92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,401–6,450 of 8,161 in High · page 129 of 164

IDTitleSummary
CVE-2025-3053CVE-2025-3053
CVSS 8.8
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and …
CVE-2025-3052CVE-2025-3052
CVSS 8.2
An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its valu…
CVE-2025-30515CVE-2025-30515
CVSS 8.8
CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.
CVE-2025-30473CVE-2025-30473
CVSS 8.8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the parti…
CVE-2025-30403CVE-2025-30403
CVSS 8.1
A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v20…
CVE-2025-30402CVE-2025-30402
CVSS 8.1
A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other unde…
CVE-2025-30400Microsoft Windows DWM Core Library Use-After-Free Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-30398CVE-2025-30398
CVSS 8.1microsoft
Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.
CVE-2025-30397Microsoft Windows Scripting Engine Type Confusion Vulnerability
KEVCVSS 7.5Microsoft
Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially …
CVE-2025-30390CVE-2025-30390
CVSS 8.8
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
CVE-2025-3039CVE-2025-3039
CVSS 8.8
A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add_…
CVE-2025-3038CVE-2025-3038
CVSS 8.8
A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /vi…
CVE-2025-30358CVE-2025-30358
CVSS 8.1
Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attac…
CVE-2025-3034CVE-2025-3034
CVSS 8.1mozilla
Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…
CVE-2025-3030CVE-2025-3030
CVSS 8.1mozilla
Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption a…
CVE-2025-30290CVE-2025-30290
CVSS 8.7
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln…
CVE-2025-30289CVE-2025-30289
CVSS 8.2
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inje…
CVE-2025-30288CVE-2025-30288
CVSS 8.2
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypas…
CVE-2025-30287CVE-2025-30287
CVSS 8.2
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution…
CVE-2025-30286CVE-2025-30286
CVSS 8.4
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inje…
CVE-2025-30285CVE-2025-30285
CVSS 8.4
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code …
CVE-2025-30284CVE-2025-30284
CVSS 8.4
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code …
CVE-2025-30279CVE-2025-30279
CVSS 8.8
An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …
CVE-2025-30278CVE-2025-30278
CVSS 8.8
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit th…
CVE-2025-30277CVE-2025-30277
CVSS 8.8
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit th…
CVE-2025-30276CVE-2025-30276
CVSS 8.8
An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerabil…
CVE-2025-30273CVE-2025-30273
CVSS 8.1qnap
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can th…
CVE-2025-30269CVE-2025-30269
CVSS 8.1
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then …
CVE-2025-30264CVE-2025-30264
CVSS 8.8qnap
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then …
CVE-2025-30255CVE-2025-30255
CVSS 8.2
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of servi…
CVE-2025-30236CVE-2025-30236
CVSS 8.6
Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST req…
CVE-2025-30234CVE-2025-30234
CVSS 8.3
SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone imag…
CVE-2025-30213CVE-2025-30213
CVSS 8.8
Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way t…
CVE-2025-30172CVE-2025-30172
CVSS 8.0
Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: throu…
CVE-2025-30165CVE-2025-30165
CVSS 8.0
vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node co…
CVE-2025-30154reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
KEVCVSS 8.6reviewdog
reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.
CVE-2025-3015CVE-2025-3015
CVSS 8.8
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepr…
CVE-2025-30142CVE-2025-30142
CVSS 8.1
An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism for rec…
CVE-2025-30106CVE-2025-30106
CVSS 8.8
On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi rang…
CVE-2025-30093CVE-2025-30093
CVSS 8.1
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization …
CVE-2025-30066tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
KEVCVSS 8.6tj-actions
tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Ac…
CVE-2025-30032CVE-2025-30032
CVSS 8.8
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the …
CVE-2025-30031CVE-2025-30031
CVSS 8.8
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the …
CVE-2025-30030CVE-2025-30030
CVSS 8.8
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the …
CVE-2025-30005CVE-2025-30005
CVSS 8.3
Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete …
CVE-2025-30004CVE-2025-30004
CVSS 8.8
Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands a…
CVE-2025-30003CVE-2025-30003
CVSS 8.8
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the …
CVE-2025-30002CVE-2025-30002
CVSS 8.8
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the …
CVE-2025-29987CVE-2025-29987
CVSS 8.8
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulner…
CVE-2025-29986CVE-2025-29986
CVSS 8.3
Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Commo…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.