92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,651–6,700 of 8,161 in High · page 134 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-26915 | CVE-2025-26915 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Injection.This i… |
| CVE-2025-26902 | CVE-2025-26902 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2.6.1. |
| CVE-2025-26901 | CVE-2025-26901 CVSS 8.8 | Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: fr… |
| CVE-2025-26871 | CVE-2025-26871 CVSS 8.8 | Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Secu… |
| CVE-2025-26866 | CVE-2025-26866 CVSS 8.8apache | A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-… |
| CVE-2025-26788 | CVE-2025-26788 CVSS 8.4 | StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction. |
| CVE-2025-26773 | CVE-2025-26773 CVSS 8.8 | Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects … |
| CVE-2025-26752 | CVE-2025-26752 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-i… |
| CVE-2025-26748 | CVE-2025-26748 CVSS 8.1 | Cross-Site Request Forgery (CSRF) vulnerability in looswebstudio Arkhe arkhe allows PHP Local File Inclusion.This issue affects Arkhe: from n/a through <= 3.12… |
| CVE-2025-26741 | CVE-2025-26741 CVSS 8.8 | Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Em… |
| CVE-2025-26733 | CVE-2025-26733 CVSS 8.2 | Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. |
| CVE-2025-26692 | CVE-2025-26692 CVSS 8.1 | Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary… |
| CVE-2025-26678 | CVE-2025-26678 CVSS 8.4 | Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. |
| CVE-2025-26671 | CVE-2025-26671 CVSS 8.1 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
| CVE-2025-26670 | CVE-2025-26670 CVSS 8.1 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. |
| CVE-2025-26669 | CVE-2025-26669 CVSS 8.8 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-26663 | CVE-2025-26663 CVSS 8.1 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. |
| CVE-2025-26661 | CVE-2025-26661 CVSS 8.8 | Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in esca… |
| CVE-2025-26647 | CVE-2025-26647 CVSS 8.8 | Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-26646 | CVE-2025-26646 CVSS 8.0 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a networ… |
| CVE-2025-26645 | CVE-2025-26645 CVSS 8.8 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2025-26633 | Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability KEVCVSS 7.0Microsoft | Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature … |
| CVE-2025-2662 | CVE-2025-2662 CVSS 8.8 | A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affected is an unknown function of the file st… |
| CVE-2025-26614 | CVE-2025-26614 CVSS 8.8 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA appli… |
| CVE-2025-26605 | CVE-2025-26605 CVSS 8.8 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA appli… |
| CVE-2025-26604 | CVE-2025-26604 CVSS 8.3 | Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the… |
| CVE-2025-26592 | CVE-2025-26592 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Lab lab allows PHP Local F… |
| CVE-2025-26534 | CVE-2025-26534 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in helloprint Helloprint helloprint allows Path Traversal.This iss… |
| CVE-2025-26525 | CVE-2025-26525 CVSS 8.6 | Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live in… |
| CVE-2025-26521 | CVE-2025-26521 CVSS 8.1 | When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the calle… |
| CVE-2025-26511 | CVE-2025-26511 CVSS 8.8 | Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through 4.1.8-1.0… |
| CVE-2025-26487 | CVE-2025-26487 CVSS 8.6nokia | Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources usin… |
| CVE-2025-26483 | CVE-2025-26483 CVSS 6.1dell | Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerabi… |
| CVE-2025-26477 | CVE-2025-26477 CVSS 8.8 | Dell ECS version 3.8.1.4 and prior contain an Improper Input Validation vulnerability. A low privileged attacker with remote access could potentially exploit t… |
| CVE-2025-26467 | CVE-2025-26467 CVSS 8.8 | Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser w… |
| CVE-2025-26438 | CVE-2025-26438 CVSS 8.8 | In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. Th… |
| CVE-2025-26411 | CVE-2025-26411 CVSS 8.8 | An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device… |
| CVE-2025-26378 | CVE-2025-26378 CVSS 8.8 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged… |
| CVE-2025-26377 | CVE-2025-26377 CVSS 8.1 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged… |
| CVE-2025-26375 | CVE-2025-26375 CVSS 8.8 | A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged… |
| CVE-2025-26372 | CVE-2025-26372 CVSS 8.1 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-priv… |
| CVE-2025-26371 | CVE-2025-26371 CVSS 8.8 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-priv… |
| CVE-2025-26369 | CVE-2025-26369 CVSS 8.8 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-priv… |
| CVE-2025-26368 | CVE-2025-26368 CVSS 8.1 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-priv… |
| CVE-2025-2636 | CVE-2025-2636 CVSS 8.1 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 … |
| CVE-2025-26350 | CVE-2025-26350 CVSS 8.8 | A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.11.0 allows an authe… |
| CVE-2025-26343 | CVE-2025-26343 CVSS 8.1 | A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote at… |
| CVE-2025-26340 | CVE-2025-26340 CVSS 8.8 | A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote atta… |
| CVE-2025-26326 | CVE-2025-26326 CVSS 8.8 | A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker t… |
| CVE-2025-26305 | CVE-2025-26305 CVSS 8.2 | A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service vi… |