-31349 | CVE-2025-31349 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-31343 | CVE-2025-31343 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-3134 | CVE-2025-3134 CVSS 8.8 | A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.ph… |
| CVE-2025-31278 | CVE-2025-31278 CVSS 8.8 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18… |
| CVE-2025-31277 | Apple Multiple Products Buffer Overflow Vulnerability KEVCVSS 8.8Apple | Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted we… |
| CVE-2025-31273 | CVE-2025-31273 CVSS 8.8 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.… |
| CVE-2025-31246 | CVE-2025-31246 CVSS 8.8 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may… |
| CVE-2025-31244 | CVE-2025-31244 CVSS 8.8 | A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox. |
| CVE-2025-31234 | CVE-2025-31234 CVSS 8.2 | The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5. An atta… |
| CVE-2025-31223 | CVE-2025-31223 CVSS 8.0apple | The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchO… |
| CVE-2025-31214 | CVE-2025-31214 CVSS 8.1 | This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged network position may b… |
| CVE-2025-31204 | CVE-2025-31204 CVSS 8.8 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.… |
| CVE-2025-31189 | CVE-2025-31189 CVSS 8.2 | A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may… |
| CVE-2025-31132 | CVE-2025-31132 CVSS 8.1 | Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fixed in 2.1.… |
| CVE-2025-31129 | CVE-2025-31129 CVSS 8.8 | Jooby is a web framework for Java and Kotlin. The pac4j io.jooby.internal.pac4j.SessionStoreImpl#get module deserializes untrusted data. This vulnerability is … |
| CVE-2025-31125 | Vite Vitejs Improper Access Control Vulnerability KEVCVSS 7.5Vite | Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicit… |
| CVE-2025-31123 | CVE-2025-31123 CVSS 8.7 | Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails… |
| CVE-2025-31097 | CVE-2025-31097 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hossein Material Dashboard material-da… |
| CVE-2025-31089 | CVE-2025-31089 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fahad Mahmood Order Splitter for WooCommerce woo-order-sp… |
| CVE-2025-31082 | CVE-2025-31082 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in InfornWeb News & Blog Designer Pack bl… |
| CVE-2025-31074 | CVE-2025-31074 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in MDJM Mobile DJ Manager mobile-dj-manager allows Object Injection.This issue affects Mobile DJ Manager: from … |
| CVE-2025-31064 | CVE-2025-31064 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Vizeon - Business Consulting vi… |
| CVE-2025-31060 | CVE-2025-31060 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Capie capie allows PHP Local… |
| CVE-2025-3105 | CVE-2025-3105 CVSS 8.8 | The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, a… |
| CVE-2025-31047 | CVE-2025-31047 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection.This issue affects Themify Edmin: from n/a through 2.0.0. |
| CVE-2025-31044 | CVE-2025-31044 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SEO Pack allows SQL Injection.This issue … |
| CVE-2025-31040 | CVE-2025-31040 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Exthemes WP Food ordering and Restaura… |
| CVE-2025-31038 | CVE-2025-31038 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows Privilege Escalation.This issue affect… |
| CVE-2025-31036 | CVE-2025-31036 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in WPSOLR WPSolr wpsolr-free allows Privilege Escalation.This issue affects WPSolr: from n/a through <= 24.0. |
| CVE-2025-31024 | CVE-2025-31024 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in randyjensen RJ Quickcharts rj-quickcharts allows SQL Inje… |
| CVE-2025-31023 | CVE-2025-31023 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Purab Seo Meta Tags seo-meta-tags allows Cross Site Request Forgery.This issue affects Seo Meta Tags: from n… |
| CVE-2025-3102 | CVE-2025-3102 CVSS 8.1 | The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due … |