91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,251–3,300 of 8,161 in High · page 66 of 164

IDTitleSummary
CVE-2025-9112CVE-2025-9112
CVSS 8.8
The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure_temp_file_uploader' function in a…
CVE-2025-9065CVE-2025-9065
CVSS 8.8
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attac…
CVE-2025-9048CVE-2025-9048
CVSS 8.1
The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the del_img_ajax_call() functi…
CVE-2025-9046CVE-2025-9046
CVSS 8.8
A vulnerability was identified in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform/setMacFilterCfg. The manipulation of t…
CVE-2025-9025CVE-2025-9025
CVSS 8.8
A vulnerability was determined in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /portal.php. …
CVE-2025-9023CVE-2025-9023
CVSS 8.8
A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manip…
CVE-2025-9018CVE-2025-9018
CVSS 8.8
The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'tt_update_table_fun…
CVE-2025-9007CVE-2025-9007
CVSS 8.8
A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the file /goform/editFileName. The manipulatio…
CVE-2025-9006CVE-2025-9006
CVSS 8.8
A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileName. The manip…
CVE-2025-8978CVE-2025-8978
CVSS 8.1
A vulnerability was determined in D-Link DIR-619L 6.02CN02. Affected is the function FirmwareUpgrade of the component boa. The manipulation leads to insufficie…
CVE-2025-8965CVE-2025-8965
CVSS 8.8
A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/…
CVE-2025-8958CVE-2025-8958
CVSS 8.8
A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability is an unknown functionality of the file /goform/fast_settin…
CVE-2025-8956CVE-2025-8956
CVSS 8.8
A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcgi. The man…
CVE-2025-8940CVE-2025-8940
CVSS 8.8
A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this vulnerability is the function strcpy of the file /goform/saveParentControlInfo…
CVE-2025-8939CVE-2025-8939
CVSS 8.8
A vulnerability was determined in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/WifiGuestSet. The manipulation of the argum…
CVE-2025-8937CVE-2025-8937
CVSS 8.8
A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /boafrm/formSysCmd. The manipulation lead…
CVE-2025-8931CVE-2025-8931
CVSS 8.8
A vulnerability was determined in code-projects Medical Store Management System 1.0. Affected is an unknown function of the file ChangePassword.java. The manip…
CVE-2025-8930CVE-2025-8930
CVSS 8.8
A vulnerability was found in code-projects Medical Store Management System 1.0. This issue affects some unknown processing of the file UpdateCompany.java of th…
CVE-2025-8929CVE-2025-8929
CVSS 8.8
A vulnerability has been found in code-projects Medical Store Management System 1.0. This vulnerability affects unknown code of the file MainPanel.java. The ma…
CVE-2025-8928CVE-2025-8928
CVSS 8.8
A vulnerability was identified in code-projects Medical Store Management System 1.0. This affects an unknown part of the file UpdateMedicines.java of the compo…
CVE-2025-8904CVE-2025-8904
CVSS 8.5
Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory…
CVE-2025-8901CVE-2025-8901
CVSS 8.8
Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.…
CVE-2025-8899CVE-2025-8899
CVSS 8.8
The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.2…
CVE-2025-8882CVE-2025-8882
CVSS 8.8
Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially…
CVE-2025-8880CVE-2025-8880
CVSS 8.8
Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium sec…
CVE-2025-8879CVE-2025-8879
CVSS 8.8
Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of g…
CVE-2025-8876N-able N-Central Command Injection Vulnerability
KEVCVSS 8.8N-able
N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-8875N-able N-Central Insecure Deserialization Vulnerability
KEVCVSS 7.8N-able
N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
CVE-2025-8868CVE-2025-8868
CVSS 8.8
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functio…
CVE-2025-8859CVE-2025-8859
CVSS 8.8
A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slide…
CVE-2025-8855CVE-2025-8855
CVSS 8.1
Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vuln…
CVE-2025-8850CVE-2025-8850
CVSS 8.8librechat
In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA…
CVE-2025-8839CVE-2025-8839
CVSS 8.8
A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The …
CVE-2025-8833CVE-2025-8833
CVSS 8.8
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function langSwitchBack of t…
CVE-2025-8832CVE-2025-8832
CVSS 8.8
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function setDMZ of t…
CVE-2025-8831CVE-2025-8831
CVSS 8.8
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function remoteManagement of the file /…
CVE-2025-8830CVE-2025-8830
CVSS 8.8
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function sub_3517C of…
CVE-2025-8829CVE-2025-8829
CVSS 8.8
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_r…
CVE-2025-8828CVE-2025-8828
CVSS 8.8
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function ipv6cmd of the file /gofor…
CVE-2025-8827CVE-2025-8827
CVSS 8.8
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function um_inspect_cross_band of…
CVE-2025-8826CVE-2025-8826
CVSS 8.8
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function um_rp_autoc…
CVE-2025-8825CVE-2025-8825
CVSS 8.8
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function RP_setBasicAuto of the fi…
CVE-2025-8824CVE-2025-8824
CVSS 8.8
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setRIP of th…
CVE-2025-8823CVE-2025-8823
CVSS 8.8
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setDevice…
CVE-2025-8822CVE-2025-8822
CVSS 8.8
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function algDisable of the file /go…
CVE-2025-8821CVE-2025-8821
CVSS 8.8
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function RP_setBasic of the …
CVE-2025-8820CVE-2025-8820
CVSS 8.8
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function wirelessBas…
CVE-2025-8819CVE-2025-8819
CVSS 8.8
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function setWan of the file /goform/set…
CVE-2025-8818CVE-2025-8818
CVSS 8.8
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function setDFSSettin…
CVE-2025-8817CVE-2025-8817
CVSS 8.8
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function setL…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.