91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,201–3,250 of 8,161 in High · page 65 of 164

IDTitleSummary
CVE-2025-9478CVE-2025-9478
CVSS 8.8
Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…
CVE-2025-9443CVE-2025-9443
CVSS 8.8
A flaw has been found in Tenda CH22 1.0.0.1. This vulnerability affects the function formeditUserName of the file /goform/editUserName. Executing manipulation …
CVE-2025-9428CVE-2025-9428
CVSS 8.3zohocorp
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
CVE-2025-9417CVE-2025-9417
CVSS 8.8
A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /employee/addemployee.ph…
CVE-2025-9408CVE-2025-9408
CVSS 8.1
System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege escalation for malicious userspace proce…
CVE-2025-9400CVE-2025-9400
CVSS 8.8
A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This manipulation…
CVE-2025-9399CVE-2025-9399
CVSS 8.8
A vulnerability was detected in YiFang CMS up to 2.0.5. Affected by this issue is some unknown functionality of the file app/logic/L_tool.php. The manipulation…
CVE-2025-9393CVE-2025-9393
CVSS 8.8
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnera…
CVE-2025-9392CVE-2025-9392
CVSS 8.8
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001…
CVE-2025-9377TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
KEVCVSS 7.2TP-Link
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could …
CVE-2025-9364CVE-2025-9364
CVSS 8.8rockwellautomation
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an att…
CVE-2025-9363CVE-2025-9363
CVSS 8.8
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affec…
CVE-2025-9362CVE-2025-9362
CVSS 8.8
A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted elemen…
CVE-2025-9361CVE-2025-9361
CVSS 8.8
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected…
CVE-2025-9360CVE-2025-9360
CVSS 8.8
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001…
CVE-2025-9359CVE-2025-9359
CVSS 8.8
A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue…
CVE-2025-9358CVE-2025-9358
CVSS 8.8
A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This …
CVE-2025-9357CVE-2025-9357
CVSS 8.8
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affec…
CVE-2025-9356CVE-2025-9356
CVSS 8.8
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected b…
CVE-2025-9355CVE-2025-9355
CVSS 8.8
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by thi…
CVE-2025-9334CVE-2025-9334
CVSS 8.8
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. …
CVE-2025-9317CVE-2025-9317
CVSS 8.4
The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' a…
CVE-2025-9297CVE-2025-9297
CVSS 8.8
A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /goform/wxportalauth. Performing manipulat…
CVE-2025-9293CVE-2025-9293
CVSS 8.1
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communicati…
CVE-2025-9262CVE-2025-9262
CVSS 8.1
A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handl…
CVE-2025-9253CVE-2025-9253
CVSS 8.8
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001…
CVE-2025-9252CVE-2025-9252
CVSS 8.8
A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected b…
CVE-2025-9251CVE-2025-9251
CVSS 8.8
A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affec…
CVE-2025-9250CVE-2025-9250
CVSS 8.8
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impac…
CVE-2025-9249CVE-2025-9249
CVSS 8.8
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affec…
CVE-2025-9248CVE-2025-9248
CVSS 8.8
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted el…
CVE-2025-9247CVE-2025-9247
CVSS 8.8
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affect…
CVE-2025-9246CVE-2025-9246
CVSS 8.8
A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the fun…
CVE-2025-9245CVE-2025-9245
CVSS 8.8
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue a…
CVE-2025-9244CVE-2025-9244
CVSS 8.8
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001…
CVE-2025-9243CVE-2025-9243
CVSS 8.1
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capability check on the get_cc_orders and u…
CVE-2025-9236CVE-2025-9236
CVSS 6.3portabilis
A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the com…
CVE-2025-9223CVE-2025-9223
CVSS 8.8
Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper config…
CVE-2025-9216CVE-2025-9216
CVSS 8.8
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file …
CVE-2025-9213CVE-2025-9213
CVSS 8.8
The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonce validati…
CVE-2025-9185CVE-2025-9185
CVSS 8.1mozilla
Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunder…
CVE-2025-9184CVE-2025-9184
CVSS 8.1mozilla
Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruptio…
CVE-2025-9180CVE-2025-9180
CVSS 8.1mozilla
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR…
CVE-2025-9161CVE-2025-9161
CVSS 8.8
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, whi…
CVE-2025-9153CVE-2025-9153
CVSS 8.8
A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operation…
CVE-2025-9146CVE-2025-9146
CVSS 8.1
A flaw has been found in Linksys E5600 1.1.0.26. The affected element is the function verify_gemtek_header of the file checkFw.sh of the component Firmware Han…
CVE-2025-9140CVE-2025-9140
CVSS 8.8
A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this issue is some unknown functionality of …
CVE-2025-9133CVE-2025-9133
CVSS 8.1
A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmware versions from V4.50 through V5.4…
CVE-2025-9132CVE-2025-9132
CVSS 8.8
Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (C…
CVE-2025-9121CVE-2025-9121
CVSS 8.8
Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.