92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,801–6,850 of 8,161 in High · page 137 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-24896 | CVE-2025-24896 CVSS 8.1 | Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is … |
| CVE-2025-24888 | CVE-2025-24888 CVSS 8.1 | The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to ve… |
| CVE-2025-24876 | CVE-2025-24876 CVSS 8.1 | The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal t… |
| CVE-2025-2486 | CVE-2025-2486 CVSS 8.8 | The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot … |
| CVE-2025-24859 | CVE-2025-24859 CVSS 8.8 | A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes.… |
| CVE-2025-2485 | CVE-2025-2485 CVSS 8.8 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.… |
| CVE-2025-24838 | CVE-2025-24838 CVSS 8.8 | Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of pri… |
| CVE-2025-24818 | CVE-2025-24818 CVSS 8.0nokia | Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search… |
| CVE-2025-24817 | CVE-2025-24817 CVSS 8.0nokia | Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Co… |
| CVE-2025-24802 | CVE-2025-24802 CVSS 8.6 | Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not divisible by 26 = floor(num_routed_wires / 3) alwa… |
| CVE-2025-24801 | CVE-2025-24801 CVSS 8.8 | GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. Th… |
| CVE-2025-24782 | CVE-2025-24782 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Carousel Ult… |
| CVE-2025-24780 | CVE-2025-24780 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for Woo… |
| CVE-2025-24779 | CVE-2025-24779 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in NooTheme Yogi yogi allows Object Injection.This issue affects Yogi: from n/a through < 2.9.3. |
| CVE-2025-24777 | CVE-2025-24777 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter: from n/a through 3.0.7. |
| CVE-2025-24770 | CVE-2025-24770 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme CraftXtore bw-craftxtore allo… |
| CVE-2025-24769 | CVE-2025-24769 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Zenny bw-zenny allows PHP Loc… |
| CVE-2025-24768 | CVE-2025-24768 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Nitan snsnitan allows PHP Loc… |
| CVE-2025-24761 | CVE-2025-24761 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme DSK dsk allows PHP Local File… |
| CVE-2025-24760 | CVE-2025-24760 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Sofass sofass allows PHP Lo… |
| CVE-2025-2476 | CVE-2025-2476 CVSS 8.8 | Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro… |
| CVE-2025-24753 | CVE-2025-24753 CVSS 8.8 | Missing Authorization vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Exploiting Incorrectly Configured Access Control Secu… |
| CVE-2025-24742 | CVE-2025-24742 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.40. |
| CVE-2025-24734 | CVE-2025-24734 CVSS 8.8 | Missing Authorization vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Privilege Escalation.This issue affects Better F… |
| CVE-2025-24728 | CVE-2025-24728 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yannick Lefebvre Bug Library bug-library allows Blind SQL… |
| CVE-2025-24717 | CVE-2025-24717 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal Window: fro… |
| CVE-2025-2471 | CVE-2025-2471 CVSS 8.8 | A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unknown function of the file /boat-details.p… |
| CVE-2025-24690 | CVE-2025-24690 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality formality all… |
| CVE-2025-24685 | CVE-2025-24685 CVSS 8.1 | Path Traversal: '.../...//' vulnerability in Ihor Kit Morkva UA Shipping morkva-ua-shipping allows PHP Local File Inclusion.This issue affects Morkva UA Shippi… |
| CVE-2025-24672 | CVE-2025-24672 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople Form Builder CP cp-easy-form-builder allows SQ… |
| CVE-2025-24669 | CVE-2025-24669 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in serpednet SERPed.net serped-net allows SQL Injection.This… |
| CVE-2025-24661 | CVE-2025-24661 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Object Injection.This i… |
| CVE-2025-24654 | CVE-2025-24654 CVSS 8.8 | Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= … |
| CVE-2025-24618 | CVE-2025-24618 CVSS 8.8 | Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Co… |
| CVE-2025-24591 | CVE-2025-24591 CVSS 8.8 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Se… |
| CVE-2025-24527 | CVE-2025-24527 CVSS 8.0 | An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can ex… |
| CVE-2025-24514 | CVE-2025-24514 CVSS 8.8 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject co… |
| CVE-2025-2450 | CVE-2025-2450 CVSS 8.8 | NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … |
| CVE-2025-2449 | CVE-2025-2449 CVSS 8.8 | NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary f… |
| CVE-2025-24472 | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability KEVCVSS 8.1Fortinet | Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF pr… |
| CVE-2025-24470 | CVE-2025-24470 CVSS 8.6 | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a rem… |
| CVE-2025-24456 | CVE-2025-24456 CVSS 8.8 | In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping |
| CVE-2025-24438 | CVE-2025-24438 CVSS 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha… |
| CVE-2025-24418 | CVE-2025-24418 CVSS 8.1 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could re… |
| CVE-2025-24417 | CVE-2025-24417 CVSS 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha… |
| CVE-2025-24416 | CVE-2025-24416 CVSS 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha… |
| CVE-2025-24415 | CVE-2025-24415 CVSS 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha… |
| CVE-2025-24414 | CVE-2025-24414 CVSS 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha… |
| CVE-2025-24413 | CVE-2025-24413 CVSS 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha… |
| CVE-2025-24412 | CVE-2025-24412 CVSS 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha… |