91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,351–3,400 of 8,161 in High · page 68 of 164

IDTitleSummary
CVE-2025-8228CVE-2025-8228
CVSS 8.8
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function getPages of the file /cms/…
CVE-2025-8218CVE-2025-8218
CVSS 8.8
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all …
CVE-2025-8190CVE-2025-8190
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Campcodes Courier Management System 1.0. This issue affects some unknown processing of the…
CVE-2025-8189CVE-2025-8189
CVSS 8.8
A vulnerability classified as critical was found in Campcodes Courier Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php…
CVE-2025-8188CVE-2025-8188
CVSS 8.8
A vulnerability classified as critical has been found in Campcodes Courier Management System 1.0. This affects an unknown part of the file /edit_staff.php. The…
CVE-2025-8187CVE-2025-8187
CVSS 8.8
A vulnerability was found in Campcodes Courier Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of th…
CVE-2025-8186CVE-2025-8186
CVSS 8.8
A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functional…
CVE-2025-8180CVE-2025-8180
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formdeleteUserName of the file …
CVE-2025-8178CVE-2025-8178
CVSS 8.8
A vulnerability classified as critical has been found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /goform/RequestsProcessLaid. The m…
CVE-2025-8172CVE-2025-8172
CVSS 8.8
A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System 1.0. Affected is an unknown function of the file /admin…
CVE-2025-8170CVE-2025-8170
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerability affects the function tcpcheck_net of the file /router…
CVE-2025-8165CVE-2025-8165
CVSS 8.8
A vulnerability was found in code-projects Food Review System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/app…
CVE-2025-8164CVE-2025-8164
CVSS 8.8
A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affects unknown code of the file send_messa…
CVE-2025-8163CVE-2025-8163
CVSS 8.8
A vulnerability, which was classified as critical, was found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/role/list. The m…
CVE-2025-8162CVE-2025-8162
CVSS 8.8
A vulnerability, which was classified as critical, has been found in deerwms deer-wms-2 up to 3.3. Affected by this issue is some unknown functionality of the …
CVE-2025-8161CVE-2025-8161
CVSS 8.8
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. Affected by this vulnerability is an unknown functionality of the file /syste…
CVE-2025-8160CVE-2025-8160
CVSS 8.8
A vulnerability classified as critical has been found in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/SetSysTimeCfg of the…
CVE-2025-8145CVE-2025-8145
CVSS 8.8
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization o…
CVE-2025-8142CVE-2025-8142
CVSS 8.8
The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes…
CVE-2025-8141CVE-2025-8141
CVSS 8.8
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associa…
CVE-2025-8140CVE-2025-8140
CVSS 8.8
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm…
CVE-2025-8139CVE-2025-8139
CVSS 8.8
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been classified as critical. This affects an unknown part of the file /boafrm/formPort…
CVE-2025-8138CVE-2025-8138
CVSS 8.8
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this issue is some unknown functionality of the file /…
CVE-2025-8137CVE-2025-8137
CVSS 8.8
A vulnerability has been found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this vulnerability is an unknown functionality of…
CVE-2025-8135CVE-2025-8135
CVSS 8.8
A vulnerability, which was classified as critical, has been found in itsourcecode Insurance Management System 1.0. This issue affects some unknown processing o…
CVE-2025-8134CVE-2025-8134
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability affects unknown code of the file /bwdate…
CVE-2025-8131CVE-2025-8131
CVSS 8.8
A vulnerability was found in Tenda AC20 16.03.08.05. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /…
CVE-2025-8127CVE-2025-8127
CVSS 8.8
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. This vulnerability affects unknown code of the file /system/user/list. The ma…
CVE-2025-8126CVE-2025-8126
CVSS 8.8
A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipu…
CVE-2025-8124CVE-2025-8124
CVSS 8.8
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …
CVE-2025-8123CVE-2025-8123
CVSS 8.8
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. T…
CVE-2025-8122CVE-2025-8122
CVSS 8.8
Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This issue affects…
CVE-2025-8121CVE-2025-8121
CVSS 8.8
Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This issue affects…
CVE-2025-8110Gogs Path Traversal Vulnerability
KEVCVSS 8.8Gogs
Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
CVE-2025-8109CVE-2025-8109
CVSS 8.8
Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory.
CVE-2025-8093CVE-2025-8093
CVSS 8.8authenticator_login_project
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authentica…
CVE-2025-8088RARLAB WinRAR Path Traversal Vulnerability
KEVCVSS 8.8RARLAB
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary …
CVE-2025-8085CVE-2025-8085
CVSS 8.6metaphorcreations
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors t…
CVE-2025-8083CVE-2025-8083
CVSS 8.6
The Preset configuration https://v2.vuetifyjs.com/en/features/presets  feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp…
CVE-2025-8067CVE-2025-8067
CVSS 8.5
A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device h…
CVE-2025-8060CVE-2025-8060
CVSS 8.8
A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /gof…
CVE-2025-8052CVE-2025-8052
CVSS 8.8opentext
SQL Injection vulnerability in opentext Flipper allows SQL Injection.  The vulnerability could allow a low privilege user to interact with the database in uni…
CVE-2025-8049CVE-2025-8049
CVSS 8.8opentext
Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Access Control Security Levels. The vulne…
CVE-2025-8040CVE-2025-8040
CVSS 8.8mozilla
Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruptio…
CVE-2025-8039CVE-2025-8039
CVSS 8.1mozilla
In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR 1…
CVE-2025-8036CVE-2025-8036
CVSS 8.1mozilla
Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Fire…
CVE-2025-8035CVE-2025-8035
CVSS 8.8mozilla
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of th…
CVE-2025-8034CVE-2025-8034
CVSS 8.8mozilla
Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunder…
CVE-2025-8032CVE-2025-8032
CVSS 8.1mozilla
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, …
CVE-2025-8030CVE-2025-8030
CVSS 8.1mozilla
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in F…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.