92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,601–6,650 of 8,161 in High · page 133 of 164

IDTitleSummary
CVE-2025-27396CVE-2025-27396
CVSS 8.8
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit the elevation of pri…
CVE-2025-27363FreeType Out-of-Bounds Write Vulnerability
KEVCVSS 8.1FreeType
FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that ma…
CVE-2025-27362CVE-2025-27362
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Petito bw-petito allows PHP L…
CVE-2025-2732CVE-2025-2732
CVSS 8.0
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected…
CVE-2025-27312CVE-2025-27312
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jenst WP Sitemap wp-sitemap allows SQL Injection.This iss…
CVE-2025-2731CVE-2025-2731
CVSS 8.0
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affec…
CVE-2025-2730CVE-2025-2730
CVSS 8.0
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Aff…
CVE-2025-27298CVE-2025-27298
CVSS 8.3
Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts wp-video-posts allows OS Command Injection.This issue affects WP Video Posts: from…
CVE-2025-2729CVE-2025-2729
CVSS 8.0
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue a…
CVE-2025-27281CVE-2025-27281
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cookforweb All In Menu all-in-menu allows Blind SQL Injec…
CVE-2025-2728CVE-2025-2728
CVSS 8.0
A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the …
CVE-2025-27276CVE-2025-27276
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Photo Gallery ( Responsive ) photo-gallery-pearlbells allows Privilege Escalation.This issue affects…
CVE-2025-2727CVE-2025-2727
CVSS 8.0
A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetw…
CVE-2025-27263CVE-2025-27263
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creativeitem Doctor Appointment Booking doctor-appointmen…
CVE-2025-2726CVE-2025-2726
CVSS 8.0
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014.…
CVE-2025-27256CVE-2025-27256
CVSS 8.3
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH serve…
CVE-2025-27255CVE-2025-27255
CVSS 8.0
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcod…
CVE-2025-27254CVE-2025-27254
CVSS 8.0
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass.  The software's startup authentication can be disabled b…
CVE-2025-2725CVE-2025-2725
CVSS 8.0
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this…
CVE-2025-27222CVE-2025-27222
CVSS 8.6
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitiz…
CVE-2025-27216CVE-2025-27216
CVSS 8.8
Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate privileges.
CVE-2025-27215CVE-2025-27215
CVSS 8.1
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to …
CVE-2025-27148CVE-2025-27148
CVSS 8.8
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory ca…
CVE-2025-27147CVE-2025-27147
CVSS 8.2
The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX hos…
CVE-2025-27142CVE-2025-27142
CVSS 8.8
LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over their local network without needing an int…
CVE-2025-27134CVE-2025-27134
CVSS 8.8
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a p…
CVE-2025-27133CVE-2025-27133
CVSS 8.8
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the `adici…
CVE-2025-27130CVE-2025-27130
CVSS 8.8
Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may…
CVE-2025-27106CVE-2025-27106
CVSS 8.8
binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Exe…
CVE-2025-27088CVE-2025-27088
CVSS 8.2
oxyno-zeta/s3-proxy is an aws s3 proxy written in go. In affected versions a Reflected Cross-site Scripting (XSS) vulnerability enables attackers to create mal…
CVE-2025-27086CVE-2025-27086
CVSS 8.1
A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.
CVE-2025-27060CVE-2025-27060
CVSS 8.8qualcomm
Memory corruption while performing SCM call with malformed inputs.
CVE-2025-27059CVE-2025-27059
CVSS 8.8qualcomm
Memory corruption while performing SCM call.
CVE-2025-27038Qualcomm Multiple Chipsets Use-After-Free Vulnerability
KEVCVSS 7.5Qualcomm
Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU dr…
CVE-2025-27025CVE-2025-27025
CVSS 8.8
The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is granted using a Basic Authentication me…
CVE-2025-27012CVE-2025-27012
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo a1post-bg-shipping-for-woocommerce allows Privilege Escalation.This issue …
CVE-2025-27010CVE-2025-27010
CVSS 8.1
Path Traversal: '.../...//' vulnerability in bslthemes Tastyc tastyc allows PHP Local File Inclusion.This issue affects Tastyc: from n/a through < 2.5.2.
CVE-2025-26999CVE-2025-26999
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.This issue a…
CVE-2025-26986CVE-2025-26986
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corporate Busin…
CVE-2025-26985CVE-2025-26985
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support maje…
CVE-2025-26978CVE-2025-26978
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster:…
CVE-2025-26976CVE-2025-26976
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino PrivateContent private-content.This issue aff…
CVE-2025-26969CVE-2025-26969
CVSS 8.3
Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.
CVE-2025-26967CVE-2025-26967
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects …
CVE-2025-26964CVE-2025-26964
CVSS 8.8
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-solution al…
CVE-2025-26963CVE-2025-26963
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in ClickWhale ClickWhale clickwhale allows Cross Site Request Forgery.This issue affects ClickWhale: from n/a t…
CVE-2025-26961CVE-2025-26961
CVSS 8.6
Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…
CVE-2025-26959CVE-2025-26959
CVSS 8.8
Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue affects Administrator Z: from n/a throu…
CVE-2025-26935CVE-2025-26935
CVSS 8.8
Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a…
CVE-2025-26921CVE-2025-26921
CVSS 8.8
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.