92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,851–6,900 of 8,161 in High · page 138 of 164

IDTitleSummary
CVE-2025-24411CVE-2025-24411
CVSS 8.1
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could r…
CVE-2025-24410CVE-2025-24410
CVSS 8.7
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha…
CVE-2025-24409CVE-2025-24409
CVSS 8.2
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could …
CVE-2025-24404CVE-2025-24404
CVSS 8.8
XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with ac…
CVE-2025-24399CVE-2025-24399
CVSS 8.8
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing …
CVE-2025-24398CVE-2025-24398
CVSS 8.8
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any ta…
CVE-2025-24381CVE-2025-24381
CVSS 8.8
Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote …
CVE-2025-24367CVE-2025-24367
CVSS 8.8
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to cr…
CVE-2025-24359CVE-2025-24359
CVSS 8.4
ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can b…
CVE-2025-24357CVE-2025-24357
CVSS 8.8
vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which i…
CVE-2025-24351CVE-2025-24351
CVSS 8.8
A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to execute arb…
CVE-2025-24337CVE-2025-24337
CVSS 8.4
WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
CVE-2025-24325CVE-2025-24325
CVSS 8.8
Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potent…
CVE-2025-24320CVE-2025-24320
CVSS 8.0
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript i…
CVE-2025-24311CVE-2025-24311
CVSS 8.4
An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior …
CVE-2025-24299CVE-2025-24299
CVSS 8.8
Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privile…
CVE-2025-24255CVE-2025-24255
CVSS 8.4
A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app …
CVE-2025-24254CVE-2025-24254
CVSS 8.8
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may…
CVE-2025-24252CVE-2025-24252
CVSS 8.8
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS…
CVE-2025-24223CVE-2025-24223
CVSS 8.0
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.…
CVE-2025-24196CVE-2025-24196
CVSS 8.8
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privi…
CVE-2025-24189CVE-2025-24189
CVSS 8.8
The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchO…
CVE-2025-24180CVE-2025-24180
CVSS 8.1
The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS…
CVE-2025-2417CVE-2025-2417
CVSS 8.6
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication Bypass. This issue affects e-Mutabakat: …
CVE-2025-2416CVE-2025-2416
CVSS 8.6
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypass. This issue affects LimonDesk: from…
CVE-2025-24150CVE-2025-24150
CVSS 8.8
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL …
CVE-2025-2415CVE-2025-2415
CVSS 8.6
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass. This issue affects MyRezzta: from s…
CVE-2025-2414CVE-2025-2414
CVSS 8.6
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypass. This issue affects OctoCloud: from…
CVE-2025-24137CVE-2025-24137
CVSS 8.0
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.…
CVE-2025-2413CVE-2025-2413
CVSS 8.6
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypass. This issue affects ProKuafor: from…
CVE-2025-2412CVE-2025-2412
CVSS 8.6
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass. This issue affects QR Menu: from s1.…
CVE-2025-2411CVE-2025-2411
CVSS 8.6
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass. This issue affects TaskPano: from s…
CVE-2025-24084CVE-2025-24084
CVSS 8.4
Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.
CVE-2025-24064CVE-2025-24064
CVSS 8.1
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2025-24056CVE-2025-24056
CVSS 8.8
Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
CVE-2025-24051CVE-2025-24051
CVSS 8.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-24049CVE-2025-24049
CVSS 8.4
Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to …
CVE-2025-24045CVE-2025-24045
CVSS 8.1
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CVE-2025-24035CVE-2025-24035
CVSS 8.1
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CVE-2025-24022CVE-2025-24022
CVSS 8.5
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's p…
CVE-2025-2402CVE-2025-2402
CVSS 8.6
A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated rem…
CVE-2025-24003CVE-2025-24003
CVSS 8.2
An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting …
CVE-2025-24000CVE-2025-24000
CVSS 8.8
Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authentication Bypass.This issue affects Post S…
CVE-2025-23974CVE-2025-23974
CVSS 8.1
Incorrect Privilege Assignment vulnerability in ifkooo One-Login one-login allows Privilege Escalation.This issue affects One-Login: from n/a through <= 1.4.
CVE-2025-2396CVE-2025-2396
CVSS 8.8
The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web sh…
CVE-2025-23952CVE-2025-23952
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget custom-fi…
CVE-2025-23949CVE-2025-23949
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dzeriho Improved Sale Badges – Free Ve…
CVE-2025-23948CVE-2025-23948
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Webarea Background animation blocks ba…
CVE-2025-23944CVE-2025-23944
CVSS 8.8
Deserialization of Untrusted Data vulnerability in bulktheme WOOEXIM wooexim allows Object Injection.This issue affects WOOEXIM: from n/a through <= 5.0.0.
CVE-2025-23937CVE-2025-23937
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Furr LinkedIn Lite linkedin-lite …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.