91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,651–3,700 of 8,161 in High · page 74 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-69627 | CVE-2025-69627 CVSS 8.4gonitro | Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During executio… |
| CVE-2025-69621 | CVE-2025-69621 CVSS 8.1 | An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to overwrite critical internal files, potent… |
| CVE-2025-6953 | CVE-2025-6953 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/form… |
| CVE-2025-69517 | CVE-2025-69517 CVSS 8.8 | An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject arbitrary HTML content during the creatio… |
| CVE-2025-69516 | CVE-2025-69516 CVSS 8.8 | A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or e… |
| CVE-2025-6948 | CVE-2025-6948 CVSS 8.0 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain c… |
| CVE-2025-69437 | CVE-2025-69437 CVSS 8.7 | PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsF… |
| CVE-2025-69410 | CVE-2025-69410 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Belletrist belletrist allo… |
| CVE-2025-69409 | CVE-2025-69409 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes PJ | Life & Business Coach… |
| CVE-2025-69408 | CVE-2025-69408 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes HealthFirst healthfirst … |
| CVE-2025-69407 | CVE-2025-69407 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows… |
| CVE-2025-69406 | CVE-2025-69406 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX FreightCo freightco allows PH… |
| CVE-2025-69402 | CVE-2025-69402 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX R&F rf allows PHP Local File … |
| CVE-2025-69400 | CVE-2025-69400 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Yokoo yokoo allows PHP Local … |
| CVE-2025-6940 | CVE-2025-6940 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of the file… |
| CVE-2025-69399 | CVE-2025-69399 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Cobble cobble allows PHP Loca… |
| CVE-2025-69398 | CVE-2025-69398 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Plank plank allows PHP Local … |
| CVE-2025-69397 | CVE-2025-69397 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tint tint allows PHP Local Fi… |
| CVE-2025-69396 | CVE-2025-69396 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Splendour splendour allows PH… |
| CVE-2025-69395 | CVE-2025-69395 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gable gable allows PHP Local … |
| CVE-2025-6939 | CVE-2025-6939 CVSS 8.8 | A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteS… |
| CVE-2025-69379 | CVE-2025-69379 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows … |
| CVE-2025-69376 | CVE-2025-69376 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Tra… |
| CVE-2025-69375 | CVE-2025-69375 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Portfolio Builder swp-portfol… |
| CVE-2025-69374 | CVE-2025-69374 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Eleblog – Elementor Blog And … |
| CVE-2025-69351 | CVE-2025-69351 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Blind SQ… |
| CVE-2025-69347 | CVE-2025-69347 CVSS 8.6 | Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Access Contr… |
| CVE-2025-69339 | CVE-2025-69339 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in don-themes Molla molla allows PHP Loca… |
| CVE-2025-69328 | CVE-2025-69328 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection… |
| CVE-2025-69322 | CVE-2025-69322 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes PeakShops peakshops allows … |
| CVE-2025-69314 | CVE-2025-69314 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Werkstatt werkstatt allows … |
| CVE-2025-6930 | CVE-2025-6930 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/manage-foreig… |
| CVE-2025-69294 | CVE-2025-69294 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a through <= 1.5… |
| CVE-2025-69293 | CVE-2025-69293 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue affects Final User: from n/a through <= … |
| CVE-2025-69292 | CVE-2025-69292 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a th… |
| CVE-2025-6929 | CVE-2025-6929 CVSS 8.8 | A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /admin… |
| CVE-2025-69276 | CVE-2025-69276 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum:… |
| CVE-2025-69274 | CVE-2025-69274 CVSS 8.8 | Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects … |
| CVE-2025-69263 | CVE-2025-69263 CVSS 7.5pnpm | pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This … |
| CVE-2025-6926 | CVE-2025-6926 CVSS 8.8 | Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - C… |
| CVE-2025-69240 | CVE-2025-69240 CVSS 8.8 | Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) … |
| CVE-2025-69222 | CVE-2025-69222 CVSS 9.1librechat | LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrict… |
| CVE-2025-69219 | CVE-2025-69219 CVSS 8.8 | A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same … |
| CVE-2025-69215 | CVE-2025-69215 CVSS 8.8 | OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability… |
| CVE-2025-69214 | CVE-2025-69214 CVSS 8.8 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQL Injection vulnerability exists in the… |
| CVE-2025-69213 | CVE-2025-69213 CVSS 8.8 | OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists i… |
| CVE-2025-69212 | CVE-2025-69212 CVSS 8.8 | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a critical OS Command Injection vulnerabilit… |
| CVE-2025-69203 | CVE-2025-69203 CVSS 6.3signalk | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features t… |
| CVE-2025-69195 | CVE-2025-69195 CVSS 8.8 | A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled… |
| CVE-2025-69183 | CVE-2025-69183 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Privilege Escalation.This issue affects Ho… |