92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,501–6,550 of 8,161 in High · page 131 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-28969 | CVE-2025-28969 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widget gallery-widget allows SQL Injection.… |
| CVE-2025-28967 | CVE-2025-28967 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LITE contac… |
| CVE-2025-28965 | CVE-2025-28965 CVSS 8.6 | Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not Properly Constrained by ACLs.This issue… |
| CVE-2025-28953 | CVE-2025-28953 CVSS 8.5axiomthemes | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart SEO smartSEO allows SQL Injection.This … |
| CVE-2025-28949 | CVE-2025-28949 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allo… |
| CVE-2025-28947 | CVE-2025-28947 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme MBStore - Digital WooCommerce… |
| CVE-2025-28946 | CVE-2025-28946 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme PrintXtore bw-printxtore allo… |
| CVE-2025-28945 | CVE-2025-28945 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Valen - Sport, Fashion WooCom… |
| CVE-2025-28944 | CVE-2025-28944 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Avaz snsavaz allows PHP Local… |
| CVE-2025-28939 | CVE-2025-28939 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in EuroCizia WP Google Calendar Manager wp-gcalendar allows … |
| CVE-2025-2891 | CVE-2025-2891 CVSS 8.8 | The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.ph… |
| CVE-2025-28888 | CVE-2025-28888 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme GiftXtore bw-giftxtore allows… |
| CVE-2025-28876 | CVE-2025-28876 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Skrill_Team Skrill Official official-skrill-woocommerce allows Cross Site Request Forgery.This issue affects… |
| CVE-2025-28873 | CVE-2025-28873 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Scott Taylor Shuffle shuffle allows Blind SQL Injection.T… |
| CVE-2025-28868 | CVE-2025-28868 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe ziplist-recipe-plugin allows Cross Site Request Forgery.This issue affects ZipList Re… |
| CVE-2025-28867 | CVE-2025-28867 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in stesvis Frontpage category filter frontpage-category-filter allows Cross Site Request Forgery.This issue aff… |
| CVE-2025-28866 | CVE-2025-28866 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger login-logger allows Cross Site Request Forgery.This issue affects Login Logger: from … |
| CVE-2025-28864 | CVE-2025-28864 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in planetstudio Builder for Contact Form 7 by Webconstruct cf7-builder allows Cross Site Request Forgery.This i… |
| CVE-2025-28863 | CVE-2025-28863 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image delete-original-image allows Cross Site Request Forgery.This issue affe… |
| CVE-2025-28862 | CVE-2025-28862 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request… |
| CVE-2025-28859 | CVE-2025-28859 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice maintenance-notice allows Cross Site Request Forgery.This issue affects Maint… |
| CVE-2025-28856 | CVE-2025-28856 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in dangrossman W3Counter Free Real-Time Web Stats blog-stats-by-w3counter allows Cross Site Request Forgery.Thi… |
| CVE-2025-2876 | CVE-2025-2876 CVSS 8.2 | The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability … |
| CVE-2025-2858 | CVE-2025-2858 CVSS 8.8 | Privilege escalation vulnerability in the saTECH BCU firmware version 2.1.3. An attacker with access to the CLI of the device could make use of the nice comman… |
| CVE-2025-2854 | CVE-2025-2854 CVSS 8.8 | A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of … |
| CVE-2025-2851 | CVE-2025-2851 CVSS 8.0 | A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate… |
| CVE-2025-2847 | CVE-2025-2847 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing of the file… |
| CVE-2025-2843 | CVE-2025-2843 CVSS 8.8 | A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resou… |
| CVE-2025-28409 | CVE-2025-28409 CVSS 8.8 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether… |
| CVE-2025-28407 | CVE-2025-28407 CVSS 8.8 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether… |
| CVE-2025-2837 | CVE-2025-2837 CVSS 8.8 | Silicon Labs Gecko OS HTTP Request Handling Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attacke… |
| CVE-2025-28357 | CVE-2025-28357 CVSS 8.8 | A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted HTTP request. |
| CVE-2025-28244 | CVE-2025-28244 CVSS 8.8 | Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localSt… |
| CVE-2025-28243 | CVE-2025-28243 CVSS 8.0 | An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component. |
| CVE-2025-28237 | CVE-2025-28237 CVSS 8.8 | An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload. |
| CVE-2025-28203 | CVE-2025-28203 CVSS 8.8 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability. |
| CVE-2025-28202 | CVE-2025-28202 CVSS 8.8 | Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication. |
| CVE-2025-2817 | CVE-2025-2817 CVSS 8.8mozilla | Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By… |
| CVE-2025-28169 | CVE-2025-28169 CVSS 8.1 | BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer's cloud server unencrypted, … |
| CVE-2025-2816 | CVE-2025-2816 CVSS 8.1 | The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability ch… |
| CVE-2025-2815 | CVE-2025-2815 CVSS 8.8 | The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability c… |
| CVE-2025-2807 | CVE-2025-2807 CVSS 8.8 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check… |
| CVE-2025-28062 | CVE-2025-28062 CVSS 8.1 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized a… |
| CVE-2025-28041 | CVE-2025-28041 CVSS 8.6 | Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication. |
| CVE-2025-28030 | CVE-2025-28030 CVSS 8.8 | TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function. |
| CVE-2025-27998 | CVE-2025-27998 CVSS 8.4 | An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL. |
| CVE-2025-27997 | CVE-2025-27997 CVSS 8.4 | An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData … |
| CVE-2025-27932 | CVE-2025-27932 CVSS 8.1 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process of the USB storage file-sharing functi… |
| CVE-2025-27920 | Srimax Output Messenger Directory Traversal Vulnerability KEVCVSS 8.8Srimax | Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentia… |
| CVE-2025-27919 | CVE-2025-27919 CVSS 8.2 | An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and … |