92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,551–6,600 of 8,161 in High · page 132 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-27912 | CVE-2025-27912 CVSS 8.8 | An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect authenticatio… |
| CVE-2025-27910 | CVE-2025-27910 CVSS 8.0 | tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execu… |
| CVE-2025-27889 | CVE-2025-27889 CVSS 8.8 | Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary li… |
| CVE-2025-2787 | CVE-2025-2787 CVSS 8.8 | KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the wo… |
| CVE-2025-2783 | Google Chromium Mojo Sandbox Escape Vulnerability KEVCVSS 8.3Google | Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspe… |
| CVE-2025-27818 | CVE-2025-27818 CVSS 8.8 | A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, … |
| CVE-2025-27813 | CVE-2025-27813 CVSS 8.1 | MSI Center before 2.0.52.0 has Missing PE Signature Validation. |
| CVE-2025-27812 | CVE-2025-27812 CVSS 8.1 | MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation. |
| CVE-2025-2780 | CVE-2025-2780 CVSS 8.8 | The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveFeatu… |
| CVE-2025-27773 | CVE-2025-27773 CVSS 8.6 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion a… |
| CVE-2025-2775 | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability KEVCVSS 7.5SysAid | SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administra… |
| CVE-2025-27740 | CVE-2025-27740 CVSS 8.8 | Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-27737 | CVE-2025-27737 CVSS 8.6 | Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2025-27718 | CVE-2025-27718 CVSS 8.8 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function… |
| CVE-2025-27709 | CVE-2025-27709 CVSS 8.3 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports. |
| CVE-2025-27700 | CVE-2025-27700 CVSS 8.4 | There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional execution … |
| CVE-2025-27696 | CVE-2025-27696 CVSS 8.8 | Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissio… |
| CVE-2025-27683 | CVE-2025-27683 CVSS 8.8 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type … |
| CVE-2025-27664 | CVE-2025-27664 CVSS 8.8 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient CSRF Protection OVE-20230524-0008. |
| CVE-2025-2766 | CVE-2025-2766 CVSS 8.8 | 70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affect… |
| CVE-2025-2765 | CVE-2025-2765 CVSS 8.8 | CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypa… |
| CVE-2025-2764 | CVE-2025-2764 CVSS 8.0 | CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent atta… |
| CVE-2025-27639 | CVE-2025-27639 CVSS 8.8 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015. |
| CVE-2025-27617 | CVE-2025-27617 CVSS 8.8 | Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL i… |
| CVE-2025-27616 | CVE-2025-27616 CVSS 8.5 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webho… |
| CVE-2025-27615 | CVE-2025-27615 CVSS 8.2 | umatiGateway is software for connecting OPC Unified Architecture servers with an MQTT broker utilizing JSON messages. The user interface may possibly be public… |
| CVE-2025-27614 | CVE-2025-27614 CVSS 8.6 | Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who ha… |
| CVE-2025-27607 | CVE-2025-27607 CVSS 8.8 | Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing… |
| CVE-2025-2757 | CVE-2025-2757 CVSS 8.8 | A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOT… |
| CVE-2025-2756 | CVE-2025-2756 CVSS 8.8 | A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectS… |
| CVE-2025-2755 | CVE-2025-2755 CVSS 8.8 | A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter… |
| CVE-2025-2754 | CVE-2025-2754 CVSS 8.8 | A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::A… |
| CVE-2025-2753 | CVE-2025-2753 CVSS 8.8 | A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of… |
| CVE-2025-27523 | CVE-2025-27523 CVSS 8.7 | XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manage… |
| CVE-2025-2752 | CVE-2025-2752 CVSS 8.8 | A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the lib… |
| CVE-2025-27516 | CVE-2025-27516 CVSS 8.8 | Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacke… |
| CVE-2025-2751 | CVE-2025-2751 CVSS 8.8 | A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImpo… |
| CVE-2025-27501 | CVE-2025-27501 CVSS 8.6 | OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form o… |
| CVE-2025-2750 | CVE-2025-2750 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternRe… |
| CVE-2025-2749 | Kentico Xperience Path Traversal Vulnerability KEVCVSS 7.2Kentico | Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relativ… |
| CVE-2025-27487 | CVE-2025-27487 CVSS 8.0 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. |
| CVE-2025-27482 | CVE-2025-27482 CVSS 8.1 | Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-27481 | CVE-2025-27481 CVSS 8.8 | Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-27480 | CVE-2025-27480 CVSS 8.1 | Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-27477 | CVE-2025-27477 CVSS 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| CVE-2025-27440 | CVE-2025-27440 CVSS 8.8 | Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2025-27439 | CVE-2025-27439 CVSS 8.8 | Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2025-27434 | CVE-2025-27434 CVSS 8.8 | Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can … |
| CVE-2025-2743 | CVE-2025-2743 CVSS 8.1 | A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the fi… |
| CVE-2025-2742 | CVE-2025-2742 CVSS 8.1 | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/materi… |