92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,651–6,700 of 8,161 in High · page 134 of 164

IDTitleSummary
CVE-2025-26915CVE-2025-26915
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Injection.This i…
CVE-2025-26902CVE-2025-26902
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2.6.1.
CVE-2025-26901CVE-2025-26901
CVSS 8.8
Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: fr…
CVE-2025-26871CVE-2025-26871
CVSS 8.8
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Secu…
CVE-2025-26866CVE-2025-26866
CVSS 8.8apache
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-…
CVE-2025-26788CVE-2025-26788
CVSS 8.4
StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
CVE-2025-26773CVE-2025-26773
CVSS 8.8
Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …
CVE-2025-26752CVE-2025-26752
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-i…
CVE-2025-26748CVE-2025-26748
CVSS 8.1
Cross-Site Request Forgery (CSRF) vulnerability in looswebstudio Arkhe arkhe allows PHP Local File Inclusion.This issue affects Arkhe: from n/a through <= 3.12…
CVE-2025-26741CVE-2025-26741
CVSS 8.8
Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Em…
CVE-2025-26733CVE-2025-26733
CVSS 8.2
Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.
CVE-2025-26692CVE-2025-26692
CVSS 8.1
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary…
CVE-2025-26678CVE-2025-26678
CVSS 8.4
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-26671CVE-2025-26671
CVSS 8.1
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CVE-2025-26670CVE-2025-26670
CVSS 8.1
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
CVE-2025-26669CVE-2025-26669
CVSS 8.8
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-26663CVE-2025-26663
CVSS 8.1
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
CVE-2025-26661CVE-2025-26661
CVSS 8.8
Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in esca…
CVE-2025-26647CVE-2025-26647
CVSS 8.8
Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2025-26646CVE-2025-26646
CVSS 8.0
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a networ…
CVE-2025-26645CVE-2025-26645
CVSS 8.8
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-26633Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
KEVCVSS 7.0Microsoft
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature …
CVE-2025-2662CVE-2025-2662
CVSS 8.8
A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affected is an unknown function of the file st…
CVE-2025-26614CVE-2025-26614
CVSS 8.8
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA appli…
CVE-2025-26605CVE-2025-26605
CVSS 8.8
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA appli…
CVE-2025-26604CVE-2025-26604
CVSS 8.3
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the…
CVE-2025-26592CVE-2025-26592
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Lab lab allows PHP Local F…
CVE-2025-26534CVE-2025-26534
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in helloprint Helloprint helloprint allows Path Traversal.This iss…
CVE-2025-26525CVE-2025-26525
CVSS 8.6
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live in…
CVE-2025-26521CVE-2025-26521
CVSS 8.1
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the calle…
CVE-2025-26511CVE-2025-26511
CVSS 8.8
Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0…
CVE-2025-26487CVE-2025-26487
CVSS 8.6nokia
Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources usin…
CVE-2025-26483CVE-2025-26483
CVSS 6.1dell
Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerabi…
CVE-2025-26477CVE-2025-26477
CVSS 8.8
Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit t…
CVE-2025-26467CVE-2025-26467
CVSS 8.8
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser w…
CVE-2025-26438CVE-2025-26438
CVSS 8.8
In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. Th…
CVE-2025-26411CVE-2025-26411
CVSS 8.8
An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device…
CVE-2025-26378CVE-2025-26378
CVSS 8.8
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged…
CVE-2025-26377CVE-2025-26377
CVSS 8.1
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged…
CVE-2025-26375CVE-2025-26375
CVSS 8.8
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged…
CVE-2025-26372CVE-2025-26372
CVSS 8.1
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-priv…
CVE-2025-26371CVE-2025-26371
CVSS 8.8
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-priv…
CVE-2025-26369CVE-2025-26369
CVSS 8.8
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-priv…
CVE-2025-26368CVE-2025-26368
CVSS 8.1
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-priv…
CVE-2025-2636CVE-2025-2636
CVSS 8.1
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 …
CVE-2025-26350CVE-2025-26350
CVSS 8.8
A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.11.0 allows an authe…
CVE-2025-26343CVE-2025-26343
CVSS 8.1
A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote at…
CVE-2025-26340CVE-2025-26340
CVSS 8.8
A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote atta…
CVE-2025-26326CVE-2025-26326
CVSS 8.8
A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker t…
CVE-2025-26305CVE-2025-26305
CVSS 8.2
A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service vi…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.