91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,601–3,650 of 8,161 in High · page 73 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-7087 | CVE-2025-7087 CVSS 8.8 | A vulnerability classified as critical was found in Belkin F9K1122 1.00.33. Affected by this vulnerability is the function formL2TPSetup of the file /goform/fo… |
| CVE-2025-70866 | CVE-2025-70866 CVSS 8.8 | LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backen… |
| CVE-2025-7086 | CVE-2025-7086 CVSS 8.8 | A vulnerability classified as critical has been found in Belkin F9K1122 1.00.33. Affected is the function formPPTPSetup of the file /goform/formPPTPSetup of th… |
| CVE-2025-7085 | CVE-2025-7085 CVSS 8.8 | A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. This issue affects the function formiNICWpsStart of the file /goform/formiN… |
| CVE-2025-7084 | CVE-2025-7084 CVSS 8.8 | A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. This vulnerability affects the function formWpsStart of the file /goform… |
| CVE-2025-7083 | CVE-2025-7083 CVSS 8.8 | A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the component w… |
| CVE-2025-70828 | CVE-2025-70828 CVSS 8.8 | An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration |
| CVE-2025-7082 | CVE-2025-7082 CVSS 8.8 | A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this issue is the function formBSSetSitesurvey of the file /goform/… |
| CVE-2025-70810 | CVE-2025-70810 CVSS 8.8 | Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authenticatio… |
| CVE-2025-7081 | CVE-2025-7081 CVSS 8.8 | A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this vulnerability is the function formSetWanStatic of the fil… |
| CVE-2025-70802 | CVE-2025-70802 CVSS 8.4 | Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in … |
| CVE-2025-70798 | CVE-2025-70798 CVSS 8.4 | Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as … |
| CVE-2025-7079 | CVE-2025-7079 CVSS 8.1 | A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing of the fil… |
| CVE-2025-7077 | CVE-2025-7077 CVSS 8.8 | A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2.2.3.6. This affects the function config_3g_para of t… |
| CVE-2025-7076 | CVE-2025-7076 CVSS 8.8 | A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the f… |
| CVE-2025-7075 | CVE-2025-7075 CVSS 8.8 | A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality… |
| CVE-2025-7070 | CVE-2025-7070 CVSS 8.8 | A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of … |
| CVE-2025-70614 | CVE-2025-70614 CVSS 8.1 | OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authentic… |
| CVE-2025-7060 | CVE-2025-7060 CVSS 8.1 | A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part of the file assets/config/_installation… |
| CVE-2025-70560 | CVE-2025-70560 CVSS 8.4 | Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecul… |
| CVE-2025-7052 | CVE-2025-7052 CVSS 8.8 | The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce valid… |
| CVE-2025-7051 | CVE-2025-7051 CVSS 8.3 | On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerabil… |
| CVE-2025-7049 | CVE-2025-7049 CVSS 8.8 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ… |
| CVE-2025-70420 | CVE-2025-70420 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a sec… |
| CVE-2025-7040 | CVE-2025-7040 CVSS 8.2 | The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings'… |
| CVE-2025-7038 | CVE-2025-7038 CVSS 8.2 | The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the la… |
| CVE-2025-70364 | CVE-2025-70364 CVSS 8.8 | An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Supplier's p… |
| CVE-2025-70329 | CVE-2025-70329 CVSS 8.0 | TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlan… |
| CVE-2025-70328 | CVE-2025-70328 CVSS 8.8 | TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The h… |
| CVE-2025-70298 | CVE-2025-70298 CVSS 8.2 | GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function. |
| CVE-2025-7029 | CVE-2025-7029 CVSS 8.2 | A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHea… |
| CVE-2025-7027 | CVE-2025-7027 CVSS 8.2 | A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and write addresses used by the CommandRcx1… |
| CVE-2025-7026 | CVE-2025-7026 CVSS 8.2 | A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer i… |
| CVE-2025-70151 | CVE-2025-70151 CVSS 8.8fabian | code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update… |
| CVE-2025-7014 | CVE-2025-7014 CVSS 5.7qrmenumpro | Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affects Menu Panel: through 29012026. NOTE:… |
| CVE-2025-70064 | CVE-2025-70064 CVSS 8.8 | PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator… |
| CVE-2025-70038 | CVE-2025-70038 CVSS 8.8 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attacker… |
| CVE-2025-70031 | CVE-2025-70031 CVSS 8.8 | An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. |
| CVE-2025-6996 | CVE-2025-6996 CVSS 8.4 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker… |
| CVE-2025-6995 | CVE-2025-6995 CVSS 8.4 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker… |
| CVE-2025-6993 | CVE-2025-6993 CVSS 8.8 | The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler i… |
| CVE-2025-69906 | CVE-2025-69906 CVSS 8.8 | Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension valida… |
| CVE-2025-6990 | CVE-2025-6990 CVSS 8.8 | The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via the `TH_PhpCode` pagebuilder widget. T… |
| CVE-2025-6989 | CVE-2025-6989 CVSS 8.1 | The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in all versio… |
| CVE-2025-69871 | CVE-2025-69871 CVSS 8.1 | A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a n… |
| CVE-2025-6979 | CVE-2025-6979 CVSS 8.8 | Captive Portal can allow authentication bypass |
| CVE-2025-69784 | CVE-2025-69784 CVSS 8.8 | A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by t… |
| CVE-2025-69689 | CVE-2025-69689 CVSS 8.8 | The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied paths with e… |
| CVE-2025-6967 | CVE-2025-6967 CVSS 8.7 | Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScr… |
| CVE-2025-69662 | CVE-2025-69662 CVSS 8.6 | SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write G… |