92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 7,151–7,200 of 8,161 in High · page 144 of 164

IDTitleSummary
CVE-2025-2052CVE-2025-2052
CVSS 8.8
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This issue affects some unknown processing of the …
CVE-2025-2051CVE-2025-2051
CVSS 8.8
A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This vulnerability affects unknown code of th…
CVE-2025-20371CVE-2025-20371
CVSS 8.8
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an un…
CVE-2025-2037CVE-2025-2037
CVSS 8.8
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the f…
CVE-2025-20362Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
KEVCVSS 6.5Cisco
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulner…
CVE-2025-20352Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
KEVCVSS 7.7Cisco
Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denia…
CVE-2025-20349CVE-2025-20349
CVSS 6.3cisco
A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container …
CVE-2025-20341CVE-2025-20341
CVSS 8.8
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected …
CVE-2025-20334CVE-2025-20334
CVSS 8.8
A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into…
CVE-2025-2033CVE-2025-2033
CVSS 8.8
A vulnerability, which was classified as critical, was found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /us…
CVE-2025-20326CVE-2025-20326
CVSS 8.8
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edi…
CVE-2025-20315CVE-2025-20315
CVSS 8.6cisco
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a…
CVE-2025-20298CVE-2025-20298
CVSS 8.0
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in inco…
CVE-2025-20287CVE-2025-20287
CVSS 8.8
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upl…
CVE-2025-20274CVE-2025-20274
CVSS 8.8
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload arbitrary fi…
CVE-2025-20271CVE-2025-20271
CVSS 8.6
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remo…
CVE-2025-20263CVE-2025-20263
CVSS 8.6
A vulnerability in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD…
CVE-2025-20261CVE-2025-20261
CVSS 8.8
A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Se…
CVE-2025-20253CVE-2025-20253
CVSS 8.6
A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FTD Software could allow an unauthenticat…
CVE-2025-20251CVE-2025-20251
CVSS 8.5
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defe…
CVE-2025-20243CVE-2025-20243
CVSS 8.6
A vulnerability in the management and VPN web servers of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote atta…
CVE-2025-20239CVE-2025-20239
CVSS 8.6
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA…
CVE-2025-20236CVE-2025-20236
CVSS 8.8
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, whi…
CVE-2025-20229CVE-2025-20229
CVSS 8.0
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.2…
CVE-2025-20222CVE-2025-20222
CVSS 8.6
A vulnerability in the RADIUS proxy feature for the IPsec VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Fire…
CVE-2025-20217CVE-2025-20217
CVSS 8.6
A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an un…
CVE-2025-20200CVE-2025-20200
CVSS 8.2
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the u…
CVE-2025-20199CVE-2025-20199
CVSS 8.2
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the u…
CVE-2025-20198CVE-2025-20198
CVSS 8.2
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the u…
CVE-2025-20197CVE-2025-20197
CVSS 8.2
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the u…
CVE-2025-20186CVE-2025-20186
CVSS 8.8
A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, remote atta…
CVE-2025-20182CVE-2025-20182
CVSS 8.6cisco
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat …
CVE-2025-20164CVE-2025-20164
CVSS 8.3
A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate priv…
CVE-2025-20163CVE-2025-20163
CVSS 8.7
A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisc…
CVE-2025-20162CVE-2025-20162
CVSS 8.6
A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue …
CVE-2025-20160CVE-2025-20160
CVSS 8.1cisco
A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker t…
CVE-2025-20154CVE-2025-20154
CVSS 8.6
A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticate…
CVE-2025-20152CVE-2025-20152
CVSS 8.6
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a den…
CVE-2025-20148CVE-2025-20148
CVSS 8.5
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker t…
CVE-2025-20146CVE-2025-20146
CVSS 8.6
A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Perform…
CVE-2025-20142CVE-2025-20142
CVSS 8.6
A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR 9000 Series Ag…
CVE-2025-20138CVE-2025-20138
CVSS 8.8
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operat…
CVE-2025-20136CVE-2025-20136
CVSS 8.6
A vulnerability in the function that performs IPv4 and IPv6 Network Address Translation (NAT) DNS inspection for Cisco Secure Firewall Adaptive Security Applia…
CVE-2025-20134CVE-2025-20134
CVSS 8.6
A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD…
CVE-2025-20133CVE-2025-20133
CVSS 8.6
A vulnerability in the management and VPN web servers of the Remote Access SSL VPN feature of Cisco Secure Firewall ASA Software and Secure FTD Software could …
CVE-2025-20115CVE-2025-20115
CVSS 8.6
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote atta…
CVE-2025-20101CVE-2025-20101
CVSS 8.4
Out-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information disclosure or denial of service via loc…
CVE-2025-20094CVE-2025-20094
CVSS 8.8
Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially craf…
CVE-2025-20093CVE-2025-20093
CVSS 8.2
Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an a…
CVE-2025-2008CVE-2025-2008
CVSS 8.8
The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.