92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,901–6,950 of 8,161 in High · page 139 of 164

IDTitleSummary
CVE-2025-23913CVE-2025-23913
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma WordPress Google Map Professional google-map…
CVE-2025-23912CVE-2025-23912
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Philipp Speck WordPress Custom Sidebar wordpress-custom-s…
CVE-2025-23911CVE-2025-23911
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solidres Solidres – Hotel booking plugin solidres allows …
CVE-2025-23910CVE-2025-23910
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in keighl Menus Plus+ menus-plus allows SQL Injection.This i…
CVE-2025-2374CVE-2025-2374
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This issue affects some un…
CVE-2025-2373CVE-2025-2373
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This vulnerability affects unknown code of …
CVE-2025-2368CVE-2025-2368
CVSS 8.8
A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryRea…
CVE-2025-23532CVE-2025-23532
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Regios MyAnime Widget myanime-widget allows Privilege Escalation.This issue affects MyAnime Widget: from n/a…
CVE-2025-23530CVE-2025-23530
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Lockdown custom-post-type-lockdown allows Privilege Escalation.This issue affects …
CVE-2025-23528CVE-2025-23528
CVSS 8.8
Incorrect Privilege Assignment vulnerability in Mosterd3d DD Roles dd-roles allows Privilege Escalation.This issue affects DD Roles: from n/a through <= 4.1.
CVE-2025-23477CVE-2025-23477
CVSS 8.2
Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constrained by ACLs.…
CVE-2025-23389CVE-2025-23389
CVSS 8.4
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This is…
CVE-2025-23388CVE-2025-23388
CVSS 8.2
A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 befor…
CVE-2025-2338CVE-2025-2338
CVSS 8.1
A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulati…
CVE-2025-2337CVE-2025-2337
CVSS 8.1
A vulnerability, which was classified as critical, has been found in tbeu matio 1.5.28. This issue affects the function Mat_VarPrint of the file src/mat.c. The…
CVE-2025-23369CVE-2025-23369
CVSS 8.8
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized i…
CVE-2025-23368CVE-2025-23368
CVSS 8.1redhat
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within…
CVE-2025-23364CVE-2025-23364
CVSS 8.4
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. Thi…
CVE-2025-23359CVE-2025-23359
CVSS 8.1
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container …
CVE-2025-23358CVE-2025-23358
CVSS 8.2
NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue. A successful exploit of this …
CVE-2025-23356CVE-2025-23356
CVSS 8.4
NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code execution, denial of serv…
CVE-2025-23309CVE-2025-23309
CVSS 8.2
NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of service, escalation of privileges, code…
CVE-2025-23293CVE-2025-23293
CVSS 8.7
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exp…
CVE-2025-2328CVE-2025-2328
CVSS 8.8
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio…
CVE-2025-23267CVE-2025-23267
CVSS 8.5
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a speci…
CVE-2025-23256CVE-2025-23256
CVSS 8.7
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the co…
CVE-2025-23254CVE-2025-23254
CVSS 8.8
NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRT…
CVE-2025-2324CVE-2025-2324
CVSS 8.8
Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This …
CVE-2025-23239CVE-2025-23239
CVSS 8.7
When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iCon…
CVE-2025-23236CVE-2025-23236
CVSS 8.8
Buffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege …
CVE-2025-23222CVE-2025-23222
CVSS 8.4
An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs …
CVE-2025-23209Craft CMS Code Injection Vulnerability
KEVCVSS 8.1Craft CMS
Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.
CVE-2025-23206CVE-2025-23206
CVSS 8.1
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS Cl…
CVE-2025-23196CVE-2025-23196
CVSS 8.8
A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. Th…
CVE-2025-2319CVE-2025-2319
CVSS 8.8
The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is due …
CVE-2025-23186CVE-2025-23186
CVSS 8.5
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted desti…
CVE-2025-23181CVE-2025-23181
CVSS 8.0
CWE-250: Execution with Unnecessary Privileges
CVE-2025-23180CVE-2025-23180
CVSS 8.0
CWE-250: Execution with Unnecessary Privileges
CVE-2025-23176CVE-2025-23176
CVSS 8.8
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-23168CVE-2025-23168
CVSS 8.8
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Di…
CVE-2025-23121CVE-2025-23121
CVSS 8.8
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVE-2025-23120CVE-2025-23120
CVSS 8.8
A vulnerability allowing remote code execution (RCE) for domain users.
CVE-2025-23113CVE-2025-23113
CVSS 8.8
An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containin…
CVE-2025-23107CVE-2025-23107
CVSS 8.6
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.
CVE-2025-23103CVE-2025-23103
CVSS 8.6
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.
CVE-2025-23102CVE-2025-23102
CVSS 8.8
An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Double Free in the mobile processor leads t…
CVE-2025-23093CVE-2025-23093
CVSS 8.8
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to …
CVE-2025-23060CVE-2025-23060
CVSS 8.1
A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vu…
CVE-2025-23058CVE-2025-23058
CVSS 8.1
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauth…
CVE-2025-2305CVE-2025-2305
CVSS 8.6
A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitrary files, …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.