91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,401–3,450 of 8,161 in High · page 69 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-8029 | CVE-2025-8029 CVSS 8.1mozilla | Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 14… |
| CVE-2025-8020 | CVE-2025-8020 CVSS 8.2 | All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that resolves to a … |
| CVE-2025-8019 | CVE-2025-8019 CVSS 8.8 | A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected by this issue is the function sub_40B6F… |
| CVE-2025-8018 | CVE-2025-8018 CVSS 8.8 | A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown func… |
| CVE-2025-8017 | CVE-2025-8017 CVSS 8.8 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSetMacFilterCfg of the file /goform/setMac… |
| CVE-2025-8011 | CVE-2025-8011 CVSS 8.8 | Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
| CVE-2025-8010 | CVE-2025-8010 CVSS 8.8 | Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
| CVE-2025-7954 | CVE-2025-7954 CVSS 8.1 | A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrict… |
| CVE-2025-7952 | CVE-2025-7952 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. This vulnerability affects the function ckeckKeepAlive of the file wireless.so of … |
| CVE-2025-7947 | CVE-2025-7947 CVSS 8.1 | A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Ha… |
| CVE-2025-7945 | CVE-2025-7945 CVSS 8.8 | A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the… |
| CVE-2025-7939 | CVE-2025-7939 CVSS 8.8 | A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of the file GoodsCo… |
| CVE-2025-7936 | CVE-2025-7936 CVSS 8.8 | A vulnerability has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a and classified as critical. Affected by this vulnera… |
| CVE-2025-7935 | CVE-2025-7935 CVSS 8.8 | A vulnerability, which was classified as critical, was found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a. Affected is the funct… |
| CVE-2025-7934 | CVE-2025-7934 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a. This issue affec… |
| CVE-2025-7932 | CVE-2025-7932 CVSS 8.8 | A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldbc_system of the file ssdpcgi. The manip… |
| CVE-2025-7927 | CVE-2025-7927 CVSS 8.8 | A vulnerability has been found in PHPGurukul Online Banquet Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file … |
| CVE-2025-7914 | CVE-2025-7914 CVSS 8.8 | A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the … |
| CVE-2025-7913 | CVE-2025-7913 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function updateWifiInfo of the component MQT… |
| CVE-2025-7912 | CVE-2025-7912 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affects the function recvSlaveUpgstatus of t… |
| CVE-2025-7910 | CVE-2025-7910 CVSS 8.8 | A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the file /goform/formSetWanNonLogin of the c… |
| CVE-2025-7909 | CVE-2025-7909 CVSS 8.8 | A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function sprintf of the file /goform/formLanSetup… |
| CVE-2025-7908 | CVE-2025-7908 CVSS 8.8 | A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file /ddns.asp… |
| CVE-2025-7905 | CVE-2025-7905 CVSS 8.8 | A vulnerability has been found in itsourcecode Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file … |
| CVE-2025-7904 | CVE-2025-7904 CVSS 8.8 | A vulnerability, which was classified as critical, was found in itsourcecode Insurance Management System 1.0. This affects an unknown part of the file /insertN… |
| CVE-2025-7880 | CVE-2025-7880 CVSS 8.8 | A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality of the file /bu… |
| CVE-2025-7878 | CVE-2025-7878 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Metasoft 美特软件 MetaCRM up to 6.4.2. Affected is an unknown function of the file /common/jsp/uplo… |
| CVE-2025-7855 | CVE-2025-7855 CVSS 8.8 | A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromqossetting of the file /goform/qoss… |
| CVE-2025-7854 | CVE-2025-7854 CVSS 8.8 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manip… |
| CVE-2025-7853 | CVE-2025-7853 CVSS 8.8 | A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. T… |
| CVE-2025-7847 | CVE-2025-7847 CVSS 8.8 | The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versi… |
| CVE-2025-7846 | CVE-2025-7846 CVSS 8.8 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() fun… |
| CVE-2025-7837 | CVE-2025-7837 CVSS 8.8 | A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the compo… |
| CVE-2025-7836 | CVE-2025-7836 CVSS 8.8 | A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_system of th… |
| CVE-2025-7812 | CVE-2025-7812 CVSS 8.8 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … |
| CVE-2025-7807 | CVE-2025-7807 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. This issue affects the function fromSafeUrlFilter of the file /goform… |
| CVE-2025-7806 | CVE-2025-7806 CVSS 8.8 | A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeC… |
| CVE-2025-7805 | CVE-2025-7805 CVSS 8.8 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserSetting of the file /goform/PPTPUserSetting… |
| CVE-2025-7799 | CVE-2025-7799 CVSS 8.6 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Acc… |
| CVE-2025-7796 | CVE-2025-7796 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserAdd of the file /goform/PPTPDClient.… |
| CVE-2025-7795 | CVE-2025-7795 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file … |
| CVE-2025-7794 | CVE-2025-7794 CVSS 8.8 | A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromNatStaticSetting of the file /gofor… |
| CVE-2025-7793 | CVE-2025-7793 CVSS 8.8 | A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary. T… |
| CVE-2025-7792 | CVE-2025-7792 CVSS 8.8 | A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function formSafeEmailFilter of the file /goform/SafeEm… |
| CVE-2025-7788 | CVE-2025-7788 CVSS 8.8 | A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of t… |
| CVE-2025-7787 | CVE-2025-7787 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\… |
| CVE-2025-7779 | CVE-2025-7779 CVSS 8.8 | Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acron… |
| CVE-2025-7766 | CVE-2025-7766 CVSS 8.0 | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remo… |
| CVE-2025-7759 | CVE-2025-7759 CVSS 8.8 | A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/jeesite/com… |
| CVE-2025-7758 | CVE-2025-7758 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected by this issue is the function setDiagnos… |