92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,901–6,950 of 8,161 in High · page 139 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-23913 | CVE-2025-23913 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma WordPress Google Map Professional google-map… |
| CVE-2025-23912 | CVE-2025-23912 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Philipp Speck WordPress Custom Sidebar wordpress-custom-s… |
| CVE-2025-23911 | CVE-2025-23911 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in solidres Solidres – Hotel booking plugin solidres allows … |
| CVE-2025-23910 | CVE-2025-23910 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in keighl Menus Plus+ menus-plus allows SQL Injection.This i… |
| CVE-2025-2374 | CVE-2025-2374 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This issue affects some un… |
| CVE-2025-2373 | CVE-2025-2373 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This vulnerability affects unknown code of … |
| CVE-2025-2368 | CVE-2025-2368 CVSS 8.8 | A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryRea… |
| CVE-2025-23532 | CVE-2025-23532 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Regios MyAnime Widget myanime-widget allows Privilege Escalation.This issue affects MyAnime Widget: from n/a… |
| CVE-2025-23530 | CVE-2025-23530 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Lockdown custom-post-type-lockdown allows Privilege Escalation.This issue affects … |
| CVE-2025-23528 | CVE-2025-23528 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Mosterd3d DD Roles dd-roles allows Privilege Escalation.This issue affects DD Roles: from n/a through <= 4.1. |
| CVE-2025-23477 | CVE-2025-23477 CVSS 8.2 | Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constrained by ACLs.… |
| CVE-2025-23389 | CVE-2025-23389 CVSS 8.4 | A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This is… |
| CVE-2025-23388 | CVE-2025-23388 CVSS 8.2 | A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 befor… |
| CVE-2025-2338 | CVE-2025-2338 CVSS 8.1 | A vulnerability, which was classified as critical, was found in tbeu matio 1.5.28. Affected is the function strdup_vprintf of the file src/io.c. The manipulati… |
| CVE-2025-2337 | CVE-2025-2337 CVSS 8.1 | A vulnerability, which was classified as critical, has been found in tbeu matio 1.5.28. This issue affects the function Mat_VarPrint of the file src/mat.c. The… |
| CVE-2025-23369 | CVE-2025-23369 CVSS 8.8 | An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized i… |
| CVE-2025-23368 | CVE-2025-23368 CVSS 8.1redhat | A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within… |
| CVE-2025-23364 | CVE-2025-23364 CVSS 8.4 | A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. Thi… |
| CVE-2025-23359 | CVE-2025-23359 CVSS 8.1 | NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container … |
| CVE-2025-23358 | CVE-2025-23358 CVSS 8.2 | NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue. A successful exploit of this … |
| CVE-2025-23356 | CVE-2025-23356 CVSS 8.4 | NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code execution, denial of serv… |
| CVE-2025-23309 | CVE-2025-23309 CVSS 8.2 | NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of service, escalation of privileges, code… |
| CVE-2025-23293 | CVE-2025-23293 CVSS 8.7 | NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exp… |
| CVE-2025-2328 | CVE-2025-2328 CVSS 8.8 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio… |
| CVE-2025-23267 | CVE-2025-23267 CVSS 8.5 | NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a speci… |
| CVE-2025-23256 | CVE-2025-23256 CVSS 8.7 | NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the co… |
| CVE-2025-23254 | CVE-2025-23254 CVSS 8.8 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRT… |
| CVE-2025-2324 | CVE-2025-2324 CVSS 8.8 | Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This … |
| CVE-2025-23239 | CVE-2025-23239 CVSS 8.7 | When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iCon… |
| CVE-2025-23236 | CVE-2025-23236 CVSS 8.8 | Buffer overflow vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYSTEM privilege … |
| CVE-2025-23222 | CVE-2025-23222 CVSS 8.4 | An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as root. Specifically, dde-api-proxy runs … |
| CVE-2025-23209 | Craft CMS Code Injection Vulnerability KEVCVSS 8.1Craft CMS | Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution. |
| CVE-2025-23206 | CVE-2025-23206 CVSS 8.1 | The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS Cl… |
| CVE-2025-23196 | CVE-2025-23196 CVSS 8.8 | A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. Th… |
| CVE-2025-2319 | CVE-2025-2319 CVSS 8.8 | The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is due … |
| CVE-2025-23186 | CVE-2025-23186 CVSS 8.5 | In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted desti… |
| CVE-2025-23181 | CVE-2025-23181 CVSS 8.0 | CWE-250: Execution with Unnecessary Privileges |
| CVE-2025-23180 | CVE-2025-23180 CVSS 8.0 | CWE-250: Execution with Unnecessary Privileges |
| CVE-2025-23176 | CVE-2025-23176 CVSS 8.8 | CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2025-23168 | CVE-2025-23168 CVSS 8.8 | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Di… |
| CVE-2025-23121 | CVE-2025-23121 CVSS 8.8 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user |
| CVE-2025-23120 | CVE-2025-23120 CVSS 8.8 | A vulnerability allowing remote code execution (RCE) for domain users. |
| CVE-2025-23113 | CVE-2025-23113 CVSS 8.8 | An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containin… |
| CVE-2025-23107 | CVE-2025-23107 CVSS 8.6 | An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes. |
| CVE-2025-23103 | CVE-2025-23103 CVSS 8.6 | An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes. |
| CVE-2025-23102 | CVE-2025-23102 CVSS 8.8 | An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Double Free in the mobile processor leads t… |
| CVE-2025-23093 | CVE-2025-23093 CVSS 8.8 | The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated attacker to … |
| CVE-2025-23060 | CVE-2025-23060 CVSS 8.1 | A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vu… |
| CVE-2025-23058 | CVE-2025-23058 CVSS 8.1 | A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauth… |
| CVE-2025-2305 | CVE-2025-2305 CVSS 8.6 | A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitrary files, … |