92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,401–6,450 of 8,161 in High · page 129 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-3053 | CVE-2025-3053 CVSS 8.8 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and … |
| CVE-2025-3052 | CVE-2025-3052 CVSS 8.2 | An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its valu… |
| CVE-2025-30515 | CVE-2025-30515 CVSS 8.8 | CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system. |
| CVE-2025-30473 | CVE-2025-30473 CVSS 8.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider. When using the parti… |
| CVE-2025-30403 | CVE-2025-30403 CVSS 8.1 | A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v20… |
| CVE-2025-30402 | CVE-2025-30402 CVSS 8.1 | A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other unde… |
| CVE-2025-30400 | Microsoft Windows DWM Core Library Use-After-Free Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. |
| CVE-2025-30398 | CVE-2025-30398 CVSS 8.1microsoft | Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-30397 | Microsoft Windows Scripting Engine Type Confusion Vulnerability KEVCVSS 7.5Microsoft | Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially … |
| CVE-2025-30390 | CVE-2025-30390 CVSS 8.8 | Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-3039 | CVE-2025-3039 CVSS 8.8 | A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add_… |
| CVE-2025-3038 | CVE-2025-3038 CVSS 8.8 | A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /vi… |
| CVE-2025-30358 | CVE-2025-30358 CVSS 8.1 | Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in Mesop prior to version 0.14.1 allows attac… |
| CVE-2025-3034 | CVE-2025-3034 CVSS 8.1mozilla | Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
| CVE-2025-3030 | CVE-2025-3030 CVSS 8.1mozilla | Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption a… |
| CVE-2025-30290 | CVE-2025-30290 CVSS 8.7 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vuln… |
| CVE-2025-30289 | CVE-2025-30289 CVSS 8.2 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inje… |
| CVE-2025-30288 | CVE-2025-30288 CVSS 8.2 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypas… |
| CVE-2025-30287 | CVE-2025-30287 CVSS 8.2 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution… |
| CVE-2025-30286 | CVE-2025-30286 CVSS 8.4 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inje… |
| CVE-2025-30285 | CVE-2025-30285 CVSS 8.4 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code … |
| CVE-2025-30284 | CVE-2025-30284 CVSS 8.4 | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code … |
| CVE-2025-30279 | CVE-2025-30279 CVSS 8.8 | An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit … |
| CVE-2025-30278 | CVE-2025-30278 CVSS 8.8 | An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit th… |
| CVE-2025-30277 | CVE-2025-30277 CVSS 8.8 | An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit th… |
| CVE-2025-30276 | CVE-2025-30276 CVSS 8.8 | An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerabil… |
| CVE-2025-30273 | CVE-2025-30273 CVSS 8.1qnap | An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can th… |
| CVE-2025-30269 | CVE-2025-30269 CVSS 8.1 | A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then … |
| CVE-2025-30264 | CVE-2025-30264 CVSS 8.8qnap | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then … |
| CVE-2025-30255 | CVE-2025-30255 CVSS 8.2 | Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of servi… |
| CVE-2025-30236 | CVE-2025-30236 CVSS 8.6 | Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST req… |
| CVE-2025-30234 | CVE-2025-30234 CVSS 8.3 | SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone imag… |
| CVE-2025-30213 | CVE-2025-30213 CVSS 8.8 | Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way t… |
| CVE-2025-30172 | CVE-2025-30172 CVSS 8.0 | Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: throu… |
| CVE-2025-30165 | CVE-2025-30165 CVSS 8.0 | vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node co… |
| CVE-2025-30154 | reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability KEVCVSS 8.6reviewdog | reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs. |
| CVE-2025-3015 | CVE-2025-3015 CVSS 8.8 | A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepr… |
| CVE-2025-30142 | CVE-2025-30142 CVSS 8.1 | An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism for rec… |
| CVE-2025-30106 | CVE-2025-30106 CVSS 8.8 | On IROAD v9 devices, the dashcam has hardcoded default credentials ("qwertyuiop") that cannot be changed by the user. This allows an attacker within Wi-Fi rang… |
| CVE-2025-30093 | CVE-2025-30093 CVSS 8.1 | HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization … |
| CVE-2025-30066 | tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability KEVCVSS 8.6tj-actions | tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Ac… |
| CVE-2025-30032 | CVE-2025-30032 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-30031 | CVE-2025-30031 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-30030 | CVE-2025-30030 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-30005 | CVE-2025-30005 CVSS 8.3 | Xorcom CompletePBX is vulnerable to a path traversal via the Diagnostics reporting module, which will allow reading of arbitrary files and additionally delete … |
| CVE-2025-30004 | CVE-2025-30004 CVSS 8.8 | Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands a… |
| CVE-2025-30003 | CVE-2025-30003 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-30002 | CVE-2025-30002 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-29987 | CVE-2025-29987 CVSS 8.8 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulner… |
| CVE-2025-29986 | CVE-2025-29986 CVSS 8.3 | Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Commo… |