91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,751–3,800 of 8,161 in High · page 76 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-69040 | CVE-2025-69040 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bfres bfres allows PHP Loca… |
| CVE-2025-69039 | CVE-2025-69039 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allows PHP Lo… |
| CVE-2025-69038 | CVE-2025-69038 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Hyori hyori allows PHP Loca… |
| CVE-2025-69037 | CVE-2025-69037 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Pippo pippo allows PHP Loca… |
| CVE-2025-69036 | CVE-2025-69036 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life CPT: from n… |
| CVE-2025-69035 | CVE-2025-69035 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injection.This issue affects Dental Care CPT: … |
| CVE-2025-69034 | CVE-2025-69034 CVSS 8.1qodeinteractive | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP… |
| CVE-2025-69005 | CVE-2025-69005 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Search & Go search-and-g… |
| CVE-2025-69004 | CVE-2025-69004 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in XpeedStudio Bajaar - Highly Customizab… |
| CVE-2025-69002 | CVE-2025-69002 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through <= 3.9. |
| CVE-2025-68999 | CVE-2025-68999 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-a… |
| CVE-2025-68990 | CVE-2025-68990 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager a… |
| CVE-2025-6899 | CVE-2025-6899 CVSS 8.8 | A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file m… |
| CVE-2025-6898 | CVE-2025-6898 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionality of the f… |
| CVE-2025-6896 | CVE-2025-6896 CVSS 8.8 | A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The manipulati… |
| CVE-2025-68948 | CVE-2025-68948 CVSS 8.1 | SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded crypto… |
| CVE-2025-68920 | CVE-2025-68920 CVSS 8.9 | C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve a… |
| CVE-2025-68912 | CVE-2025-68912 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms hdforms allows Path Traversal.This issu… |
| CVE-2025-68908 | CVE-2025-68908 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in temash Barberry barberry allows PHP Lo… |
| CVE-2025-68903 | CVE-2025-68903 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0. |
| CVE-2025-68901 | CVE-2025-68901 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affect… |
| CVE-2025-6890 | CVE-2025-6890 CVSS 8.8 | A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /t… |
| CVE-2025-68899 | CVE-2025-68899 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= 2.4. |
| CVE-2025-68881 | CVE-2025-68881 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExperts appexperts allows SQL Injection.Thi… |
| CVE-2025-6887 | CVE-2025-6887 CVSS 8.8 | A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetSysT… |
| CVE-2025-6886 | CVE-2025-6886 CVSS 8.8 | A vulnerability has been found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /gof… |
| CVE-2025-68853 | CVE-2025-68853 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Kleor Contact Manager contact-manager allows Object Injection.This issue affects Contact Manager: from n/a t… |
| CVE-2025-6884 | CVE-2025-6884 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the fi… |
| CVE-2025-6882 | CVE-2025-6882 CVSS 8.8 | A vulnerability classified as critical has been found in D-Link DIR-513 1.0. This affects an unknown part of the file /goform/formSetWanPPTP. The manipulation … |
| CVE-2025-6881 | CVE-2025-6881 CVSS 8.8 | A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pppoe_ba… |
| CVE-2025-6880 | CVE-2025-6880 CVSS 8.8 | A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/ed… |
| CVE-2025-6879 | CVE-2025-6879 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the … |
| CVE-2025-6878 | CVE-2025-6878 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the … |
| CVE-2025-6877 | CVE-2025-6877 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pan… |
| CVE-2025-6876 | CVE-2025-6876 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality o… |
| CVE-2025-6875 | CVE-2025-6875 CVSS 8.8 | A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown func… |
| CVE-2025-6874 | CVE-2025-6874 CVSS 8.8 | A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /p… |
| CVE-2025-68722 | CVE-2025-68722 CVSS 8.8 | Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improp… |
| CVE-2025-68721 | CVE-2025-68721 CVSS 8.1 | Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions … |
| CVE-2025-68719 | CVE-2025-68719 CVSS 8.8 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an attacker ca… |
| CVE-2025-68716 | CVE-2025-68716 CVSS 8.4 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no passwor… |
| CVE-2025-68707 | CVE-2025-68707 CVSS 8.8 | An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated network-adjacent attackers to perform arb… |
| CVE-2025-68700 | CVE-2025-68700 CVSS 8.8infiniflow | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) … |
| CVE-2025-68696 | CVE-2025-68696 CVSS 8.2 | httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow th… |
| CVE-2025-68664 | CVE-2025-68664 CVSS 8.2 | LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists i… |
| CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability KEVCVSS 8.8Synacor | Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/r… |
| CVE-2025-68623 | CVE-2025-68623 CVSS 8.8 | In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process, which may… |
| CVE-2025-6862 | CVE-2025-6862 CVSS 8.8 | A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/ed… |
| CVE-2025-68613 | n8n Improper Control of Dynamically-Managed Code Resources Vulnerability KEVCVSS 8.8n8n | n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code e… |
| CVE-2025-6861 | CVE-2025-6861 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the … |