92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,701–6,750 of 8,161 in High · page 135 of 164

IDTitleSummary
CVE-2025-26304CVE-2025-26304
CVSS 8.2
A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.
CVE-2025-26264CVE-2025-26264
CVSS 8.8
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings fea…
CVE-2025-26260CVE-2025-26260
CVSS 8.8
Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. Th…
CVE-2025-2622CVE-2025-2622
CVSS 8.8
A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/ch…
CVE-2025-26211CVE-2025-26211
CVSS 8.8
Gibbon before 29.0.00 allows CSRF.
CVE-2025-26210CVE-2025-26210
CVSS 8.8
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parti…
CVE-2025-26186CVE-2025-26186
CVSS 8.1
SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php
CVE-2025-26169CVE-2025-26169
CVSS 8.1
IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be contr…
CVE-2025-26168CVE-2025-26168
CVSS 8.1
IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be…
CVE-2025-26156CVE-2025-26156
CVSS 8.8
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbit…
CVE-2025-2608CVE-2025-2608
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown part of the file /admin/view-user-queri…
CVE-2025-2605CVE-2025-2605
CVSS 8.8
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This is…
CVE-2025-2602CVE-2025-2602
CVSS 8.8
A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unkno…
CVE-2025-26013CVE-2025-26013
CVSS 8.2
An issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.
CVE-2025-2601CVE-2025-2601
CVSS 8.8
A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part …
CVE-2025-25967CVE-2025-25967
CVSS 8.8
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthori…
CVE-2025-25950CVE-2025-25950
CVSS 8.1
Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 al…
CVE-2025-2594CVE-2025-2594
CVSS 8.1
The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowi…
CVE-2025-25928CVE-2025-25928
CVSS 8.0
A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via …
CVE-2025-2592CVE-2025-2592
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::Inter…
CVE-2025-25907CVE-2025-25907
CVSS 8.8
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arb…
CVE-2025-25895CVE-2025-25895
CVSS 8.0
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulnerability allows attackers to execute arb…
CVE-2025-25894CVE-2025-25894
CVSS 8.0
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters. This vulnerability allows attackers to…
CVE-2025-25893CVE-2025-25893
CVSS 8.0
An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This v…
CVE-2025-25871CVE-2025-25871
CVSS 8.0
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
CVE-2025-2585CVE-2025-2585
CVSS 8.8
EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL comma…
CVE-2025-25777CVE-2025-25777
CVSS 8.0
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in…
CVE-2025-25769CVE-2025-25769
CVSS 8.0
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.
CVE-2025-25745CVE-2025-25745
CVSS 8.8
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetQuickVPNSettings module.
CVE-2025-25723CVE-2025-25723
CVSS 8.4
Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.
CVE-2025-25711CVE-2025-25711
CVSS 8.8
An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/admin/updateUser] API…
CVE-2025-25679CVE-2025-25679
CVSS 8.0
Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet function.
CVE-2025-25635CVE-2025-25635
CVSS 8.0
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 p…
CVE-2025-2563CVE-2025-2563
CVSS 8.1
The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leadin…
CVE-2025-25614CVE-2025-25614
CVSS 8.8
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.
CVE-2025-25610CVE-2025-25610
CVSS 8.0
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw pa…
CVE-2025-25609CVE-2025-25609
CVSS 8.0
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 …
CVE-2025-25598CVE-2025-25598
CVSS 8.8
Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a c…
CVE-2025-25589CVE-2025-25589
CVSS 8.1
An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitr…
CVE-2025-2558CVE-2025-2558
CVSS 8.6
The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenti…
CVE-2025-25515CVE-2025-25515
CVSS 8.8
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
CVE-2025-25497CVE-2025-25497
CVSS 8.1
An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field d…
CVE-2025-2549CVE-2025-2549
CVSS 8.8
A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown functionali…
CVE-2025-2548CVE-2025-2548
CVSS 8.8
A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file /goform/f…
CVE-2025-25477CVE-2025-25477
CVSS 8.1
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the vic…
CVE-2025-25428CVE-2025-25428
CVSS 8.0
TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
CVE-2025-25364CVE-2025-25364
CVSS 8.4
A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary command…
CVE-2025-25282CVE-2025-25282
CVSS 8.1
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Dire…
CVE-2025-25274CVE-2025-25274
CVSS 8.8
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated us…
CVE-2025-25271CVE-2025-25271
CVSS 8.8
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.