92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,451–6,500 of 8,161 in High · page 130 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-2997 | CVE-2025-2997 CVSS 8.8 | A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. The manipu… |
| CVE-2025-29967 | CVE-2025-29967 CVSS 8.8 | Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-29966 | CVE-2025-29966 CVSS 8.8 | Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. |
| CVE-2025-29964 | CVE-2025-29964 CVSS 8.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. |
| CVE-2025-29963 | CVE-2025-29963 CVSS 8.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. |
| CVE-2025-29962 | CVE-2025-29962 CVSS 8.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. |
| CVE-2025-29928 | CVE-2025-29928 CVSS 8.0 | authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage … |
| CVE-2025-29906 | CVE-2025-29906 CVSS 8.6 | Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration … |
| CVE-2025-29905 | CVE-2025-29905 CVSS 8.8 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the … |
| CVE-2025-29894 | CVE-2025-29894 CVSS 8.8 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to… |
| CVE-2025-29893 | CVE-2025-29893 CVSS 8.8 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to… |
| CVE-2025-29892 | CVE-2025-29892 CVSS 8.8 | An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user acc… |
| CVE-2025-29885 | CVE-2025-29885 CVSS 8.8 | An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who h… |
| CVE-2025-29884 | CVE-2025-29884 CVSS 8.8 | An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who h… |
| CVE-2025-29883 | CVE-2025-29883 CVSS 8.8 | An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who h… |
| CVE-2025-2985 | CVE-2025-2985 CVSS 8.8 | A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affects an unknown part of the file update_a… |
| CVE-2025-29840 | CVE-2025-29840 CVSS 8.8 | Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. |
| CVE-2025-2984 | CVE-2025-2984 CVSS 8.8 | A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of th… |
| CVE-2025-29828 | CVE-2025-29828 CVSS 8.1 | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network. |
| CVE-2025-29827 | CVE-2025-29827 CVSS 8.8 | Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-29826 | CVE-2025-29826 CVSS 8.8 | Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-29824 | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. |
| CVE-2025-29814 | CVE-2025-29814 CVSS 8.8 | Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-29807 | CVE-2025-29807 CVSS 8.8 | Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. |
| CVE-2025-29794 | CVE-2025-29794 CVSS 8.8 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-29778 | CVE-2025-29778 CVSS 8.0 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegEx… |
| CVE-2025-29635 | D-Link DIR-823X Command Injection Vulnerability KEVCVSS 7.2D-Link | D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST… |
| CVE-2025-29534 | CVE-2025-29534 CVSS 8.8 | An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbit… |
| CVE-2025-29509 | CVE-2025-29509 CVSS 8.8 | Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external websit… |
| CVE-2025-29471 | CVE-2025-29471 CVSS 8.3 | Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field. |
| CVE-2025-2945 | CVE-2025-2945 CVSS 8.8 | Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoint… |
| CVE-2025-29394 | CVE-2025-29394 CVSS 8.1 | An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type. |
| CVE-2025-29390 | CVE-2025-29390 CVSS 8.8 | jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php. |
| CVE-2025-2938 | CVE-2025-2938 CVSS 8.8 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowe… |
| CVE-2025-2933 | CVE-2025-2933 CVSS 8.8 | The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a miss… |
| CVE-2025-2932 | CVE-2025-2932 CVSS 8.8 | The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' function in al… |
| CVE-2025-29314 | CVE-2025-29314 CVSS 8.1 | Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to access sensitive in… |
| CVE-2025-29281 | CVE-2025-29281 CVSS 8.8 | In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute … |
| CVE-2025-29230 | CVE-2025-29230 CVSS 8.6 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via th… |
| CVE-2025-29093 | CVE-2025-29093 CVSS 8.2 | File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images compon… |
| CVE-2025-29017 | CVE-2025-29017 CVSS 8.8 | A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parame… |
| CVE-2025-29004 | CVE-2025-29004 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Hol… |
| CVE-2025-29002 | CVE-2025-29002 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Simen snssimen allows PHP Loc… |
| CVE-2025-28998 | CVE-2025-28998 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in serpednet SERPed.net serped-net allows… |
| CVE-2025-28993 | CVE-2025-28993 CVSS 8.6 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-cache allows Code Injection.This issue a… |
| CVE-2025-28992 | CVE-2025-28992 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Anton snsanton allows PHP… |
| CVE-2025-28991 | CVE-2025-28991 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Evon snsevon allows PHP Local… |
| CVE-2025-28990 | CVE-2025-28990 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Vicky snsvicky allows PHP… |
| CVE-2025-28986 | CVE-2025-28986 CVSS 8.2 | Cross-Site Request Forgery (CSRF) vulnerability in Webaholicson Epicwin Plugin epicwin-subscribers allows SQL Injection.This issue affects Epicwin Plugin: from… |
| CVE-2025-2898 | CVE-2025-2898 CVSS 8.8 | IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in… |