91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,301–3,350 of 8,161 in High · page 67 of 164

IDTitleSummary
CVE-2025-8816CVE-2025-8816
CVSS 8.8
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function setOpMode of the file /gof…
CVE-2025-8810CVE-2025-8810
CVSS 8.8
A vulnerability classified as critical was found in Tenda AC20 16.03.08.05. Affected by this vulnerability is the function strcpy of the file /goform/SetFirewa…
CVE-2025-8807CVE-2025-8807
CVSS 8.8
A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tianti-module-a…
CVE-2025-8797CVE-2025-8797
CVSS 8.8
A vulnerability was found in LitmusChaos Litmus up to 3.19.0 and classified as critical. This issue affects some unknown processing of the component LocalStora…
CVE-2025-8756CVE-2025-8756
CVSS 8.8
A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preHandle of t…
CVE-2025-8748CVE-2025-8748
CVSS 8.8
MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP request crafted by an authenticated user coul…
CVE-2025-8715CVE-2025-8715
CVSS 8.8
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the clie…
CVE-2025-8714CVE-2025-8714
CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the …
CVE-2025-8706CVE-2025-8706
CVSS 8.8
A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as critical. Affected by this vulnerability is …
CVE-2025-8705CVE-2025-8705
CVSS 8.8
A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Affected is an unknown function…
CVE-2025-8704CVE-2025-8704
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This issue affects some un…
CVE-2025-8703CVE-2025-8703
CVSS 8.8
A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This vulnerability affects unknown code of …
CVE-2025-8702CVE-2025-8702
CVSS 8.8
A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This affects an unknown part of the fi…
CVE-2025-8701CVE-2025-8701
CVSS 8.8
A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is some unkn…
CVE-2025-8693CVE-2025-8693
CVSS 8.8
A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an a…
CVE-2025-8675CVE-2025-8675
CVSS 8.8
Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advisor: from …
CVE-2025-8654CVE-2025-8654
CVSS 8.8
Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary …
CVE-2025-8653CVE-2025-8653
CVSS 8.8
Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execut…
CVE-2025-8627CVE-2025-8627
CVSS 8.8
The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information leak. This…
CVE-2025-8593CVE-2025-8593
CVSS 8.8
The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to a m…
CVE-2025-8592CVE-2025-8592
CVSS 8.1
The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or incorrect no…
CVE-2025-8578CVE-2025-8578
CVSS 8.8
Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom…
CVE-2025-8576CVE-2025-8576
CVSS 8.8
Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Exte…
CVE-2025-8565CVE-2025-8565
CVSS 8.1
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized access of funct…
CVE-2025-8557CVE-2025-8557
CVSS 8.8
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local…
CVE-2025-8527CVE-2025-8527
CVSS 8.8
A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fast/src/mai…
CVE-2025-8500CVE-2025-8500
CVSS 8.8
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of t…
CVE-2025-8480CVE-2025-8480
CVSS 8.0
Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installation…
CVE-2025-8476CVE-2025-8476
CVSS 8.0
Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected …
CVE-2025-8450CVE-2025-8450
CVSS 8.2
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms pag…
CVE-2025-8432CVE-2025-8432
CVSS 8.4
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on th…
CVE-2025-8425CVE-2025-8425
CVSS 8.8
The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability c…
CVE-2025-8420CVE-2025-8420
CVSS 8.1
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the e…
CVE-2025-8418CVE-2025-8418
CVSS 8.8
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all versions up to, and including, 1.1.30. T…
CVE-2025-8417CVE-2025-8417
CVSS 8.1
The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to re…
CVE-2025-8382CVE-2025-8382
CVSS 8.8
A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected is an unknown function of the file /adm…
CVE-2025-8381CVE-2025-8381
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This issue affects some unknown processing …
CVE-2025-8342CVE-2025-8342
CVSS 8.1
The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value check…
CVE-2025-8323CVE-2025-8323
CVSS 8.8
The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereb…
CVE-2025-8322CVE-2025-8322
CVSS 8.8
The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator functions, includi…
CVE-2025-8320CVE-2025-8320
CVSS 8.8
Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …
CVE-2025-8310CVE-2025-8310
CVSS 8.8
Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take…
CVE-2025-8309CVE-2025-8309
CVSS 8.1
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter …
CVE-2025-8302CVE-2025-8302
CVSS 8.8
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca…
CVE-2025-8300CVE-2025-8300
CVSS 8.8
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca…
CVE-2025-8299CVE-2025-8299
CVSS 8.8realtek
Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows…
CVE-2025-8292CVE-2025-8292
CVSS 8.8
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…
CVE-2025-8247CVE-2025-8247
CVSS 8.8
A vulnerability classified as critical has been found in Projectworlds Online Admission System 1.0. This affects an unknown part of the file /admin.php. The ma…
CVE-2025-8230CVE-2025-8230
CVSS 8.8
A vulnerability classified as critical was found in Campcodes Courier Management System 1.0. This vulnerability affects unknown code of the file /manage_user.p…
CVE-2025-8229CVE-2025-8229
CVSS 8.8
A vulnerability classified as critical has been found in Campcodes Courier Management System 1.0. This affects an unknown part of the file /parcel_list.php. Th…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.