91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,851–3,900 of 8,161 in High · page 78 of 164

IDTitleSummary
CVE-2025-67950CVE-2025-67950
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In One SEO Pack all-in-one-seo-pack allow…
CVE-2025-67946CVE-2025-67946
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scriptsbundle AdForest adforest allows…
CVE-2025-67941CVE-2025-67941
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes The Aisle theaisle allow…
CVE-2025-67940CVE-2025-67940
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Powerlift powerlift allo…
CVE-2025-67938CVE-2025-67938
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Biagiotti biagiotti allo…
CVE-2025-67937CVE-2025-67937
CVSS 8.1qodeinteractive
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon allows PHP…
CVE-2025-67936CVE-2025-67936
CVSS 8.1qodeinteractive
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly allows PHP L…
CVE-2025-67935CVE-2025-67935
CVSS 8.1qodeinteractive
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allo…
CVE-2025-67934CVE-2025-67934
CVSS 8.1qodeinteractive
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring wellspring al…
CVE-2025-67921CVE-2025-67921
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.This issue…
CVE-2025-67920CVE-2025-67920
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Neo Ocular neoocular all…
CVE-2025-67915CVE-2025-67915
CVSS 8.8
Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: …
CVE-2025-6791CVE-2025-6791
CVSS 8.8
In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Spec…
CVE-2025-67905CVE-2025-67905
CVSS 8.7
Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllab…
CVE-2025-67900CVE-2025-67900
CVSS 8.1
NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
CVE-2025-67877CVE-2025-67877
CVSS 8.8
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the `src/CartToFamily.php` file, specifical…
CVE-2025-67848CVE-2025-67848
CVSS 8.1
A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) P…
CVE-2025-67847CVE-2025-67847
CVSS 8.8
A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient…
CVE-2025-67823CVE-2025-67823
CVSS 8.2
A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthentica…
CVE-2025-67796CVE-2025-67796
CVSS 8.1
IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API doe…
CVE-2025-67752CVE-2025-67752
CVSS 8.1
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper …
CVE-2025-67750CVE-2025-67750
CVSS 8.4
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.5 and belo…
CVE-2025-67738CVE-2025-67738
CVSS 8.5
squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are availa…
CVE-2025-67729CVE-2025-67729
CVSS 8.8internlm
LMDeploy is a toolkit for compressing, deploying, and serving LLMs. Prior to version 0.11.1, an insecure deserialization vulnerability exists in lmdeploy where…
CVE-2025-6766CVE-2025-6766
CVSS 8.8
A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. It has been declared as critical. This vulnerability affects t…
CVE-2025-6765CVE-2025-6765
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/…
CVE-2025-67645CVE-2025-67645
CVSS 8.8
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control i…
CVE-2025-6763CVE-2025-6763
CVSS 8.1
A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. Affected by this issue is some unknown …
CVE-2025-67619CVE-2025-67619
CVSS 8.8
Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issue affects Kids Heaven: from n/a through…
CVE-2025-67616CVE-2025-67616
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Mella mella allows PHP Local …
CVE-2025-67615CVE-2025-67615
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in bslthemes Myour myour allows PHP Local…
CVE-2025-6755CVE-2025-6755
CVSS 8.8
The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDeleteTheme() fu…
CVE-2025-6754CVE-2025-6754
CVSS 8.8
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_cl…
CVE-2025-6752CVE-2025-6752
CVSS 8.8
A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critical. This vulnerability affects the funct…
CVE-2025-67518CVE-2025-67518
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Accordion Slider PRO accordion_slider_pro al…
CVE-2025-67517CVE-2025-67517
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Blind …
CVE-2025-67516CVE-2025-67516
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator a…
CVE-2025-67515CVE-2025-67515
CVSS 8.8qodeinteractive
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP…
CVE-2025-6751CVE-2025-6751
CVSS 8.8
A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the function set_device_language of the file po…
CVE-2025-67509CVE-2025-67509
CVSS 8.2neuron-ai
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. My…
CVE-2025-67508CVE-2025-67508
CVSS 8.4linuxfoundation
gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells such as Fish …
CVE-2025-67507CVE-2025-67507
CVSS 8.1
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery …
CVE-2025-67505CVE-2025-67505
CVSS 8.4okta
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent re…
CVE-2025-67501CVE-2025-67501
CVSS 8.8
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain an SQL Injection vulnerability…
CVE-2025-67494CVE-2025-67494
CVSS 8.6
ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADE…
CVE-2025-67488CVE-2025-67488
CVSS 8.8
SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function importZipMd wh…
CVE-2025-67487CVE-2025-67487
CVSS 8.6
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (symlinks) w…
CVE-2025-67478CVE-2025-67478
CVSS 8.8
Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserMailer.Php. This issue affects CheckUse…
CVE-2025-67472CVE-2025-67472
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Si…
CVE-2025-6746CVE-2025-6746
CVSS 8.8
The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it p…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.