91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,001–4,050 of 8,161 in High · page 81 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-65840 | CVE-2025-65840 CVSS 8.8 | PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController. |
| CVE-2025-6583 | CVE-2025-6583 CVSS 8.8 | A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /view… |
| CVE-2025-65824 | CVE-2025-65824 CVSS 8.8meatmeet | An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmware upgrade using Bluetooth Low Energy … |
| CVE-2025-6582 | CVE-2025-6582 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown fu… |
| CVE-2025-65817 | CVE-2025-65817 CVSS 8.8 | LSC Smart Connect Indoor IP Camera 1.4.13 contains a RCE vulnerability in start_app.sh. |
| CVE-2025-6581 | CVE-2025-6581 CVSS 8.8 | A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality… |
| CVE-2025-65807 | CVE-2025-65807 CVSS 8.4chmln | An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command. |
| CVE-2025-65781 | CVE-2025-65781 CVSS 8.2 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer… |
| CVE-2025-65780 | CVE-2025-65780 CVSS 8.8 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire user docu… |
| CVE-2025-65778 | CVE-2025-65778 CVSS 8.1 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with attacker-cont… |
| CVE-2025-65742 | CVE-2025-65742 CVSS 8.2newgensoft | An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execu… |
| CVE-2025-6574 | CVE-2025-6574 CVSS 8.8 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is … |
| CVE-2025-65730 | CVE-2025-65730 CVSS 8.8 | Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication. |
| CVE-2025-65716 | CVE-2025-65716 CVSS 8.8 | An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file. |
| CVE-2025-6570 | CVE-2025-6570 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected by this issue is some unknown function… |
| CVE-2025-6568 | CVE-2025-6568 CVSS 8.8 | A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formIpv6S… |
| CVE-2025-6565 | CVE-2025-6565 CVSS 8.8 | A vulnerability was found in Netgear WNCE3001 1.0.0.50. It has been classified as critical. This affects the function http_d of the component HTTP POST Request… |
| CVE-2025-6562 | CVE-2025-6562 CVSS 8.8 | Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with regular privi… |
| CVE-2025-65594 | CVE-2025-65594 CVSS 8.1os4ed | OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized databa… |
| CVE-2025-65593 | CVE-2025-65593 CVSS 8.8nopcommerce | nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality. |
| CVE-2025-6558 | Google Chromium ANGLE and GPU Improper Input Validation Vulnerability KEVCVSS 8.8Google | Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a… |
| CVE-2025-65573 | CVE-2025-65573 CVSS 8.8 | Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a denial of service via function handle_in… |
| CVE-2025-6554 | Google Chromium V8 Type Confusion Vulnerability KEVCVSS 8.1Google | Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vul… |
| CVE-2025-65530 | CVE-2025-65530 CVSS 8.8cloudlinux | An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanni… |
| CVE-2025-65480 | CVE-2025-65480 CVSS 8.8 | An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain… |
| CVE-2025-65472 | CVE-2025-65472 CVSS 8.8 | A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Adminis… |
| CVE-2025-65471 | CVE-2025-65471 CVSS 8.8 | An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via up… |
| CVE-2025-6541 | CVE-2025-6541 CVSS 8.8 | An arbitrary OS command may be executed on the product by the user who can log in to the web management interface. |
| CVE-2025-6535 | CVE-2025-6535 CVSS 8.8 | A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file… |
| CVE-2025-65295 | CVE-2025-65295 CVSS 8.1aqara | Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 devices, allow attacker… |
| CVE-2025-6529 | CVE-2025-6529 CVSS 8.8 | A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknown functionality of the component Telnet… |
| CVE-2025-65271 | CVE-2025-65271 CVSS 8.8 | Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an admini… |
| CVE-2025-65202 | CVE-2025-65202 CVSS 8.0 | TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command… |
| CVE-2025-65128 | CVE-2025-65128 CVSS 8.1 | A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers … |
| CVE-2025-65118 | CVE-2025-65118 CVSS 8.8 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code… |
| CVE-2025-6511 | CVE-2025-6511 CVSS 8.8 | A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_410090. The manipulation leads to stack-… |
| CVE-2025-65103 | CVE-2025-65103 CVSS 8.8 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an authenticated SQL Injection vulnerabili… |
| CVE-2025-6510 | CVE-2025-6510 CVSS 8.8 | A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is the function sub_415EF8. The manipulatio… |
| CVE-2025-65094 | CVE-2025-65094 CVSS 8.8 | WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrators group by… |
| CVE-2025-6505 | CVE-2025-6505 CVSS 8.1 | Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerabilit… |
| CVE-2025-6504 | CVE-2025-6504 CVSS 8.4 | In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header. Since XFF is a client-con… |
| CVE-2025-65036 | CVE-2025-65036 CVSS 8.3xwiki | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from t… |
| CVE-2025-65034 | CVE-2025-65034 CVSS 8.1 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerability allows any authenticated user to re… |
| CVE-2025-65033 | CVE-2025-65033 CVSS 8.1 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any authenticat… |
| CVE-2025-65029 | CVE-2025-65029 CVSS 8.1 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authent… |
| CVE-2025-65001 | CVE-2025-65001 CVSS 8.2 | Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and availability. |
| CVE-2025-64983 | CVE-2025-64983 CVSS 8.0 | Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via Telnet and gain acce… |
| CVE-2025-6487 | CVE-2025-6487 CVSS 8.8 | A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the function formRoute of the file /boafrm… |
| CVE-2025-6486 | CVE-2025-6486 CVSS 8.8 | A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability affects the function formWlanMultipleAP… |
| CVE-2025-64751 | CVE-2025-64751 CVSS 8.8 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( op… |