91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,901–3,950 of 8,161 in High · page 79 of 164

IDTitleSummary
CVE-2025-6736CVE-2025-6736
CVSS 8.8
A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/i…
CVE-2025-6735CVE-2025-6735
CVSS 8.8
A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Impo…
CVE-2025-6734CVE-2025-6734
CVSS 8.8
A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. This issue affects the function sub_484E40 of the file /goform/f…
CVE-2025-6733CVE-2025-6733
CVSS 8.8
A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been declared as critical. This vulnerability affects the function sub_416928 of the fil…
CVE-2025-6732CVE-2025-6732
CVSS 8.8
A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been classified as critical. This affects the function strcpy of the file /goform/setSys…
CVE-2025-67298CVE-2025-67298
CVSS 8.1
An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile
CVE-2025-67260CVE-2025-67260
CVSS 8.8aster-te
The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to e…
CVE-2025-67255CVE-2025-67255
CVSS 8.8
In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.
CVE-2025-6724CVE-2025-6724
CVSS 8.8
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functio…
CVE-2025-6718CVE-2025-6718
CVSS 8.8
The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to, and incl…
CVE-2025-67089CVE-2025-67089
CVSS 8.1
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC me…
CVE-2025-67077CVE-2025-67077
CVSS 8.8
File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile a…
CVE-2025-67070CVE-2025-67070
CVSS 8.2
A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the multi-factor authenticati…
CVE-2025-6706CVE-2025-6706
CVSS 8.8
An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have author…
CVE-2025-67037CVE-2025-67037
CVSS 7.2lantronix
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel conn…
CVE-2025-67036CVE-2025-67036
CVSS 7.2lantronix
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitizatio…
CVE-2025-67034CVE-2025-67034
CVSS 7.2lantronix
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credential…
CVE-2025-67030CVE-2025-67030
CVSS 8.8codehaus-plexus
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642.…
CVE-2025-66953CVE-2025-66953
CVSS 8.8
CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interfa…
CVE-2025-66918CVE-2025-66918
CVSS 8.8
edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.
CVE-2025-6691CVE-2025-6691
CVSS 8.1
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation…
CVE-2025-6685CVE-2025-6685
CVSS 8.8
ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio…
CVE-2025-66824CVE-2025-66824
CVSS 8.7trueconf
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10…
CVE-2025-66738CVE-2025-66738
CVSS 8.8yealink
An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of th…
CVE-2025-6670CVE-2025-6670
CVSS 8.8
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within a…
CVE-2025-66698CVE-2025-66698
CVSS 8.6semantic-machines
An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.
CVE-2025-66675CVE-2025-66675
CVSS 8.2
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0…
CVE-2025-6667CVE-2025-6667
CVSS 8.8
A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /…
CVE-2025-66524CVE-2025-66524
CVSS 8.8
Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for s…
CVE-2025-66518CVE-2025-66518
CVSS 8.8apache
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local…
CVE-2025-66474CVE-2025-66474
CVSS 8.8xwiki
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions…
CVE-2025-66467CVE-2025-66467
CVSS 8.0apache
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user cre…
CVE-2025-66457CVE-2025-66457
CVSS 8.8
Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.17 and below are s…
CVE-2025-66449CVE-2025-66449
CVSS 8.8c4illin
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on th…
CVE-2025-66448CVE-2025-66448
CVSS 8.8
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class n…
CVE-2025-66444CVE-2025-66444
CVSS 8.2
Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops C…
CVE-2025-66440CVE-2025-66440
CVSS 8.8
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_ent…
CVE-2025-66439CVE-2025-66439
CVSS 8.8
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_ent…
CVE-2025-66438CVE-2025-66438
CVSS 8.8
A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frap…
CVE-2025-66437CVE-2025-66437
CVSS 8.8
An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders addres…
CVE-2025-66434CVE-2025-66434
CVSS 8.8
An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders att…
CVE-2025-66429CVE-2025-66429
CVSS 8.8
An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. T…
CVE-2025-66428CVE-2025-66428
CVSS 8.8
An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
CVE-2025-66416CVE-2025-66416
CVSS 8.1
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context Protocol …
CVE-2025-66414CVE-2025-66414
CVSS 8.1
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript …
CVE-2025-66404CVE-2025-66404
CVSS 8.8
MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_…
CVE-2025-66399CVE-2025-66399
CVSS 8.8
Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functio…
CVE-2025-66398CVE-2025-66398
CVSS 9.6signalk
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal sta…
CVE-2025-66397CVE-2025-66397
CVSS 8.3
ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in t…
CVE-2025-66395CVE-2025-66395
CVSS 8.8
ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. When filte…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.