91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,801–3,850 of 8,161 in High · page 77 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-6860 | CVE-2025-6860 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the … |
| CVE-2025-6859 | CVE-2025-6859 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pan… |
| CVE-2025-6855 | CVE-2025-6855 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing … |
| CVE-2025-68545 | CVE-2025-68545 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local Fil… |
| CVE-2025-68543 | CVE-2025-68543 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local Fil… |
| CVE-2025-68539 | CVE-2025-68539 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local Fil… |
| CVE-2025-68536 | CVE-2025-68536 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local Fil… |
| CVE-2025-68531 | CVE-2025-68531 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Object Injecti… |
| CVE-2025-68526 | CVE-2025-68526 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n… |
| CVE-2025-68519 | CVE-2025-68519 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce al… |
| CVE-2025-68510 | CVE-2025-68510 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeGoods Photography photography all… |
| CVE-2025-68506 | CVE-2025-68506 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache docket-cach… |
| CVE-2025-6850 | CVE-2025-6850 CVSS 8.8 | A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the … |
| CVE-2025-68493 | CVE-2025-68493 CVSS 8.1apache | Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 thr… |
| CVE-2025-68481 | CVE-2025-68481 CVSS 8.8 | FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tok… |
| CVE-2025-6848 | CVE-2025-6848 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /fo… |
| CVE-2025-68473 | CVE-2025-68473 CVSS 8.6espressif | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the ESP-IDF Bluetooth h… |
| CVE-2025-68454 | CVE-2025-68454 CVSS 8.8craftcms | Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated… |
| CVE-2025-68434 | CVE-2025-68434 CVSS 8.8 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and pr… |
| CVE-2025-68400 | CVE-2025-68400 CVSS 8.8 | ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Reports/ConfirmReportEmail.php` in ChurchCR… |
| CVE-2025-6829 | CVE-2025-6829 CVSS 8.8 | A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function ou… |
| CVE-2025-68278 | CVE-2025-68278 CVSS 8.8ssw | Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers tha… |
| CVE-2025-6825 | CVE-2025-6825 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK A702R up to 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of th… |
| CVE-2025-68158 | CVE-2025-68158 CVSS 8.8 | Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tie… |
| CVE-2025-68154 | CVE-2025-68154 CVSS 8.1systeminformation | systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable … |
| CVE-2025-68147 | CVE-2025-68147 CVSS 8.1 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and pr… |
| CVE-2025-68143 | CVE-2025-68143 CVSS 8.8lfprojects | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25… |
| CVE-2025-68137 | CVE-2025-68137 CVSS 8.3 | EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer le… |
| CVE-2025-6813 | CVE-2025-6813 CVSS 8.8 | The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versi… |
| CVE-2025-68112 | CVE-2025-68112 CVSS 8.8 | ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability in ChurchCRM's Event Attendee Editor allows aut… |
| CVE-2025-68110 | CVE-2025-68110 CVSS 8.8 | ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an error message including the host, ip, use… |
| CVE-2025-68056 | CVE-2025-68056 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allo… |
| CVE-2025-68055 | CVE-2025-68055 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection… |
| CVE-2025-68054 | CVE-2025-68054 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Background cou… |
| CVE-2025-68053 | CVE-2025-68053 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows Blind SQL … |
| CVE-2025-68047 | CVE-2025-68047 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= … |
| CVE-2025-68044 | CVE-2025-68044 CVSS 8.6 | Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorr… |
| CVE-2025-67998 | CVE-2025-67998 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-el allows Authentication Abuse.This issu… |
| CVE-2025-67992 | CVE-2025-67992 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean PatioTime patiotime allows P… |
| CVE-2025-67988 | CVE-2025-67988 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean CozyStay cozystay allows PHP… |
| CVE-2025-67987 | CVE-2025-67987 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-ne… |
| CVE-2025-67982 | CVE-2025-67982 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local Fil… |
| CVE-2025-67981 | CVE-2025-67981 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local Fil… |
| CVE-2025-67980 | CVE-2025-67980 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local Fil… |
| CVE-2025-67977 | CVE-2025-67977 CVSS 8.2 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security L… |
| CVE-2025-67966 | CVE-2025-67966 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.This issue affects Lawyer Directory: fr… |
| CVE-2025-67963 | CVE-2025-67963 CVSS 8.6 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ovatheme Movie Booking movie-booking allows Path Traversal.This… |
| CVE-2025-67957 | CVE-2025-67957 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP Listivo Core listivo-core a… |
| CVE-2025-67956 | CVE-2025-67956 CVSS 8.2 | Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.Th… |
| CVE-2025-67953 | CVE-2025-67953 CVSS 8.1 | Incorrect Privilege Assignment vulnerability in Booking Activities Team Booking Activities booking-activities allows Privilege Escalation.This issue affects Bo… |