92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,551–6,600 of 8,161 in High · page 132 of 164

IDTitleSummary
CVE-2025-27912CVE-2025-27912
CVSS 8.8
An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect authenticatio…
CVE-2025-27910CVE-2025-27910
CVSS 8.0
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execu…
CVE-2025-27889CVE-2025-27889
CVSS 8.8
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary li…
CVE-2025-2787CVE-2025-2787
CVSS 8.8
KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the wo…
CVE-2025-2783Google Chromium Mojo Sandbox Escape Vulnerability
KEVCVSS 8.3Google
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspe…
CVE-2025-27818CVE-2025-27818
CVSS 8.8
A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, …
CVE-2025-27813CVE-2025-27813
CVSS 8.1
MSI Center before 2.0.52.0 has Missing PE Signature Validation.
CVE-2025-27812CVE-2025-27812
CVSS 8.1
MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.
CVE-2025-2780CVE-2025-2780
CVSS 8.8
The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveFeatu…
CVE-2025-27773CVE-2025-27773
CVSS 8.6
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion a…
CVE-2025-2775SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
KEVCVSS 7.5SysAid
SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administra…
CVE-2025-27740CVE-2025-27740
CVSS 8.8
Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.
CVE-2025-27737CVE-2025-27737
CVSS 8.6
Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-27718CVE-2025-27718
CVSS 8.8
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function…
CVE-2025-27709CVE-2025-27709
CVSS 8.3
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.
CVE-2025-27700CVE-2025-27700
CVSS 8.4
There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional execution …
CVE-2025-27696CVE-2025-27696
CVSS 8.8
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissio…
CVE-2025-27683CVE-2025-27683
CVSS 8.8
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type …
CVE-2025-27664CVE-2025-27664
CVSS 8.8
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient CSRF Protection OVE-20230524-0008.
CVE-2025-2766CVE-2025-2766
CVSS 8.8
70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affect…
CVE-2025-2765CVE-2025-2765
CVSS 8.8
CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypa…
CVE-2025-2764CVE-2025-2764
CVSS 8.0
CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent atta…
CVE-2025-27639CVE-2025-27639
CVSS 8.8
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015.
CVE-2025-27617CVE-2025-27617
CVSS 8.8
Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL i…
CVE-2025-27616CVE-2025-27616
CVSS 8.5
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webho…
CVE-2025-27615CVE-2025-27615
CVSS 8.2
umatiGateway is software for connecting OPC Unified Architecture servers with an MQTT broker utilizing JSON messages. The user interface may possibly be public…
CVE-2025-27614CVE-2025-27614
CVSS 8.6
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who ha…
CVE-2025-27607CVE-2025-27607
CVSS 8.8
Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing…
CVE-2025-2757CVE-2025-2757
CVSS 8.8
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOT…
CVE-2025-2756CVE-2025-2756
CVSS 8.8
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectS…
CVE-2025-2755CVE-2025-2755
CVSS 8.8
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter…
CVE-2025-2754CVE-2025-2754
CVSS 8.8
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::A…
CVE-2025-2753CVE-2025-2753
CVSS 8.8
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of…
CVE-2025-27523CVE-2025-27523
CVSS 8.7
XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manage…
CVE-2025-2752CVE-2025-2752
CVSS 8.8
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the lib…
CVE-2025-27516CVE-2025-27516
CVSS 8.8
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacke…
CVE-2025-2751CVE-2025-2751
CVSS 8.8
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImpo…
CVE-2025-27501CVE-2025-27501
CVSS 8.6
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form o…
CVE-2025-2750CVE-2025-2750
CVSS 8.8
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternRe…
CVE-2025-2749Kentico Xperience Path Traversal Vulnerability
KEVCVSS 7.2Kentico
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relativ…
CVE-2025-27487CVE-2025-27487
CVSS 8.0
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
CVE-2025-27482CVE-2025-27482
CVSS 8.1
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27481CVE-2025-27481
CVSS 8.8
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27480CVE-2025-27480
CVSS 8.1
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27477CVE-2025-27477
CVSS 8.8
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27440CVE-2025-27440
CVSS 8.8
Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
CVE-2025-27439CVE-2025-27439
CVSS 8.8
Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.
CVE-2025-27434CVE-2025-27434
CVSS 8.8
Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can …
CVE-2025-2743CVE-2025-2743
CVSS 8.1
A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the fi…
CVE-2025-2742CVE-2025-2742
CVSS 8.1
A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/materi…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.