91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,401–3,450 of 8,161 in High · page 69 of 164

IDTitleSummary
CVE-2025-8029CVE-2025-8029
CVSS 8.1mozilla
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 14…
CVE-2025-8020CVE-2025-8020
CVSS 8.2
All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that resolves to a …
CVE-2025-8019CVE-2025-8019
CVSS 8.8
A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected by this issue is the function sub_40B6F…
CVE-2025-8018CVE-2025-8018
CVSS 8.8
A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown func…
CVE-2025-8017CVE-2025-8017
CVSS 8.8
A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSetMacFilterCfg of the file /goform/setMac…
CVE-2025-8011CVE-2025-8011
CVSS 8.8
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…
CVE-2025-8010CVE-2025-8010
CVSS 8.8
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…
CVE-2025-7954CVE-2025-7954
CVSS 8.1
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrict…
CVE-2025-7952CVE-2025-7952
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. This vulnerability affects the function ckeckKeepAlive of the file wireless.so of …
CVE-2025-7947CVE-2025-7947
CVSS 8.1
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Ha…
CVE-2025-7945CVE-2025-7945
CVSS 8.8
A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the…
CVE-2025-7939CVE-2025-7939
CVSS 8.8
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of the file GoodsCo…
CVE-2025-7936CVE-2025-7936
CVSS 8.8
A vulnerability has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a and classified as critical. Affected by this vulnera…
CVE-2025-7935CVE-2025-7935
CVSS 8.8
A vulnerability, which was classified as critical, was found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a. Affected is the funct…
CVE-2025-7934CVE-2025-7934
CVSS 8.8
A vulnerability, which was classified as critical, has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a. This issue affec…
CVE-2025-7932CVE-2025-7932
CVSS 8.8
A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldbc_system of the file ssdpcgi. The manip…
CVE-2025-7927CVE-2025-7927
CVSS 8.8
A vulnerability has been found in PHPGurukul Online Banquet Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file …
CVE-2025-7914CVE-2025-7914
CVSS 8.8
A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the …
CVE-2025-7913CVE-2025-7913
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function updateWifiInfo of the component MQT…
CVE-2025-7912CVE-2025-7912
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affects the function recvSlaveUpgstatus of t…
CVE-2025-7910CVE-2025-7910
CVSS 8.8
A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the file /goform/formSetWanNonLogin of the c…
CVE-2025-7909CVE-2025-7909
CVSS 8.8
A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function sprintf of the file /goform/formLanSetup…
CVE-2025-7908CVE-2025-7908
CVSS 8.8
A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file /ddns.asp…
CVE-2025-7905CVE-2025-7905
CVSS 8.8
A vulnerability has been found in itsourcecode Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …
CVE-2025-7904CVE-2025-7904
CVSS 8.8
A vulnerability, which was classified as critical, was found in itsourcecode Insurance Management System 1.0. This affects an unknown part of the file /insertN…
CVE-2025-7880CVE-2025-7880
CVSS 8.8
A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality of the file /bu…
CVE-2025-7878CVE-2025-7878
CVSS 8.8
A vulnerability, which was classified as critical, was found in Metasoft 美特软件 MetaCRM up to 6.4.2. Affected is an unknown function of the file /common/jsp/uplo…
CVE-2025-7855CVE-2025-7855
CVSS 8.8
A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromqossetting of the file /goform/qoss…
CVE-2025-7854CVE-2025-7854
CVSS 8.8
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manip…
CVE-2025-7853CVE-2025-7853
CVSS 8.8
A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. T…
CVE-2025-7847CVE-2025-7847
CVSS 8.8
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versi…
CVE-2025-7846CVE-2025-7846
CVSS 8.8
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() fun…
CVE-2025-7837CVE-2025-7837
CVSS 8.8
A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the compo…
CVE-2025-7836CVE-2025-7836
CVSS 8.8
A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_system of th…
CVE-2025-7812CVE-2025-7812
CVSS 8.8
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …
CVE-2025-7807CVE-2025-7807
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. This issue affects the function fromSafeUrlFilter of the file /goform…
CVE-2025-7806CVE-2025-7806
CVSS 8.8
A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeC…
CVE-2025-7805CVE-2025-7805
CVSS 8.8
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserSetting of the file /goform/PPTPUserSetting…
CVE-2025-7799CVE-2025-7799
CVSS 8.6
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Acc…
CVE-2025-7796CVE-2025-7796
CVSS 8.8
A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserAdd of the file /goform/PPTPDClient.…
CVE-2025-7795CVE-2025-7795
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file …
CVE-2025-7794CVE-2025-7794
CVSS 8.8
A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromNatStaticSetting of the file /gofor…
CVE-2025-7793CVE-2025-7793
CVSS 8.8
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary. T…
CVE-2025-7792CVE-2025-7792
CVSS 8.8
A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function formSafeEmailFilter of the file /goform/SafeEm…
CVE-2025-7788CVE-2025-7788
CVSS 8.8
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of t…
CVE-2025-7787CVE-2025-7787
CVSS 8.8
A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\…
CVE-2025-7779CVE-2025-7779
CVSS 8.8
Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acron…
CVE-2025-7766CVE-2025-7766
CVSS 8.0
Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remo…
CVE-2025-7759CVE-2025-7759
CVSS 8.8
A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/jeesite/com…
CVE-2025-7758CVE-2025-7758
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected by this issue is the function setDiagnos…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.