91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,551–3,600 of 8,161 in High · page 72 of 164

IDTitleSummary
CVE-2025-7388CVE-2025-7388
CVSS 8.4
It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execut…
CVE-2025-7382CVE-2025-7382
CVSS 8.8
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code e…
CVE-2025-7359CVE-2025-7359
CVSS 8.2
The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wcvisit…
CVE-2025-7347CVE-2025-7347
CVSS 8.8
Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Tracking System allows Exploitation of Trusted…
CVE-2025-7344CVE-2025-7344
CVSS 8.8
The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to adminis…
CVE-2025-7327CVE-2025-7327
CVSS 8.8
The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. …
CVE-2025-7212CVE-2025-7212
CVSS 8.8
A vulnerability was found in itsourcecode Insurance Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing of t…
CVE-2025-7210CVE-2025-7210
CVSS 8.8
A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknown function…
CVE-2025-7194CVE-2025-7194
CVSS 8.8
A vulnerability was found in D-Link DI-500WF 17.04.10A1T. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file …
CVE-2025-7192CVE-2025-7192
CVSS 8.8
A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin o…
CVE-2025-7190CVE-2025-7190
CVSS 8.8
A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/st…
CVE-2025-7189CVE-2025-7189
CVSS 8.8
A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the…
CVE-2025-7188CVE-2025-7188
CVSS 8.8
A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user…
CVE-2025-7187CVE-2025-7187
CVSS 8.8
A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The…
CVE-2025-7186CVE-2025-7186
CVSS 8.8
A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_c…
CVE-2025-7167CVE-2025-7167
CVSS 8.8
A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cat…
CVE-2025-7166CVE-2025-7166
CVSS 8.8
A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an unknown part of the file /single.php. …
CVE-2025-7163CVE-2025-7163
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/add-an…
CVE-2025-7162CVE-2025-7162
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue affects some unknown processing of the fi…
CVE-2025-7161CVE-2025-7161
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-normal…
CVE-2025-7159CVE-2025-7159
CVSS 8.8
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue is some unknown functionality of the f…
CVE-2025-7158CVE-2025-7158
CVSS 8.8
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality…
CVE-2025-7154CVE-2025-7154
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the…
CVE-2025-7152CVE-2025-7152
CVSS 8.8
A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unknown function of the file /admin/candid…
CVE-2025-7151CVE-2025-7151
CVSS 8.8
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file…
CVE-2025-7150CVE-2025-7150
CVSS 8.8
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file…
CVE-2025-7149CVE-2025-7149
CVSS 8.8
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/c…
CVE-2025-7138CVE-2025-7138
CVSS 8.8
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …
CVE-2025-7137CVE-2025-7137
CVSS 8.8
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pan…
CVE-2025-71278CVE-2025-71278
CVSS 8.8
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo…
CVE-2025-71260CVE-2025-71260
CVSS 8.8bmc
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handlin…
CVE-2025-7124CVE-2025-7124
CVSS 8.8
A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown function of the file /dashboard/userprof…
CVE-2025-7121CVE-2025-7121
CVSS 8.8
A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects an unknown part of the file /users/com…
CVE-2025-7118CVE-2025-7118
CVSS 8.8
A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affects some unknown processing of the file …
CVE-2025-7117CVE-2025-7117
CVSS 8.8
A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteLis…
CVE-2025-71057CVE-2025-71057
CVSS 8.2
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via spoofing th…
CVE-2025-71056CVE-2025-71056
CVSS 8.1
Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an…
CVE-2025-70995CVE-2025-70995
CVSS 8.8
An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of upload…
CVE-2025-7098CVE-2025-7098
CVSS 8.8
A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the component …
CVE-2025-7097CVE-2025-7097
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown processing o…
CVE-2025-7096CVE-2025-7096
CVSS 8.8
A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_updat…
CVE-2025-7094CVE-2025-7094
CVSS 8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. Affected by this issue is the function formBSSetSitesurvey of the file /gof…
CVE-2025-7093CVE-2025-7093
CVSS 8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. Affected by this vulnerability is the function formSetLanguage of the fi…
CVE-2025-7092CVE-2025-7092
CVSS 8.8
A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. This vulnerability affects the function formWlanSetupWPS of the file /gofo…
CVE-2025-7091CVE-2025-7091
CVSS 8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. Affected is the function formWlanMP of the file /goform/formWlanMP of …
CVE-2025-7090CVE-2025-7090
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Belkin F9K1122 1.00.33. Affected by this issue is the function formConnectionSetting of th…
CVE-2025-70893CVE-2025-70893
CVSS 8.8
A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fai…
CVE-2025-7089CVE-2025-7089
CVSS 8.8
A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. This issue affects the function formWanTcpipSetup of the file /goform/formWanTc…
CVE-2025-70887CVE-2025-70887
CVSS 8.8
An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components
CVE-2025-7088CVE-2025-7088
CVSS 8.8
A vulnerability, which was classified as critical, was found in Belkin F9K1122 1.00.33. This affects the function formPPPoESetup of the file /goform/formPPPoES…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.