92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 6,951–7,000 of 8,161 in High · page 140 of 164

IDTitleSummary
CVE-2025-23044CVE-2025-23044
CVSS 8.1
PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This in…
CVE-2025-2303CVE-2025-2303
CVSS 8.8
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 …
CVE-2025-23025CVE-2025-23025
CVSS 8.0
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **expe…
CVE-2025-23023CVE-2025-23023
CVSS 8.2
Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a request with the right request headers to…
CVE-2025-23015CVE-2025-23015
CVSS 8.8
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser w…
CVE-2025-23011CVE-2025-23011
CVSS 8.8
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted a…
CVE-2025-22964CVE-2025-22964
CVSS 8.1
DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and…
CVE-2025-22961CVE-2025-22961
CVSS 8.0
A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorrect Access…
CVE-2025-22960CVE-2025-22960
CVSS 8.0
A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access…
CVE-2025-22924CVE-2025-22924
CVSS 8.8
OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
CVE-2025-22923CVE-2025-22923
CVSS 8.8
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.ph…
CVE-2025-22894CVE-2025-22894
CVSS 8.8
Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially craf…
CVE-2025-22890CVE-2025-22890
CVSS 8.8
Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYS…
CVE-2025-2289CVE-2025-2289
CVSS 8.8
The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoints in all …
CVE-2025-22851CVE-2025-22851
CVSS 8.8
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.
CVE-2025-22800CVE-2025-22800
CVSS 8.8
Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect…
CVE-2025-2280CVE-2025-2280
CVSS 8.1
Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser …
CVE-2025-22799CVE-2025-22799
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-wo…
CVE-2025-22787CVE-2025-22787
CVSS 8.8
Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bu…
CVE-2025-22786CVE-2025-22786
CVSS 8.8
Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows PHP Local File Incl…
CVE-2025-22784CVE-2025-22784
CVSS 8.6
Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Background Control background-control allows Path Traversal.This issue affects Background Contro…
CVE-2025-22783CVE-2025-22783
CVSS 8.8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo allo…
CVE-2025-22736CVE-2025-22736
CVSS 8.8
Incorrect Privilege Assignment vulnerability in Saad Iqbal User Management user-management allows Privilege Escalation.This issue affects User Management: from…
CVE-2025-22728CVE-2025-22728
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows SQL …
CVE-2025-22716CVE-2025-22716
CVSS 8.8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder taskbuilder allows SQL Injection.…
CVE-2025-22713CVE-2025-22713
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommerce Orders & Customers Exporter woocomme…
CVE-2025-22712CVE-2025-22712
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Typify typify allows PHP …
CVE-2025-22708CVE-2025-22708
CVSS 8.1thememove
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Loc…
CVE-2025-22707CVE-2025-22707
CVSS 8.1thememove
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Lo…
CVE-2025-22700CVE-2025-22700
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects…
CVE-2025-2270CVE-2025-2270
CVSS 8.1
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.…
CVE-2025-22663CVE-2025-22663
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allow…
CVE-2025-22656CVE-2025-22656
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Oscar Alvarez Cookie Monster cookie-mo…
CVE-2025-22639CVE-2025-22639
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerce distance…
CVE-2025-22636CVE-2025-22636
CVSS 8.2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vicente Ruiz Gálvez VR-Frases vr-frases allows Reflected …
CVE-2025-22603CVE-2025-22603
CVSS 8.1
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Versions prior…
CVE-2025-22537CVE-2025-22537
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google Maps Travel Route google-maps-travel-r…
CVE-2025-22535CVE-2025-22535
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal wplistcal allows SQL Injection.This iss…
CVE-2025-22519CVE-2025-22519
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jerodmoore eDoc Easy Tables edoc-easy-tables allows SQL I…
CVE-2025-22509CVE-2025-22509
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TMRW-studio Atlas atlas allows PHP Loc…
CVE-2025-22508CVE-2025-22508
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Event Lite fat-event-lite …
CVE-2025-22505CVE-2025-22505
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlist-for-wooc…
CVE-2025-22495CVE-2025-22495
CVSS 8.4
An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authenticated h…
CVE-2025-2249CVE-2025-2249
CVSS 8.8
The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() …
CVE-2025-22486CVE-2025-22486
CVSS 8.8
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who h…
CVE-2025-22482CVE-2025-22482
CVSS 8.1
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attack…
CVE-2025-22481CVE-2025-22481
CVSS 8.8
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attack…
CVE-2025-22478CVE-2025-22478
CVSS 8.1
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthent…
CVE-2025-22477CVE-2025-22477
CVSS 8.8
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent …
CVE-2025-22476CVE-2025-22476
CVSS 8.0
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.