91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,251–3,300 of 8,161 in High · page 66 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-9112 | CVE-2025-9112 CVSS 8.8 | The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure_temp_file_uploader' function in a… |
| CVE-2025-9065 | CVE-2025-9065 CVSS 8.8 | A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attac… |
| CVE-2025-9048 | CVE-2025-9048 CVSS 8.1 | The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the del_img_ajax_call() functi… |
| CVE-2025-9046 | CVE-2025-9046 CVSS 8.8 | A vulnerability was identified in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform/setMacFilterCfg. The manipulation of t… |
| CVE-2025-9025 | CVE-2025-9025 CVSS 8.8 | A vulnerability was determined in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /portal.php. … |
| CVE-2025-9023 | CVE-2025-9023 CVSS 8.8 | A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manip… |
| CVE-2025-9018 | CVE-2025-9018 CVSS 8.8 | The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update_table_fun… |
| CVE-2025-9007 | CVE-2025-9007 CVSS 8.8 | A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the file /goform/editFileName. The manipulatio… |
| CVE-2025-9006 | CVE-2025-9006 CVSS 8.8 | A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileName. The manip… |
| CVE-2025-8978 | CVE-2025-8978 CVSS 8.1 | A vulnerability was determined in D-Link DIR-619L 6.02CN02. Affected is the function FirmwareUpgrade of the component boa. The manipulation leads to insufficie… |
| CVE-2025-8965 | CVE-2025-8965 CVSS 8.8 | A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/… |
| CVE-2025-8958 | CVE-2025-8958 CVSS 8.8 | A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability is an unknown functionality of the file /goform/fast_settin… |
| CVE-2025-8956 | CVE-2025-8956 CVSS 8.8 | A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcgi. The man… |
| CVE-2025-8940 | CVE-2025-8940 CVSS 8.8 | A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this vulnerability is the function strcpy of the file /goform/saveParentControlInfo… |
| CVE-2025-8939 | CVE-2025-8939 CVSS 8.8 | A vulnerability was determined in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/WifiGuestSet. The manipulation of the argum… |
| CVE-2025-8937 | CVE-2025-8937 CVSS 8.8 | A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /boafrm/formSysCmd. The manipulation lead… |
| CVE-2025-8931 | CVE-2025-8931 CVSS 8.8 | A vulnerability was determined in code-projects Medical Store Management System 1.0. Affected is an unknown function of the file ChangePassword.java. The manip… |
| CVE-2025-8930 | CVE-2025-8930 CVSS 8.8 | A vulnerability was found in code-projects Medical Store Management System 1.0. This issue affects some unknown processing of the file UpdateCompany.java of th… |
| CVE-2025-8929 | CVE-2025-8929 CVSS 8.8 | A vulnerability has been found in code-projects Medical Store Management System 1.0. This vulnerability affects unknown code of the file MainPanel.java. The ma… |
| CVE-2025-8928 | CVE-2025-8928 CVSS 8.8 | A vulnerability was identified in code-projects Medical Store Management System 1.0. This affects an unknown part of the file UpdateMedicines.java of the compo… |
| CVE-2025-8904 | CVE-2025-8904 CVSS 8.5 | Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory… |
| CVE-2025-8901 | CVE-2025-8901 CVSS 8.8 | Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.… |
| CVE-2025-8899 | CVE-2025-8899 CVSS 8.8 | The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.2… |
| CVE-2025-8882 | CVE-2025-8882 CVSS 8.8 | Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially… |
| CVE-2025-8880 | CVE-2025-8880 CVSS 8.8 | Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium sec… |
| CVE-2025-8879 | CVE-2025-8879 CVSS 8.8 | Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of g… |
| CVE-2025-8876 | N-able N-Central Command Injection Vulnerability KEVCVSS 8.8N-able | N-able N-Central contains a command injection vulnerability via improper sanitization of user input. |
| CVE-2025-8875 | N-able N-Central Insecure Deserialization Vulnerability KEVCVSS 7.8N-able | N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. |
| CVE-2025-8868 | CVE-2025-8868 CVSS 8.8 | In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functio… |
| CVE-2025-8859 | CVE-2025-8859 CVSS 8.8 | A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slide… |
| CVE-2025-8855 | CVE-2025-8855 CVSS 8.1 | Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vuln… |
| CVE-2025-8850 | CVE-2025-8850 CVSS 8.8librechat | In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA… |
| CVE-2025-8839 | CVE-2025-8839 CVSS 8.8 | A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The … |
| CVE-2025-8833 | CVE-2025-8833 CVSS 8.8 | A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function langSwitchBack of t… |
| CVE-2025-8832 | CVE-2025-8832 CVSS 8.8 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function setDMZ of t… |
| CVE-2025-8831 | CVE-2025-8831 CVSS 8.8 | A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function remoteManagement of the file /… |
| CVE-2025-8830 | CVE-2025-8830 CVSS 8.8 | A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function sub_3517C of… |
| CVE-2025-8829 | CVE-2025-8829 CVSS 8.8 | A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_r… |
| CVE-2025-8828 | CVE-2025-8828 CVSS 8.8 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function ipv6cmd of the file /gofor… |
| CVE-2025-8827 | CVE-2025-8827 CVSS 8.8 | A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function um_inspect_cross_band of… |
| CVE-2025-8826 | CVE-2025-8826 CVSS 8.8 | A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function um_rp_autoc… |
| CVE-2025-8825 | CVE-2025-8825 CVSS 8.8 | A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto of the fi… |
| CVE-2025-8824 | CVE-2025-8824 CVSS 8.8 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setRIP of th… |
| CVE-2025-8823 | CVE-2025-8823 CVSS 8.8 | A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setDevice… |
| CVE-2025-8822 | CVE-2025-8822 CVSS 8.8 | A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function algDisable of the file /go… |
| CVE-2025-8821 | CVE-2025-8821 CVSS 8.8 | A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function RP_setBasic of the … |
| CVE-2025-8820 | CVE-2025-8820 CVSS 8.8 | A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function wirelessBas… |
| CVE-2025-8819 | CVE-2025-8819 CVSS 8.8 | A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function setWan of the file /goform/set… |
| CVE-2025-8818 | CVE-2025-8818 CVSS 8.8 | A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setDFSSettin… |
| CVE-2025-8817 | CVE-2025-8817 CVSS 8.8 | A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setL… |