92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,851–6,900 of 8,161 in High · page 138 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-24411 | CVE-2025-24411 CVSS 8.1 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could r… |
| CVE-2025-24410 | CVE-2025-24410 CVSS 8.7 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha… |
| CVE-2025-24409 | CVE-2025-24409 CVSS 8.2 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could … |
| CVE-2025-24404 | CVE-2025-24404 CVSS 8.8 | XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with ac… |
| CVE-2025-24399 | CVE-2025-24399 CVSS 8.8 | Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing … |
| CVE-2025-24398 | CVE-2025-24398 CVSS 8.8 | Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any ta… |
| CVE-2025-24381 | CVE-2025-24381 CVSS 8.8 | Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote … |
| CVE-2025-24367 | CVE-2025-24367 CVSS 8.8 | Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to cr… |
| CVE-2025-24359 | CVE-2025-24359 CVSS 8.4 | ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can b… |
| CVE-2025-24357 | CVE-2025-24357 CVSS 8.8 | vLLM is a library for LLM inference and serving. vllm/model_executor/weight_utils.py implements hf_model_weights_iterator to load the model checkpoint, which i… |
| CVE-2025-24351 | CVE-2025-24351 CVSS 8.8 | A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to execute arb… |
| CVE-2025-24337 | CVE-2025-24337 CVSS 8.4 | WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini. |
| CVE-2025-24325 | CVE-2025-24325 CVSS 8.8 | Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potent… |
| CVE-2025-24320 | CVE-2025-24320 CVSS 8.0 | A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript i… |
| CVE-2025-24311 | CVE-2025-24311 CVSS 8.4 | An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior … |
| CVE-2025-24299 | CVE-2025-24299 CVSS 8.8 | Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privile… |
| CVE-2025-24255 | CVE-2025-24255 CVSS 8.4 | A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app … |
| CVE-2025-24254 | CVE-2025-24254 CVSS 8.8 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may… |
| CVE-2025-24252 | CVE-2025-24252 CVSS 8.8 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS… |
| CVE-2025-24223 | CVE-2025-24223 CVSS 8.0 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.… |
| CVE-2025-24196 | CVE-2025-24196 CVSS 8.8 | A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privi… |
| CVE-2025-24189 | CVE-2025-24189 CVSS 8.8 | The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchO… |
| CVE-2025-24180 | CVE-2025-24180 CVSS 8.1 | The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS… |
| CVE-2025-2417 | CVE-2025-2417 CVSS 8.6 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication Bypass. This issue affects e-Mutabakat: … |
| CVE-2025-2416 | CVE-2025-2416 CVSS 8.6 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypass. This issue affects LimonDesk: from… |
| CVE-2025-24150 | CVE-2025-24150 CVSS 8.8 | A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL … |
| CVE-2025-2415 | CVE-2025-2415 CVSS 8.6 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass. This issue affects MyRezzta: from s… |
| CVE-2025-2414 | CVE-2025-2414 CVSS 8.6 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypass. This issue affects OctoCloud: from… |
| CVE-2025-24137 | CVE-2025-24137 CVSS 8.0 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.… |
| CVE-2025-2413 | CVE-2025-2413 CVSS 8.6 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypass. This issue affects ProKuafor: from… |
| CVE-2025-2412 | CVE-2025-2412 CVSS 8.6 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass. This issue affects QR Menu: from s1.… |
| CVE-2025-2411 | CVE-2025-2411 CVSS 8.6 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypass. This issue affects TaskPano: from s… |
| CVE-2025-24084 | CVE-2025-24084 CVSS 8.4 | Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. |
| CVE-2025-24064 | CVE-2025-24064 CVSS 8.1 | Use after free in DNS Server allows an unauthorized attacker to execute code over a network. |
| CVE-2025-24056 | CVE-2025-24056 CVSS 8.8 | Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network. |
| CVE-2025-24051 | CVE-2025-24051 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-24049 | CVE-2025-24049 CVSS 8.4 | Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to … |
| CVE-2025-24045 | CVE-2025-24045 CVSS 8.1 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
| CVE-2025-24035 | CVE-2025-24035 CVSS 8.1 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
| CVE-2025-24022 | CVE-2025-24022 CVSS 8.5 | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend of iTop's p… |
| CVE-2025-2402 | CVE-2025-2402 CVSS 8.6 | A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all versions except the ones listed below allows an unauthenticated rem… |
| CVE-2025-24003 | CVE-2025-24003 CVSS 8.2 | An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting … |
| CVE-2025-24000 | CVE-2025-24000 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authentication Bypass.This issue affects Post S… |
| CVE-2025-23974 | CVE-2025-23974 CVSS 8.1 | Incorrect Privilege Assignment vulnerability in ifkooo One-Login one-login allows Privilege Escalation.This issue affects One-Login: from n/a through <= 1.4. |
| CVE-2025-2396 | CVE-2025-2396 CVSS 8.8 | The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web sh… |
| CVE-2025-23952 | CVE-2025-23952 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget custom-fi… |
| CVE-2025-23949 | CVE-2025-23949 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dzeriho Improved Sale Badges – Free Ve… |
| CVE-2025-23948 | CVE-2025-23948 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Webarea Background animation blocks ba… |
| CVE-2025-23944 | CVE-2025-23944 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in bulktheme WOOEXIM wooexim allows Object Injection.This issue affects WOOEXIM: from n/a through <= 5.0.0. |
| CVE-2025-23937 | CVE-2025-23937 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Furr LinkedIn Lite linkedin-lite … |