91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,601–3,650 of 8,161 in High · page 73 of 164

IDTitleSummary
CVE-2025-7087CVE-2025-7087
CVSS 8.8
A vulnerability classified as critical was found in Belkin F9K1122 1.00.33. Affected by this vulnerability is the function formL2TPSetup of the file /goform/fo…
CVE-2025-70866CVE-2025-70866
CVSS 8.8
LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backen…
CVE-2025-7086CVE-2025-7086
CVSS 8.8
A vulnerability classified as critical has been found in Belkin F9K1122 1.00.33. Affected is the function formPPTPSetup of the file /goform/formPPTPSetup of th…
CVE-2025-7085CVE-2025-7085
CVSS 8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. This issue affects the function formiNICWpsStart of the file /goform/formiN…
CVE-2025-7084CVE-2025-7084
CVSS 8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. This vulnerability affects the function formWpsStart of the file /goform…
CVE-2025-7083CVE-2025-7083
CVSS 8.8
A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the component w…
CVE-2025-70828CVE-2025-70828
CVSS 8.8
An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration
CVE-2025-7082CVE-2025-7082
CVSS 8.8
A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this issue is the function formBSSetSitesurvey of the file /goform/…
CVE-2025-70810CVE-2025-70810
CVSS 8.8
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authenticatio…
CVE-2025-7081CVE-2025-7081
CVSS 8.8
A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. Affected by this vulnerability is the function formSetWanStatic of the fil…
CVE-2025-70802CVE-2025-70802
CVSS 8.4
Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in …
CVE-2025-70798CVE-2025-70798
CVSS 8.4
Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as …
CVE-2025-7079CVE-2025-7079
CVSS 8.1
A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing of the fil…
CVE-2025-7077CVE-2025-7077
CVSS 8.8
A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2.2.3.6. This affects the function config_3g_para of t…
CVE-2025-7076CVE-2025-7076
CVSS 8.8
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the f…
CVE-2025-7075CVE-2025-7075
CVSS 8.8
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality…
CVE-2025-7070CVE-2025-7070
CVSS 8.8
A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functionality of …
CVE-2025-70614CVE-2025-70614
CVSS 8.1
OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authentic…
CVE-2025-7060CVE-2025-7060
CVSS 8.1
A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part of the file assets/config/_installation…
CVE-2025-70560CVE-2025-70560
CVSS 8.4
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecul…
CVE-2025-7052CVE-2025-7052
CVSS 8.8
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce valid…
CVE-2025-7051CVE-2025-7051
CVSS 8.3
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerabil…
CVE-2025-7049CVE-2025-7049
CVSS 8.8
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ…
CVE-2025-70420CVE-2025-70420Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a sec…
CVE-2025-7040CVE-2025-7040
CVSS 8.2
The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings'…
CVE-2025-7038CVE-2025-7038
CVSS 8.2
The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the la…
CVE-2025-70364CVE-2025-70364
CVSS 8.8
An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Supplier's p…
CVE-2025-70329CVE-2025-70329
CVSS 8.0
TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlan…
CVE-2025-70328CVE-2025-70328
CVSS 8.8
TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The h…
CVE-2025-70298CVE-2025-70298
CVSS 8.2
GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.
CVE-2025-7029CVE-2025-7029
CVSS 8.2
A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHea…
CVE-2025-7027CVE-2025-7027
CVSS 8.2
A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and write addresses used by the CommandRcx1…
CVE-2025-7026CVE-2025-7026
CVSS 8.2
A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer i…
CVE-2025-70151CVE-2025-70151
CVSS 8.8fabian
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update…
CVE-2025-7014CVE-2025-7014
CVSS 5.7qrmenumpro
Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affects Menu Panel: through 29012026.  NOTE:…
CVE-2025-70064CVE-2025-70064
CVSS 8.8
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator…
CVE-2025-70038CVE-2025-70038
CVSS 8.8
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attacker…
CVE-2025-70031CVE-2025-70031
CVSS 8.8
An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CVE-2025-6996CVE-2025-6996
CVSS 8.4
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker…
CVE-2025-6995CVE-2025-6995
CVSS 8.4
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker…
CVE-2025-6993CVE-2025-6993
CVSS 8.8
The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler i…
CVE-2025-69906CVE-2025-69906
CVSS 8.8
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension valida…
CVE-2025-6990CVE-2025-6990
CVSS 8.8
The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via the `TH_PhpCode` pagebuilder widget. T…
CVE-2025-6989CVE-2025-6989
CVSS 8.1
The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in all versio…
CVE-2025-69871CVE-2025-69871
CVSS 8.1
A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a n…
CVE-2025-6979CVE-2025-6979
CVSS 8.8
Captive Portal can allow authentication bypass
CVE-2025-69784CVE-2025-69784
CVSS 8.8
A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by t…
CVE-2025-69689CVE-2025-69689
CVSS 8.8
The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied paths with e…
CVE-2025-6967CVE-2025-6967
CVSS 8.7
Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScr…
CVE-2025-69662CVE-2025-69662
CVSS 8.6
SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write G…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.