92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,751–6,800 of 8,161 in High · page 136 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-25269 | CVE-2025-25269 CVSS 8.4 | An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation. |
| CVE-2025-25268 | CVE-2025-25268 CVSS 8.8 | An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing… |
| CVE-2025-2526 | CVE-2025-2526 CVSS 8.8 | The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.2. This is due to the plu… |
| CVE-2025-2525 | CVE-2025-2525 CVSS 8.8 | The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_Authentication_Controller::edit_profile… |
| CVE-2025-25246 | CVE-2025-25246 CVSS 8.1 | NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users. |
| CVE-2025-25243 | CVE-2025-25243 CVSS 8.6 | SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arb… |
| CVE-2025-25235 | CVE-2025-25235 CVSS 8.6 | Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows ro… |
| CVE-2025-25220 | CVE-2025-25220 CVSS 8.8 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vul… |
| CVE-2025-25215 | CVE-2025-25215 CVSS 8.8 | An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36.… |
| CVE-2025-25210 | CVE-2025-25210 CVSS 8.2 | Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of… |
| CVE-2025-2521 | CVE-2025-2521 CVSS 8.6 | The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Access (CDA). An attacker could potentially… |
| CVE-2025-25206 | CVE-2025-25206 CVSS 8.8 | eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user t… |
| CVE-2025-25205 | CVE-2025-25205 CVSS 8.2 | Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic… |
| CVE-2025-25203 | CVE-2025-25203 CVSS 8.1 | CtrlPanel is open-source billing software for hosting providers. Prior to version 1.0, a Cross-Site Scripting (XSS) vulnerability exists in the `TicketsControl… |
| CVE-2025-25198 | CVE-2025-25198 CVSS 8.8 | mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability in mailcow's password reset functionali… |
| CVE-2025-25181 | Advantive VeraCore SQL Injection Vulnerability KEVCVSS 7.5Advantive | Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1… |
| CVE-2025-25172 | CVE-2025-25172 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidMov vidmov allows PHP Lo… |
| CVE-2025-25171 | CVE-2025-25171 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authentication Abuse.This issue affects WP Sm… |
| CVE-2025-25151 | CVE-2025-25151 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing ulisting allows SQL Injection.This issu… |
| CVE-2025-25122 | CVE-2025-25122 CVSS 8.1 | Path Traversal: '.../...//' vulnerability in hashshop WizShop wizshop allows Path Traversal.This issue affects WizShop: from n/a through <= 3.0.2. |
| CVE-2025-25109 | CVE-2025-25109 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky WP Vehicle Manager js-vehicle-… |
| CVE-2025-25068 | CVE-2025-25068 CVSS 8.8 | Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated … |
| CVE-2025-25066 | CVE-2025-25066 CVSS 8.4 | nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c. |
| CVE-2025-25064 | CVE-2025-25064 CVSS 8.8 | SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4 due to insufficient … |
| CVE-2025-25060 | CVE-2025-25060 CVSS 8.2 | Missing authentication for critical function vulnerability exists in AssetView and AssetView CLOUD. If exploited, the files on the server where the product is … |
| CVE-2025-25053 | CVE-2025-25053 CVSS 8.8 | OS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be … |
| CVE-2025-25050 | CVE-2025-25050 CVSS 8.8 | An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 … |
| CVE-2025-25039 | CVE-2025-25039 CVSS 8.8 | A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrar… |
| CVE-2025-25022 | CVE-2025-25022 CVSS 8.8 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the envir… |
| CVE-2025-25000 | CVE-2025-25000 CVSS 8.8 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-24999 | CVE-2025-24999 CVSS 8.8 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-24993 | Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code lo… |
| CVE-2025-24990 | Microsoft Windows Untrusted Pointer Dereference Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully… |
| CVE-2025-24985 | Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code loc… |
| CVE-2025-24983 | Microsoft Windows Win32k Use-After-Free Vulnerability KEVCVSS 7.0Microsoft | Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24975 | CVE-2025-24975 CVSS 8.8 | Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnerable if ExtConnPoolSize is not set equal… |
| CVE-2025-24968 | CVE-2025-24968 CVSS 8.8 | reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, suc… |
| CVE-2025-24964 | CVE-2025-24964 CVSS 8.8 | Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest… |
| CVE-2025-24962 | CVE-2025-24962 CVSS 8.8 | reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue … |
| CVE-2025-24960 | CVE-2025-24960 CVSS 8.7 | Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This can lead t… |
| CVE-2025-24958 | CVE-2025-24958 CVSS 8.8 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_tag.php` endpoint. This vuln… |
| CVE-2025-24938 | CVE-2025-24938 CVSS 8.4 | The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (adm… |
| CVE-2025-24922 | CVE-2025-24922 CVSS 8.8 | A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Pl… |
| CVE-2025-24919 | CVE-2025-24919 CVSS 8.1 | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Pl… |
| CVE-2025-24904 | CVE-2025-24904 CVSS 8.5 | libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal servers. Prior … |
| CVE-2025-24903 | CVE-2025-24903 CVSS 8.5 | libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal servers. Prior … |
| CVE-2025-24902 | CVE-2025-24902 CVSS 8.8 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_cargo.php` endpoint. This vu… |
| CVE-2025-24901 | CVE-2025-24901 CVSS 8.8 | WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_permissao.php` endpoint. Th… |
| CVE-2025-24900 | CVE-2025-24900 CVSS 8.6 | Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper settings of co… |
| CVE-2025-24897 | CVE-2025-24897 CVSS 8.2 | Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protectio… |