91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,751–3,800 of 8,161 in High · page 76 of 164

IDTitleSummary
CVE-2025-69040CVE-2025-69040
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bfres bfres allows PHP Loca…
CVE-2025-69039CVE-2025-69039
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allows PHP Lo…
CVE-2025-69038CVE-2025-69038
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Hyori hyori allows PHP Loca…
CVE-2025-69037CVE-2025-69037
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Pippo pippo allows PHP Loca…
CVE-2025-69036CVE-2025-69036
CVSS 8.8
Deserialization of Untrusted Data vulnerability in strongholdthemes Tech Life CPT techlife-cpt allows Object Injection.This issue affects Tech Life CPT: from n…
CVE-2025-69035CVE-2025-69035
CVSS 8.8
Deserialization of Untrusted Data vulnerability in strongholdthemes Dental Care CPT dentalcare-cpt allows Object Injection.This issue affects Dental Care CPT: …
CVE-2025-69034CVE-2025-69034
CVSS 8.1qodeinteractive
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP…
CVE-2025-69005CVE-2025-69005
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Search & Go search-and-g…
CVE-2025-69004CVE-2025-69004
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in XpeedStudio Bajaar - Highly Customizab…
CVE-2025-69002CVE-2025-69002
CVSS 8.8
Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through <= 3.9.
CVE-2025-68999CVE-2025-68999
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-a…
CVE-2025-68990CVE-2025-68990
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager a…
CVE-2025-6899CVE-2025-6899
CVSS 8.8
A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file m…
CVE-2025-6898CVE-2025-6898
CVSS 8.8
A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionality of the f…
CVE-2025-6896CVE-2025-6896
CVSS 8.8
A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The manipulati…
CVE-2025-68948CVE-2025-68948
CVSS 8.1
SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded crypto…
CVE-2025-68920CVE-2025-68920
CVSS 8.9
C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve a…
CVE-2025-68912CVE-2025-68912
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Harmonic Design HDForms hdforms allows Path Traversal.This issu…
CVE-2025-68908CVE-2025-68908
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in temash Barberry barberry allows PHP Lo…
CVE-2025-68903CVE-2025-68903
CVSS 8.8
Deserialization of Untrusted Data vulnerability in AivahThemes Anona anona allows Object Injection.This issue affects Anona: from n/a through <= 8.0.
CVE-2025-68901CVE-2025-68901
CVSS 8.6
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona allows Path Traversal.This issue affect…
CVE-2025-6890CVE-2025-6890
CVSS 8.8
A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /t…
CVE-2025-68899CVE-2025-68899
CVSS 8.8
Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= 2.4.
CVE-2025-68881CVE-2025-68881
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal AppExperts appexperts allows SQL Injection.Thi…
CVE-2025-6887CVE-2025-6887
CVSS 8.8
A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetSysT…
CVE-2025-6886CVE-2025-6886
CVSS 8.8
A vulnerability has been found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /gof…
CVE-2025-68853CVE-2025-68853
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Kleor Contact Manager contact-manager allows Object Injection.This issue affects Contact Manager: from n/a t…
CVE-2025-6884CVE-2025-6884
CVSS 8.8
A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the fi…
CVE-2025-6882CVE-2025-6882
CVSS 8.8
A vulnerability classified as critical has been found in D-Link DIR-513 1.0. This affects an unknown part of the file /goform/formSetWanPPTP. The manipulation …
CVE-2025-6881CVE-2025-6881
CVSS 8.8
A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pppoe_ba…
CVE-2025-6880CVE-2025-6880
CVSS 8.8
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/ed…
CVE-2025-6879CVE-2025-6879
CVSS 8.8
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …
CVE-2025-6878CVE-2025-6878
CVSS 8.8
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …
CVE-2025-6877CVE-2025-6877
CVSS 8.8
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pan…
CVE-2025-6876CVE-2025-6876
CVSS 8.8
A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality o…
CVE-2025-6875CVE-2025-6875
CVSS 8.8
A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown func…
CVE-2025-6874CVE-2025-6874
CVSS 8.8
A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /p…
CVE-2025-68722CVE-2025-68722
CVSS 8.8
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improp…
CVE-2025-68721CVE-2025-68721
CVSS 8.1
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions …
CVE-2025-68719CVE-2025-68719
CVSS 8.8
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an attacker ca…
CVE-2025-68716CVE-2025-68716
CVSS 8.4
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no passwor…
CVE-2025-68707CVE-2025-68707
CVSS 8.8
An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated network-adjacent attackers to perform arb…
CVE-2025-68700CVE-2025-68700
CVSS 8.8infiniflow
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) …
CVE-2025-68696CVE-2025-68696
CVSS 8.2
httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow th…
CVE-2025-68664CVE-2025-68664
CVSS 8.2
LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists i…
CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
KEVCVSS 8.8Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/r…
CVE-2025-68623CVE-2025-68623
CVSS 8.8
In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process, which may…
CVE-2025-6862CVE-2025-6862
CVSS 8.8
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/ed…
CVE-2025-68613n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
KEVCVSS 8.8n8n
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code e…
CVE-2025-6861CVE-2025-6861
CVSS 8.8
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.