91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,001–4,050 of 8,161 in High · page 81 of 164

IDTitleSummary
CVE-2025-65840CVE-2025-65840
CVSS 8.8
PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
CVE-2025-6583CVE-2025-6583
CVSS 8.8
A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /view…
CVE-2025-65824CVE-2025-65824
CVSS 8.8meatmeet
An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy …
CVE-2025-6582CVE-2025-6582
CVSS 8.8
A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown fu…
CVE-2025-65817CVE-2025-65817
CVSS 8.8
LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh.
CVE-2025-6581CVE-2025-6581
CVSS 8.8
A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality…
CVE-2025-65807CVE-2025-65807
CVSS 8.4chmln
An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.
CVE-2025-65781CVE-2025-65781
CVSS 8.2
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer…
CVE-2025-65780CVE-2025-65780
CVSS 8.8
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user docu…
CVE-2025-65778CVE-2025-65778
CVSS 8.1
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-cont…
CVE-2025-65742CVE-2025-65742
CVSS 8.2newgensoft
An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execu…
CVE-2025-6574CVE-2025-6574
CVSS 8.8
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is …
CVE-2025-65730CVE-2025-65730
CVSS 8.8
Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication.
CVE-2025-65716CVE-2025-65716
CVSS 8.8
An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.
CVE-2025-6570CVE-2025-6570
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected by this issue is some unknown function…
CVE-2025-6568CVE-2025-6568
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formIpv6S…
CVE-2025-6565CVE-2025-6565
CVSS 8.8
A vulnerability was found in Netgear WNCE3001 1.0.0.50. It has been classified as critical. This affects the function http_d of the component HTTP POST Request…
CVE-2025-6562CVE-2025-6562
CVSS 8.8
Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with regular privi…
CVE-2025-65594CVE-2025-65594
CVSS 8.1os4ed
OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized databa…
CVE-2025-65593CVE-2025-65593
CVSS 8.8nopcommerce
nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.
CVE-2025-6558Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
KEVCVSS 8.8Google
Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a…
CVE-2025-65573CVE-2025-65573
CVSS 8.8
Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a denial of service via function handle_in…
CVE-2025-6554Google Chromium V8 Type Confusion Vulnerability
KEVCVSS 8.1Google
Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vul…
CVE-2025-65530CVE-2025-65530
CVSS 8.8cloudlinux
An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanni…
CVE-2025-65480CVE-2025-65480
CVSS 8.8
An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain…
CVE-2025-65472CVE-2025-65472
CVSS 8.8
A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Adminis…
CVE-2025-65471CVE-2025-65471
CVSS 8.8
An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via up…
CVE-2025-6541CVE-2025-6541
CVSS 8.8
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
CVE-2025-6535CVE-2025-6535
CVSS 8.8
A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file…
CVE-2025-65295CVE-2025-65295
CVSS 8.1aqara
Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attacker…
CVE-2025-6529CVE-2025-6529
CVSS 8.8
A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknown functionality of the component Telnet…
CVE-2025-65271CVE-2025-65271
CVSS 8.8
Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an admini…
CVE-2025-65202CVE-2025-65202
CVSS 8.0
TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command…
CVE-2025-65128CVE-2025-65128
CVSS 8.1
A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers …
CVE-2025-65118CVE-2025-65118
CVSS 8.8
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code…
CVE-2025-6511CVE-2025-6511
CVSS 8.8
A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_410090. The manipulation leads to stack-…
CVE-2025-65103CVE-2025-65103
CVSS 8.8
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerabili…
CVE-2025-6510CVE-2025-6510
CVSS 8.8
A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is the function sub_415EF8. The manipulatio…
CVE-2025-65094CVE-2025-65094
CVSS 8.8
WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by…
CVE-2025-6505CVE-2025-6505
CVSS 8.1
Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerabilit…
CVE-2025-6504CVE-2025-6504
CVSS 8.4
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a client-con…
CVE-2025-65036CVE-2025-65036
CVSS 8.3xwiki
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from t…
CVE-2025-65034CVE-2025-65034
CVSS 8.1
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerability allows any authenticated user to re…
CVE-2025-65033CVE-2025-65033
CVSS 8.1
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any authenticat…
CVE-2025-65029CVE-2025-65029
CVSS 8.1
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authent…
CVE-2025-65001CVE-2025-65001
CVSS 8.2
Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and availability.
CVE-2025-64983CVE-2025-64983
CVSS 8.0
Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via Telnet and gain acce…
CVE-2025-6487CVE-2025-6487
CVSS 8.8
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the function formRoute of the file /boafrm…
CVE-2025-6486CVE-2025-6486
CVSS 8.8
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability affects the function formWlanMultipleAP…
CVE-2025-64751CVE-2025-64751
CVSS 8.8
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( op…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.