92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 7,001–7,050 of 8,161 in High · page 141 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-22467 | CVE-2025-22467 CVSS 8.8 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution. |
| CVE-2025-2242 | CVE-2025-2242 CVSS 8.8 | An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 all… |
| CVE-2025-22412 | CVE-2025-22412 CVSS 8.8 | In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code… |
| CVE-2025-22411 | CVE-2025-22411 CVSS 8.8 | In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjac… |
| CVE-2025-22410 | CVE-2025-22410 CVSS 8.4 | In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no addi… |
| CVE-2025-2241 | CVE-2025-2241 CVSS 8.2 | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be e… |
| CVE-2025-22409 | CVE-2025-22409 CVSS 8.4 | In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of priv… |
| CVE-2025-22406 | CVE-2025-22406 CVSS 8.4 | In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation of … |
| CVE-2025-22405 | CVE-2025-22405 CVSS 8.4 | In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no addi… |
| CVE-2025-22404 | CVE-2025-22404 CVSS 8.4 | In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privi… |
| CVE-2025-22389 | CVE-2025-22389 CVSS 8.0 | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not prop… |
| CVE-2025-22381 | CVE-2025-22381 CVSS 8.2 | Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password. |
| CVE-2025-2238 | CVE-2025-2238 CVSS 8.8 | The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restrictions in… |
| CVE-2025-22348 | CVE-2025-22348 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rtowebsites DynamicTags dynamictags allows Blind SQL Inje… |
| CVE-2025-22347 | CVE-2025-22347 CVSS 8.2 | Cross-Site Request Forgery (CSRF) vulnerability in bannersky BSK Forms Blacklist bsk-gravityforms-blacklist allows Blind SQL Injection.This issue affects BSK F… |
| CVE-2025-2233 | CVE-2025-2233 CVSS 8.8 | Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers … |
| CVE-2025-22277 | CVE-2025-22277 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authentication Abuse.This issue affects Vitepos: f… |
| CVE-2025-22256 | CVE-2025-22256 CVSS 8.8 | A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3,… |
| CVE-2025-22249 | CVE-2025-22249 CVSS 8.2 | VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a l… |
| CVE-2025-22239 | CVE-2025-22239 CVSS 8.1 | Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's e… |
| CVE-2025-22236 | CVE-2025-22236 CVSS 8.1 | Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007… |
| CVE-2025-22225 | VMware ESXi Arbitrary Write Vulnerability KEVCVSS 8.2VMware | VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrar… |
| CVE-2025-22224 | VMware ESXi and Workstation TOCTOU Race Condition Vulnerability KEVCVSS 8.2VMware | VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploita… |
| CVE-2025-22217 | CVE-2025-22217 CVSS 8.6 | Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this… |
| CVE-2025-22157 | CVE-2025-22157 CVSS 8.8 | This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Se… |
| CVE-2025-22141 | CVE-2025-22141 CVSS 8.8 | WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specificall… |
| CVE-2025-22140 | CVE-2025-22140 CVSS 8.8 | WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, sp… |
| CVE-2025-22130 | CVE-2025-22130 CVSS 8.8 | Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over… |
| CVE-2025-22041 | CVE-2025-22041 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue … |
| CVE-2025-22040 | CVE-2025-22040 CVSS 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel connection There is a race condition be… |
| CVE-2025-2193 | CVE-2025-2193 CVSS 8.1 | A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of t… |
| CVE-2025-2190 | CVE-2025-2190 CVSS 8.1 | The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks. |
| CVE-2025-2185 | CVE-2025-2185 CVSS 8.0 | ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which … |
| CVE-2025-21628 | CVE-2025-21628 CVSS 8.8 | Chatwoot is a customer engagement suite. Prior to 3.16.0, conversation and contact filters endpoints did not sanitize the input of query_operator passed from t… |
| CVE-2025-21612 | CVE-2025-21612 CVSS 8.6 | TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when o… |
| CVE-2025-21611 | CVE-2025-21611 CVSS 8.8 | tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of … |
| CVE-2025-2158 | CVE-2025-2158 CVSS 8.8 | The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all versions up … |
| CVE-2025-21564 | CVE-2025-21564 CVSS 8.1 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affecte… |
| CVE-2025-2155 | CVE-2025-2155 CVSS 8.8 | Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. Thi… |
| CVE-2025-2153 | CVE-2025-2153 CVSS 8.1 | A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 File H… |
| CVE-2025-21516 | CVE-2025-21516 CVSS 8.1 | Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported versions that are affected are 12.2.5-12… |
| CVE-2025-21515 | CVE-2025-21515 CVSS 8.8 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior … |
| CVE-2025-2151 | CVE-2025-2151 CVSS 8.8 | A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the … |
| CVE-2025-21506 | CVE-2025-21506 CVSS 8.1 | Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). Supported versions that are affected are… |
| CVE-2025-21488 | CVE-2025-21488 CVSS 8.2qualcomm | Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. |
| CVE-2025-21487 | CVE-2025-21487 CVSS 8.2qualcomm | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. |
| CVE-2025-21484 | CVE-2025-21484 CVSS 8.2qualcomm | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. |
| CVE-2025-21480 | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability KEVCVSS 8.6Qualcomm | Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execut… |
| CVE-2025-21479 | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability KEVCVSS 8.6Qualcomm | Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execut… |
| CVE-2025-21427 | CVE-2025-21427 CVSS 8.2 | Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. |