91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,951–4,000 of 8,161 in High · page 80 of 164

IDTitleSummary
CVE-2025-66384CVE-2025-66384
CVSS 8.2
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
CVE-2025-66360CVE-2025-66360
CVSS 8.8logpoint
An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) informatio…
CVE-2025-66315CVE-2025-66315
CVSS 8.8
There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can …
CVE-2025-66300CVE-2025-66300
CVSS 8.5getgrav
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatte…
CVE-2025-66299CVE-2025-66299
CVSS 8.8getgrav
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user…
CVE-2025-66297CVE-2025-66297
CVSS 8.8getgrav
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig p…
CVE-2025-66296CVE-2025-66296
CVSS 8.8getgrav
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username un…
CVE-2025-66295CVE-2025-66295
CVSS 8.8getgrav
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a u…
CVE-2025-66294CVE-2025-66294
CVSS 8.8getgrav
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attac…
CVE-2025-66292CVE-2025-66292
CVSS 8.1
DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/d…
CVE-2025-66289CVE-2025-66289
CVSS 8.8
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user…
CVE-2025-66287CVE-2025-66287
CVSS 8.8
A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.
CVE-2025-6627CVE-2025-6627
CVSS 8.8
A vulnerability has been found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. This vulnerability affects unknown code of the file /boafrm/f…
CVE-2025-66225CVE-2025-66225
CVSS 8.8
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username su…
CVE-2025-66224CVE-2025-66224
CVSS 8.8
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw in its mail…
CVE-2025-66214CVE-2025-66214
CVSS 8.8
Ladybug adds message-based debugging, unit, system, and regression testing to Java applications. Versions prior to 3.0-20251107.114628 contain the APIs /iaf/la…
CVE-2025-66213CVE-2025-66213
CVSS 8.8
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i…
CVE-2025-66212CVE-2025-66212
CVSS 8.8
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i…
CVE-2025-66211CVE-2025-66211
CVSS 8.8
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i…
CVE-2025-66210CVE-2025-66210
CVSS 8.8
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i…
CVE-2025-66209CVE-2025-66209
CVSS 8.8
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i…
CVE-2025-66206CVE-2025-66206
CVSS 8.6
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein some files …
CVE-2025-66204CVE-2025-66204
CVSS 8.1wbce
WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifyi…
CVE-2025-66201CVE-2025-66201
CVSS 8.1librechat
LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by passing sp…
CVE-2025-66177CVE-2025-66177
CVSS 8.8
There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same …
CVE-2025-66176CVE-2025-66176
CVSS 8.8hikvision
There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same…
CVE-2025-66172CVE-2025-66172
CVSS 8.1apache
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0…
CVE-2025-6617CVE-2025-6617
CVSS 8.8
A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formAdvanceSetup of the file /goform/formAdvan…
CVE-2025-66168CVE-2025-66168
CVSS 8.8
WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https://activemq…
CVE-2025-6616CVE-2025-6616
CVSS 8.8
A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWAN_Wizard51 of the file /…
CVE-2025-6615CVE-2025-6615
CVSS 8.8
A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formAutoDetecWAN_wizard4 of the file /goform…
CVE-2025-6614CVE-2025-6614
CVSS 8.8
A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetWANType_Wizard5 of …
CVE-2025-66095CVE-2025-66095
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system …
CVE-2025-6609CVE-2025-6609
CVSS 8.8
A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality o…
CVE-2025-6608CVE-2025-6608
CVSS 8.8
A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown func…
CVE-2025-6607CVE-2025-6607
CVSS 8.8
A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /p…
CVE-2025-6606CVE-2025-6606
CVSS 8.8
A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. This issue affects some unknown processin…
CVE-2025-6605CVE-2025-6605
CVSS 8.8
A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability affects unknown code of the file /panel…
CVE-2025-6604CVE-2025-6604
CVSS 8.8
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add-s…
CVE-2025-66028CVE-2025-66028
CVSS 8.2
OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Respo…
CVE-2025-66001CVE-2025-66001
CVSS 8.8
NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) f…
CVE-2025-65966CVE-2025-65966
CVSS 8.1
OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API re…
CVE-2025-65964CVE-2025-65964
CVSS 8.8
n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-…
CVE-2025-65951CVE-2025-65951
CVSS 8.7
Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based timelock encryption system fails to enforc…
CVE-2025-65950CVE-2025-65950
CVSS 8.8wbce
WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to…
CVE-2025-65946CVE-2025-65946
CVSS 8.1
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo …
CVE-2025-65897CVE-2025-65897
CVSS 8.8zhaoyachao
zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths…
CVE-2025-65883CVE-2025-65883
CVSS 8.4
A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execu…
CVE-2025-65879CVE-2025-65879
CVSS 8.1yeqifu
Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled good…
CVE-2025-6585CVE-2025-6585
CVSS 8.1
The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.2 via the cs_remove_profile_callb…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.