92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 6,951–7,000 of 8,161 in High · page 140 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-23044 | CVE-2025-23044 CVSS 8.1 | PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This in… |
| CVE-2025-2303 | CVE-2025-2303 CVSS 8.8 | The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 … |
| CVE-2025-23025 | CVE-2025-23025 CVSS 8.0 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **expe… |
| CVE-2025-23023 | CVE-2025-23023 CVSS 8.2 | Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a request with the right request headers to… |
| CVE-2025-23015 | CVE-2025-23015 CVSS 8.8 | Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser w… |
| CVE-2025-23011 | CVE-2025-23011 CVSS 8.8 | Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted a… |
| CVE-2025-22964 | CVE-2025-22964 CVSS 8.1 | DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and… |
| CVE-2025-22961 | CVE-2025-22961 CVSS 8.0 | A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters due to Incorrect Access… |
| CVE-2025-22960 | CVE-2025-22960 CVSS 8.0 | A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access… |
| CVE-2025-22924 | CVE-2025-22924 CVSS 8.8 | OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php. |
| CVE-2025-22923 | CVE-2025-22923 CVSS 8.8 | An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.ph… |
| CVE-2025-22894 | CVE-2025-22894 CVSS 8.8 | Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially craf… |
| CVE-2025-22890 | CVE-2025-22890 CVSS 8.8 | Execution with unnecessary privileges issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker performs a specific operation, SYS… |
| CVE-2025-2289 | CVE-2025-2289 CVSS 8.8 | The Zegen - Church WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX endpoints in all … |
| CVE-2025-22851 | CVE-2025-22851 CVSS 8.8 | in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow. |
| CVE-2025-22800 | CVE-2025-22800 CVSS 8.8 | Missing Authorization vulnerability in Saad Iqbal Post SMTP post-smtp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect… |
| CVE-2025-2280 | CVE-2025-2280 CVSS 8.1 | Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser … |
| CVE-2025-22799 | CVE-2025-22799 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-wo… |
| CVE-2025-22787 | CVE-2025-22787 CVSS 8.8 | Missing Authorization vulnerability in bPlugins Button Block button-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Bu… |
| CVE-2025-22786 | CVE-2025-22786 CVSS 8.8 | Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows PHP Local File Incl… |
| CVE-2025-22784 | CVE-2025-22784 CVSS 8.6 | Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Background Control background-control allows Path Traversal.This issue affects Background Contro… |
| CVE-2025-22783 | CVE-2025-22783 CVSS 8.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo allo… |
| CVE-2025-22736 | CVE-2025-22736 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Saad Iqbal User Management user-management allows Privilege Escalation.This issue affects User Management: from… |
| CVE-2025-22728 | CVE-2025-22728 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows SQL … |
| CVE-2025-22716 | CVE-2025-22716 CVSS 8.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in taskbuilder Taskbuilder taskbuilder allows SQL Injection.… |
| CVE-2025-22713 | CVE-2025-22713 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vanquish WooCommerce Orders & Customers Exporter woocomme… |
| CVE-2025-22712 | CVE-2025-22712 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Typify typify allows PHP … |
| CVE-2025-22708 | CVE-2025-22708 CVSS 8.1thememove | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Loc… |
| CVE-2025-22707 | CVE-2025-22707 CVSS 8.1thememove | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Lo… |
| CVE-2025-22700 | CVE-2025-22700 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects… |
| CVE-2025-2270 | CVE-2025-2270 CVSS 8.1 | The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.… |
| CVE-2025-22663 | CVE-2025-22663 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allow… |
| CVE-2025-22656 | CVE-2025-22656 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Oscar Alvarez Cookie Monster cookie-mo… |
| CVE-2025-22639 | CVE-2025-22639 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerce distance… |
| CVE-2025-22636 | CVE-2025-22636 CVSS 8.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vicente Ruiz Gálvez VR-Frases vr-frases allows Reflected … |
| CVE-2025-22603 | CVE-2025-22603 CVSS 8.1 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Versions prior… |
| CVE-2025-22537 | CVE-2025-22537 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google Maps Travel Route google-maps-travel-r… |
| CVE-2025-22535 | CVE-2025-22535 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal wplistcal allows SQL Injection.This iss… |
| CVE-2025-22519 | CVE-2025-22519 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jerodmoore eDoc Easy Tables edoc-easy-tables allows SQL I… |
| CVE-2025-22509 | CVE-2025-22509 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TMRW-studio Atlas atlas allows PHP Loc… |
| CVE-2025-22508 | CVE-2025-22508 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Event Lite fat-event-lite … |
| CVE-2025-22505 | CVE-2025-22505 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlist-for-wooc… |
| CVE-2025-22495 | CVE-2025-22495 CVSS 8.4 | An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authenticated h… |
| CVE-2025-2249 | CVE-2025-2249 CVSS 8.8 | The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_subpanel() … |
| CVE-2025-22486 | CVE-2025-22486 CVSS 8.8 | An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who h… |
| CVE-2025-22482 | CVE-2025-22482 CVSS 8.1 | A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attack… |
| CVE-2025-22481 | CVE-2025-22481 CVSS 8.8 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attack… |
| CVE-2025-22478 | CVE-2025-22478 CVSS 8.1 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthent… |
| CVE-2025-22477 | CVE-2025-22477 CVSS 8.8 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent … |
| CVE-2025-22476 | CVE-2025-22476 CVSS 8.0 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection… |