89,492 indexed

CVECVE vulnerabilities

89,492 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,151–3,200 of 8,161 in High · page 64 of 164

IDTitleSummary
CVE-2025-9812CVE-2025-9812
CVSS 8.8tenda
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Executing manipula…
CVE-2025-9803CVE-2025-9803
CVSS 8.8
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to v…
CVE-2025-9801CVE-2025-9801
CVSS 8.1
A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manipulation of…
CVE-2025-9798CVE-2025-9798
CVSS 8.9
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows Stored XSS. T…
CVE-2025-9783CVE-2025-9783
CVSS 8.8totolink
A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentControl. Execut…
CVE-2025-9782CVE-2025-9782
CVSS 8.8totolink
A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAccessButton…
CVE-2025-9781CVE-2025-9781
CVSS 8.8totolink
A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file /boafrm/formFilter. Such manipulation o…
CVE-2025-9780CVE-2025-9780
CVSS 8.8totolink
A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the file /boafrm/formIpQoS. This manipulatio…
CVE-2025-9779CVE-2025-9779
CVSS 8.8totolink
A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_4162DC of the file /boafrm/formFilter. …
CVE-2025-9760CVE-2025-9760
CVSS 8.8
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Matricula API…
CVE-2025-9756CVE-2025-9756
CVSS 8.8
A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of…
CVE-2025-9747CVE-2025-9747
CVSS 8.8
A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such …
CVE-2025-9725CVE-2025-9725
CVSS 8.8
A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component Web Interfac…
CVE-2025-9713CVE-2025-9713
CVSS 8.8ivanti
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction i…
CVE-2025-9712CVE-2025-9712
CVSS 8.8
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote cod…
CVE-2025-9693CVE-2025-9693
CVSS 8.0
The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val…
CVE-2025-9690CVE-2025-9690
CVSS 8.8
A flaw has been found in SourceCodester Advanced School Management System 1.0. This affects an unknown function of the file /index.php/stock/vendordetails. Thi…
CVE-2025-9689CVE-2025-9689
CVSS 8.8
A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/stock/…
CVE-2025-9687CVE-2025-9687
CVSS 8.8
A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoApi. Execut…
CVE-2025-9686CVE-2025-9686
CVSS 8.8
A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/AreaConhecimento/edit of …
CVE-2025-9685CVE-2025-9685
CVSS 8.8
A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the comp…
CVE-2025-9684CVE-2025-9684
CVSS 8.8
A vulnerability was determined in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/edit of the component Formula d…
CVE-2025-9667CVE-2025-9667
CVSS 8.8
A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delete_account.php of the component Admin Pa…
CVE-2025-9666CVE-2025-9666
CVSS 8.8
A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some unknown functionality of the file /delete…
CVE-2025-9665CVE-2025-9665
CVSS 8.8
A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_student…
CVE-2025-9664CVE-2025-9664
CVSS 8.8
A security flaw has been discovered in code-projects Simple Grading System 1.0. Affected is an unknown function of the file /add_student_grade.php of the compo…
CVE-2025-9663CVE-2025-9663
CVSS 8.8
A vulnerability was identified in code-projects Simple Grading System 1.0. This impacts an unknown function of the file /edit_account.php of the component Admi…
CVE-2025-9609CVE-2025-9609
CVSS 8.8
A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulation results…
CVE-2025-9608CVE-2025-9608
CVSS 8.8
A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/view of the component Formula d…
CVE-2025-9607CVE-2025-9607
CVSS 8.8
A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/TabelaArredondamento/view of …
CVE-2025-9606CVE-2025-9606
CVSS 6.3portabilis
A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_prefere…
CVE-2025-9587CVE-2025-9587
CVSS 8.6
The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX act…
CVE-2025-9586CVE-2025-9586
CVSS 6.3comfast
A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipu…
CVE-2025-9585CVE-2025-9585
CVSS 6.3comfast
A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of th…
CVE-2025-9584CVE-2025-9584
CVSS 6.3comfast
A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of…
CVE-2025-9583CVE-2025-9583
CVSS 6.3comfast
A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulatio…
CVE-2025-9580CVE-2025-9580
CVSS 6.3lb-link
A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Ha…
CVE-2025-9579CVE-2025-9579
CVSS 6.3b-link
A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the component HTTP …
CVE-2025-9575CVE-2025-9575
CVSS 8.8
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue…
CVE-2025-9566CVE-2025-9566
CVSS 8.1
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap…
CVE-2025-9561CVE-2025-9561
CVSS 8.8
The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insufficient file validation within the advPara…
CVE-2025-9539CVE-2025-9539
CVSS 8.0
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modi…
CVE-2025-9532CVE-2025-9532
CVSS 8.8
A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the file /RegraAvaliacao/view. Executing manipulation of the argum…
CVE-2025-9531CVE-2025-9531
CVSS 6.3portabilis
A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Modul…
CVE-2025-9527CVE-2025-9527
CVSS 8.8
A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup. Performing manipulation of the argumen…
CVE-2025-9526CVE-2025-9526
CVSS 8.8
A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the file /goform/setSysAdm. Such manipulation …
CVE-2025-9525CVE-2025-9525
CVSS 8.8
A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /goform/setWan. This manipulation of the …
CVE-2025-9483CVE-2025-9483
CVSS 8.8
A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the fun…
CVE-2025-9482CVE-2025-9482
CVSS 8.8
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts…
CVE-2025-9481CVE-2025-9481
CVSS 8.8
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.