91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,551–3,600 of 8,161 in High · page 72 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-7388 | CVE-2025-7388 CVSS 8.4 | It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject and execut… |
| CVE-2025-7382 | CVE-2025-7382 CVSS 8.8 | A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code e… |
| CVE-2025-7359 | CVE-2025-7359 CVSS 8.2 | The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wcvisit… |
| CVE-2025-7347 | CVE-2025-7347 CVSS 8.8 | Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Tracking System allows Exploitation of Trusted… |
| CVE-2025-7344 | CVE-2025-7344 CVSS 8.8 | The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to adminis… |
| CVE-2025-7327 | CVE-2025-7327 CVSS 8.8 | The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. … |
| CVE-2025-7212 | CVE-2025-7212 CVSS 8.8 | A vulnerability was found in itsourcecode Insurance Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing of t… |
| CVE-2025-7210 | CVE-2025-7210 CVSS 8.8 | A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknown function… |
| CVE-2025-7194 | CVE-2025-7194 CVSS 8.8 | A vulnerability was found in D-Link DI-500WF 17.04.10A1T. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file … |
| CVE-2025-7192 | CVE-2025-7192 CVSS 8.8 | A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin o… |
| CVE-2025-7190 | CVE-2025-7190 CVSS 8.8 | A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/st… |
| CVE-2025-7189 | CVE-2025-7189 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the… |
| CVE-2025-7188 | CVE-2025-7188 CVSS 8.8 | A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user… |
| CVE-2025-7187 | CVE-2025-7187 CVSS 8.8 | A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The… |
| CVE-2025-7186 | CVE-2025-7186 CVSS 8.8 | A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_c… |
| CVE-2025-7167 | CVE-2025-7167 CVSS 8.8 | A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cat… |
| CVE-2025-7166 | CVE-2025-7166 CVSS 8.8 | A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an unknown part of the file /single.php. … |
| CVE-2025-7163 | CVE-2025-7163 CVSS 8.8 | A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/add-an… |
| CVE-2025-7162 | CVE-2025-7162 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue affects some unknown processing of the fi… |
| CVE-2025-7161 | CVE-2025-7161 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-normal… |
| CVE-2025-7159 | CVE-2025-7159 CVSS 8.8 | A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue is some unknown functionality of the f… |
| CVE-2025-7158 | CVE-2025-7158 CVSS 8.8 | A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality… |
| CVE-2025-7154 | CVE-2025-7154 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the… |
| CVE-2025-7152 | CVE-2025-7152 CVSS 8.8 | A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unknown function of the file /admin/candid… |
| CVE-2025-7151 | CVE-2025-7151 CVSS 8.8 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file… |
| CVE-2025-7150 | CVE-2025-7150 CVSS 8.8 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file… |
| CVE-2025-7149 | CVE-2025-7149 CVSS 8.8 | A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/c… |
| CVE-2025-7138 | CVE-2025-7138 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the … |
| CVE-2025-7137 | CVE-2025-7137 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pan… |
| CVE-2025-71278 | CVE-2025-71278 CVSS 8.8 | XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo… |
| CVE-2025-71260 | CVE-2025-71260 CVSS 8.8bmc | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handlin… |
| CVE-2025-7124 | CVE-2025-7124 CVSS 8.8 | A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown function of the file /dashboard/userprof… |
| CVE-2025-7121 | CVE-2025-7121 CVSS 8.8 | A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects an unknown part of the file /users/com… |
| CVE-2025-7118 | CVE-2025-7118 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affects some unknown processing of the file … |
| CVE-2025-7117 | CVE-2025-7117 CVSS 8.8 | A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteLis… |
| CVE-2025-71057 | CVE-2025-71057 CVSS 8.2 | Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via spoofing th… |
| CVE-2025-71056 | CVE-2025-71056 CVSS 8.1 | Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an… |
| CVE-2025-70995 | CVE-2025-70995 CVSS 8.8 | An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of upload… |
| CVE-2025-7098 | CVE-2025-7098 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the component … |
| CVE-2025-7097 | CVE-2025-7097 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown processing o… |
| CVE-2025-7096 | CVE-2025-7096 CVSS 8.8 | A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_updat… |
| CVE-2025-7094 | CVE-2025-7094 CVSS 8.8 | A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. Affected by this issue is the function formBSSetSitesurvey of the file /gof… |
| CVE-2025-7093 | CVE-2025-7093 CVSS 8.8 | A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. Affected by this vulnerability is the function formSetLanguage of the fi… |
| CVE-2025-7092 | CVE-2025-7092 CVSS 8.8 | A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. This vulnerability affects the function formWlanSetupWPS of the file /gofo… |
| CVE-2025-7091 | CVE-2025-7091 CVSS 8.8 | A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. Affected is the function formWlanMP of the file /goform/formWlanMP of … |
| CVE-2025-7090 | CVE-2025-7090 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Belkin F9K1122 1.00.33. Affected by this issue is the function formConnectionSetting of th… |
| CVE-2025-70893 | CVE-2025-70893 CVSS 8.8 | A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fai… |
| CVE-2025-7089 | CVE-2025-7089 CVSS 8.8 | A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. This issue affects the function formWanTcpipSetup of the file /goform/formWanTc… |
| CVE-2025-70887 | CVE-2025-70887 CVSS 8.8 | An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components |
| CVE-2025-7088 | CVE-2025-7088 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Belkin F9K1122 1.00.33. This affects the function formPPPoESetup of the file /goform/formPPPoES… |