91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,901–3,950 of 8,161 in High · page 79 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-6736 | CVE-2025-6736 CVSS 8.8 | A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/i… |
| CVE-2025-6735 | CVE-2025-6735 CVSS 8.8 | A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Impo… |
| CVE-2025-6734 | CVE-2025-6734 CVSS 8.8 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. This issue affects the function sub_484E40 of the file /goform/f… |
| CVE-2025-6733 | CVE-2025-6733 CVSS 8.8 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been declared as critical. This vulnerability affects the function sub_416928 of the fil… |
| CVE-2025-6732 | CVE-2025-6732 CVSS 8.8 | A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been classified as critical. This affects the function strcpy of the file /goform/setSys… |
| CVE-2025-67298 | CVE-2025-67298 CVSS 8.1 | An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile |
| CVE-2025-67260 | CVE-2025-67260 CVSS 8.8aster-te | The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to e… |
| CVE-2025-67255 | CVE-2025-67255 CVSS 8.8 | In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability. |
| CVE-2025-6724 | CVE-2025-6724 CVSS 8.8 | In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functio… |
| CVE-2025-6718 | CVE-2025-6718 CVSS 8.8 | The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to, and incl… |
| CVE-2025-67089 | CVE-2025-67089 CVSS 8.1 | A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC me… |
| CVE-2025-67077 | CVE-2025-67077 CVSS 8.8 | File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile a… |
| CVE-2025-67070 | CVE-2025-67070 CVSS 8.2 | A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the multi-factor authenticati… |
| CVE-2025-6706 | CVE-2025-6706 CVSS 8.8 | An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have author… |
| CVE-2025-67037 | CVE-2025-67037 CVSS 7.2lantronix | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel conn… |
| CVE-2025-67036 | CVE-2025-67036 CVSS 7.2lantronix | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitizatio… |
| CVE-2025-67034 | CVE-2025-67034 CVSS 7.2lantronix | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credential… |
| CVE-2025-67030 | CVE-2025-67030 CVSS 8.8codehaus-plexus | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642.… |
| CVE-2025-66953 | CVE-2025-66953 CVSS 8.8 | CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interfa… |
| CVE-2025-66918 | CVE-2025-66918 CVSS 8.8 | edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter. |
| CVE-2025-6691 | CVE-2025-6691 CVSS 8.1 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… |
| CVE-2025-6685 | CVE-2025-6685 CVSS 8.8 | ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio… |
| CVE-2025-66824 | CVE-2025-66824 CVSS 8.7trueconf | A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10… |
| CVE-2025-66738 | CVE-2025-66738 CVSS 8.8yealink | An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of th… |
| CVE-2025-6670 | CVE-2025-6670 CVSS 8.8 | A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within a… |
| CVE-2025-66698 | CVE-2025-66698 CVSS 8.6semantic-machines | An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints. |
| CVE-2025-66675 | CVE-2025-66675 CVSS 8.2 | Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0… |
| CVE-2025-6667 | CVE-2025-6667 CVSS 8.8 | A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /… |
| CVE-2025-66524 | CVE-2025-66524 CVSS 8.8 | Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for s… |
| CVE-2025-66518 | CVE-2025-66518 CVSS 8.8apache | Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local… |
| CVE-2025-66474 | CVE-2025-66474 CVSS 8.8xwiki | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions… |
| CVE-2025-66467 | CVE-2025-66467 CVSS 8.0apache | Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user cre… |
| CVE-2025-66457 | CVE-2025-66457 CVSS 8.8 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communication. Versions 1.4.17 and below are s… |
| CVE-2025-66449 | CVE-2025-66449 CVSS 8.8c4illin | ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on th… |
| CVE-2025-66448 | CVE-2025-66448 CVSS 8.8 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class n… |
| CVE-2025-66444 | CVE-2025-66444 CVSS 8.2 | Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops C… |
| CVE-2025-66440 | CVE-2025-66440 CVSS 8.8 | An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/accounts/doctype/payment_entry/payment_ent… |
| CVE-2025-66439 | CVE-2025-66439 CVSS 8.8 | An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.accounts.doctype.payment_entry.payment_ent… |
| CVE-2025-66438 | CVE-2025-66438 CVSS 8.8 | A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format rendering mechanism. Specifically, the API frap… |
| CVE-2025-66437 | CVE-2025-66437 CVSS 8.8 | An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders addres… |
| CVE-2025-66434 | CVE-2025-66434 CVSS 8.8 | An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext through 15.89.0. The function renders att… |
| CVE-2025-66429 | CVE-2025-66429 CVSS 8.8 | An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. T… |
| CVE-2025-66428 | CVE-2025-66428 CVSS 8.8 | An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation. |
| CVE-2025-66416 | CVE-2025-66416 CVSS 8.1 | The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to version 1.23.0, tThe Model Context Protocol … |
| CVE-2025-66414 | CVE-2025-66414 CVSS 8.1 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The Model Context Protocol (MCP) TypeScript … |
| CVE-2025-66404 | CVE-2025-66404 CVSS 8.8 | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_… |
| CVE-2025-66399 | CVE-2025-66399 CVSS 8.8 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functio… |
| CVE-2025-66398 | CVE-2025-66398 CVSS 9.6signalk | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal sta… |
| CVE-2025-66397 | CVE-2025-66397 CVSS 8.3 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions in t… |
| CVE-2025-66395 | CVE-2025-66395 CVSS 8.8 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in the `src/ListEvents.php` file. When filte… |