92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,351–6,400 of 8,161 in High · page 128 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-31019 | CVE-2025-31019 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-policy-manager allows Authentication Abus… |
| CVE-2025-3101 | CVE-2025-3101 CVSS 8.8 | The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.7. This is due to the plugin n… |
| CVE-2025-30998 | CVE-2025-30998 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rico Macchi WP Links Page wp-links-page allows SQL Inject… |
| CVE-2025-30992 | CVE-2025-30992 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Puca puca allows PHP Local Fil… |
| CVE-2025-30979 | CVE-2025-30979 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Pixelating image slideshow gallery pixelating-im… |
| CVE-2025-30974 | CVE-2025-30974 CVSS 8.8 | Missing Authorization vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allows Exploiting Incorrectly Configured Access Control Security … |
| CVE-2025-30969 | CVE-2025-30969 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Images Gallery wp-iframe-images-gallery a… |
| CVE-2025-30960 | CVE-2025-30960 CVSS 8.3 | Missing Authorization vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster: from n/a through <= 6.5.8. |
| CVE-2025-30947 | CVE-2025-30947 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade popup cool-fade-popup allows Blind SQL… |
| CVE-2025-30910 | CVE-2025-30910 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CreativeMindsSolutions CM Download Manager cm-download-manager … |
| CVE-2025-30901 | CVE-2025-30901 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Help Desk js-support-ticket… |
| CVE-2025-3090 | CVE-2025-3090 CVSS 8.2 | An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function. |
| CVE-2025-30892 | CVE-2025-30892 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Object Injection.This issue affects WpTravelly: from n… |
| CVE-2025-30891 | CVE-2025-30891 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly tour-booking… |
| CVE-2025-30889 | CVE-2025-30889 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial Slider: fr… |
| CVE-2025-30846 | CVE-2025-30846 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu by MotoPre… |
| CVE-2025-30825 | CVE-2025-30825 CVSS 8.8 | Missing Authorization vulnerability in WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce wpc-smart-linked-products allows Privilege Es… |
| CVE-2025-30819 | CVE-2025-30819 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Igor Benic Simple Giveaways giveasap allows SQL Injection… |
| CVE-2025-30810 | CVE-2025-30810 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-lea… |
| CVE-2025-30806 | CVE-2025-30806 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Constantin Boiangiu Vimeotheque codeflavors-vimeo-video-p… |
| CVE-2025-3079 | CVE-2025-3079 CVSS 8.7 | A passback vulnerability which relates to office/small office multifunction printers and laser printers. |
| CVE-2025-30788 | CVE-2025-30788 CVSS 8.2 | Cross-Site Request Forgery (CSRF) vulnerability in Eli EZ SQL Reports Shortcode Widget and DB Backup elisqlreports allows SQL Injection.This issue affects EZ S… |
| CVE-2025-30784 | CVE-2025-30784 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Shuffle WP Subscription Forms wp-subscription-forms al… |
| CVE-2025-30783 | CVE-2025-30783 CVSS 8.2 | Cross-Site Request Forgery (CSRF) vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows SQL Injection.This issue affects WP … |
| CVE-2025-3078 | CVE-2025-3078 CVSS 8.7 | A passback vulnerability which relates to production printers and office multifunction printers. |
| CVE-2025-30775 | CVE-2025-30775 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows SQ… |
| CVE-2025-30772 | CVE-2025-30772 CVSS 8.8 | Missing Authorization vulnerability in WPClever WPC Smart Upsell Funnel for WooCommerce wpc-smart-upsell-funnel allows Privilege Escalation.This issue affects … |
| CVE-2025-30751 | CVE-2025-30751 CVSS 8.8 | Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.27 and 23.4-23.8. Easily exploitable v… |
| CVE-2025-30749 | CVE-2025-30749 CVSS 8.1 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions t… |
| CVE-2025-30744 | CVE-2025-30744 CVSS 8.1 | Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors). Supported versions that are affect… |
| CVE-2025-30743 | CVE-2025-30743 CVSS 8.1 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). The supported version that is a… |
| CVE-2025-30735 | CVE-2025-30735 CVSS 8.1 | Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Page and Field Configuration). The supporte… |
| CVE-2025-30712 | CVE-2025-30712 CVSS 8.1 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploit… |
| CVE-2025-3069 | CVE-2025-3069 CVSS 8.8 | Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML… |
| CVE-2025-3068 | CVE-2025-3068 CVSS 8.8 | Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a craf… |
| CVE-2025-3067 | CVE-2025-3067 CVSS 8.8 | Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in spec… |
| CVE-2025-30664 | CVE-2025-30664 CVSS 8.2 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access. |
| CVE-2025-3066 | CVE-2025-3066 CVSS 8.8 | Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
| CVE-2025-3064 | CVE-2025-3064 CVSS 8.8 | The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.1. This is due to missi… |
| CVE-2025-30635 | CVE-2025-30635 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeAtelier IDonatePro idonate-pro al… |
| CVE-2025-3063 | CVE-2025-3063 CVSS 8.8 | The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing cap… |
| CVE-2025-30628 | CVE-2025-30628 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Page Builder… |
| CVE-2025-30590 | CVE-2025-30590 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dourou Flickr set slideshows flickr-set-slideshows allows… |
| CVE-2025-30589 | CVE-2025-30589 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dourou Flickr set slideshows flickr-set-slideshows allows… |
| CVE-2025-30582 | CVE-2025-30582 CVSS 8.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in aytechnet DyaPress ERP/CRM dyapress allows PHP Local File Inclu… |
| CVE-2025-3058 | CVE-2025-3058 CVSS 8.8 | The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability ch… |
| CVE-2025-30569 | CVE-2025-30569 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featured Entries wp-featured-entries allows S… |
| CVE-2025-30562 | CVE-2025-30562 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdistillery Navigation Tree Elementor navigation-tree-el… |
| CVE-2025-3055 | CVE-2025-3055 CVSS 8.1 | The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() fun… |
| CVE-2025-3054 | CVE-2025-3054 CVSS 8.8 | The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all… |