91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 3,951–4,000 of 8,161 in High · page 80 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-66384 | CVE-2025-66384 CVSS 8.2 | app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name. |
| CVE-2025-66360 | CVE-2025-66360 CVSS 8.8logpoint | An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) informatio… |
| CVE-2025-66315 | CVE-2025-66315 CVSS 8.8 | There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can … |
| CVE-2025-66300 | CVE-2025-66300 CVSS 8.5getgrav | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatte… |
| CVE-2025-66299 | CVE-2025-66299 CVSS 8.8getgrav | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user… |
| CVE-2025-66297 | CVE-2025-66297 CVSS 8.8getgrav | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig p… |
| CVE-2025-66296 | CVE-2025-66296 CVSS 8.8getgrav | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username un… |
| CVE-2025-66295 | CVE-2025-66295 CVSS 8.8getgrav | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a u… |
| CVE-2025-66294 | CVE-2025-66294 CVSS 8.8getgrav | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attac… |
| CVE-2025-66292 | CVE-2025-66292 CVSS 8.1 | DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/d… |
| CVE-2025-66289 | CVE-2025-66289 CVSS 8.8 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user… |
| CVE-2025-66287 | CVE-2025-66287 CVSS 8.8 | A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling. |
| CVE-2025-6627 | CVE-2025-6627 CVSS 8.8 | A vulnerability has been found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. This vulnerability affects unknown code of the file /boafrm/f… |
| CVE-2025-66225 | CVE-2025-66225 CVSS 8.8 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username su… |
| CVE-2025-66224 | CVE-2025-66224 CVSS 8.8 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains an input-neutralization flaw in its mail… |
| CVE-2025-66214 | CVE-2025-66214 CVSS 8.8 | Ladybug adds message-based debugging, unit, system, and regression testing to Java applications. Versions prior to 3.0-20251107.114628 contain the APIs /iaf/la… |
| CVE-2025-66213 | CVE-2025-66213 CVSS 8.8 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i… |
| CVE-2025-66212 | CVE-2025-66212 CVSS 8.8 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i… |
| CVE-2025-66211 | CVE-2025-66211 CVSS 8.8 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i… |
| CVE-2025-66210 | CVE-2025-66210 CVSS 8.8 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i… |
| CVE-2025-66209 | CVE-2025-66209 CVSS 8.8 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command i… |
| CVE-2025-66206 | CVE-2025-66206 CVSS 8.6 | Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein some files … |
| CVE-2025-66204 | CVE-2025-66204 CVSS 8.1wbce | WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifyi… |
| CVE-2025-66201 | CVE-2025-66201 CVSS 8.1librechat | LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by passing sp… |
| CVE-2025-66177 | CVE-2025-66177 CVSS 8.8 | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same … |
| CVE-2025-66176 | CVE-2025-66176 CVSS 8.8hikvision | There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same… |
| CVE-2025-66172 | CVE-2025-66172 CVSS 8.1apache | The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0… |
| CVE-2025-6617 | CVE-2025-6617 CVSS 8.8 | A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formAdvanceSetup of the file /goform/formAdvan… |
| CVE-2025-66168 | CVE-2025-66168 CVSS 8.8 | WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the following for more details: https://activemq… |
| CVE-2025-6616 | CVE-2025-6616 CVSS 8.8 | A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWAN_Wizard51 of the file /… |
| CVE-2025-6615 | CVE-2025-6615 CVSS 8.8 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formAutoDetecWAN_wizard4 of the file /goform… |
| CVE-2025-6614 | CVE-2025-6614 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetWANType_Wizard5 of … |
| CVE-2025-66095 | CVE-2025-66095 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system … |
| CVE-2025-6609 | CVE-2025-6609 CVSS 8.8 | A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality o… |
| CVE-2025-6608 | CVE-2025-6608 CVSS 8.8 | A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown func… |
| CVE-2025-6607 | CVE-2025-6607 CVSS 8.8 | A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /p… |
| CVE-2025-6606 | CVE-2025-6606 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. This issue affects some unknown processin… |
| CVE-2025-6605 | CVE-2025-6605 CVSS 8.8 | A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability affects unknown code of the file /panel… |
| CVE-2025-6604 | CVE-2025-6604 CVSS 8.8 | A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add-s… |
| CVE-2025-66028 | CVE-2025-66028 CVSS 8.2 | OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Respo… |
| CVE-2025-66001 | CVE-2025-66001 CVSS 8.8 | NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) f… |
| CVE-2025-65966 | CVE-2025-65966 CVSS 8.1 | OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API re… |
| CVE-2025-65964 | CVE-2025-65964 CVSS 8.8 | n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to prevent RCE through the project's pre-… |
| CVE-2025-65951 | CVE-2025-65951 CVSS 8.7 | Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based timelock encryption system fails to enforc… |
| CVE-2025-65950 | CVE-2025-65950 CVSS 8.8wbce | WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to… |
| CVE-2025-65946 | CVE-2025-65946 CVSS 8.1 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was possible for Roo … |
| CVE-2025-65897 | CVE-2025-65897 CVSS 8.8zhaoyachao | zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths… |
| CVE-2025-65883 | CVE-2025-65883 CVSS 8.4 | A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execu… |
| CVE-2025-65879 | CVE-2025-65879 CVSS 8.1yeqifu | Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled good… |
| CVE-2025-6585 | CVE-2025-6585 CVSS 8.1 | The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.2 via the cs_remove_profile_callb… |