92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,451–6,500 of 8,161 in High · page 130 of 164

IDTitleSummary
CVE-2025-2997CVE-2025-2997
CVSS 8.8
A vulnerability was found in zhangyanbo2007 youkefu 4.2.0. It has been classified as critical. Affected is an unknown function of the file /res/url. The manipu…
CVE-2025-29967CVE-2025-29967
CVSS 8.8
Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-29966CVE-2025-29966
CVSS 8.8
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
CVE-2025-29964CVE-2025-29964
CVSS 8.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-29963CVE-2025-29963
CVSS 8.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-29962CVE-2025-29962
CVSS 8.8
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-29928CVE-2025-29928
CVSS 8.0
authentik is an open-source identity provider. Prior to versions 2024.12.4 and 2025.2.3, when authentik was configured to use the database for session storage …
CVE-2025-29906CVE-2025-29906
CVSS 8.6
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration …
CVE-2025-29905CVE-2025-29905
CVSS 8.8
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the …
CVE-2025-29894CVE-2025-29894
CVSS 8.8
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to…
CVE-2025-29893CVE-2025-29893
CVSS 8.8
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to…
CVE-2025-29892CVE-2025-29892
CVSS 8.8
An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user acc…
CVE-2025-29885CVE-2025-29885
CVSS 8.8
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who h…
CVE-2025-29884CVE-2025-29884
CVSS 8.8
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who h…
CVE-2025-29883CVE-2025-29883
CVSS 8.8
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who h…
CVE-2025-2985CVE-2025-2985
CVSS 8.8
A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affects an unknown part of the file update_a…
CVE-2025-29840CVE-2025-29840
CVSS 8.8
Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-2984CVE-2025-2984
CVSS 8.8
A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of th…
CVE-2025-29828CVE-2025-29828
CVSS 8.1
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.
CVE-2025-29827CVE-2025-29827
CVSS 8.8
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
CVE-2025-29826CVE-2025-29826
CVSS 8.8
Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
CVE-2025-29824Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-29814CVE-2025-29814
CVSS 8.8
Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
CVE-2025-29807CVE-2025-29807
CVSS 8.8
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
CVE-2025-29794CVE-2025-29794
CVSS 8.8
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-29778CVE-2025-29778
CVSS 8.0
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegEx…
CVE-2025-29635D-Link DIR-823X Command Injection Vulnerability
KEVCVSS 7.2D-Link
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST…
CVE-2025-29534CVE-2025-29534
CVSS 8.8
An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbit…
CVE-2025-29509CVE-2025-29509
CVSS 8.8
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external websit…
CVE-2025-29471CVE-2025-29471
CVSS 8.3
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.
CVE-2025-2945CVE-2025-2945
CVSS 8.8
Remote Code Execution security vulnerability in pgAdmin 4 (Query Tool and Cloud Deployment modules). The vulnerability is associated with the 2 POST endpoint…
CVE-2025-29394CVE-2025-29394
CVSS 8.1
An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type.
CVE-2025-29390CVE-2025-29390
CVSS 8.8
jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.
CVE-2025-2938CVE-2025-2938
CVSS 8.8
An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowe…
CVE-2025-2933CVE-2025-2933
CVSS 8.8
The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a miss…
CVE-2025-2932CVE-2025-2932
CVSS 8.8
The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' function in al…
CVE-2025-29314CVE-2025-29314
CVSS 8.1
Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to access sensitive in…
CVE-2025-29281CVE-2025-29281
CVSS 8.8
In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute …
CVE-2025-29230CVE-2025-29230
CVSS 8.6
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via th…
CVE-2025-29093CVE-2025-29093
CVSS 8.2
File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images compon…
CVE-2025-29017CVE-2025-29017
CVSS 8.8
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parame…
CVE-2025-29004CVE-2025-29004
CVSS 8.8
Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Hol…
CVE-2025-29002CVE-2025-29002
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Simen snssimen allows PHP Loc…
CVE-2025-28998CVE-2025-28998
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in serpednet SERPed.net serped-net allows…
CVE-2025-28993CVE-2025-28993
CVSS 8.6
Improper Control of Generation of Code ('Code Injection') vulnerability in Jose Mortellaro Content No Cache content-no-cache allows Code Injection.This issue a…
CVE-2025-28992CVE-2025-28992
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Anton snsanton allows PHP…
CVE-2025-28991CVE-2025-28991
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Evon snsevon allows PHP Local…
CVE-2025-28990CVE-2025-28990
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Vicky snsvicky allows PHP…
CVE-2025-28986CVE-2025-28986
CVSS 8.2
Cross-Site Request Forgery (CSRF) vulnerability in Webaholicson Epicwin Plugin epicwin-subscribers allows SQL Injection.This issue affects Epicwin Plugin: from…
CVE-2025-2898CVE-2025-2898
CVSS 8.8
IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.