91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,051–4,100 of 8,161 in High · page 82 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-64729 | CVE-2025-64729 CVSS 8.2 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and… |
| CVE-2025-64691 | CVE-2025-64691 CVSS 8.8 | The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS sys… |
| CVE-2025-64678 | CVE-2025-64678 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-64677 | CVE-2025-64677 CVSS 8.2microsoft | Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform… |
| CVE-2025-64663 | CVE-2025-64663 CVSS 8.8 | Custom Question Answering Elevation of Privilege Vulnerability |
| CVE-2025-64660 | CVE-2025-64660 CVSS 8.0 | Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. |
| CVE-2025-6464 | CVE-2025-6464 CVSS 8.8 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i… |
| CVE-2025-6463 | CVE-2025-6463 CVSS 8.8 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file … |
| CVE-2025-6459 | CVE-2025-6459 CVSS 8.8 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… |
| CVE-2025-6454 | CVE-2025-6454 CVSS 8.8 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowe… |
| CVE-2025-64523 | CVE-2025-64523 CVSS 8.8 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions pri… |
| CVE-2025-64519 | CVE-2025-64519 CVSS 8.8 | TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL injection v… |
| CVE-2025-64511 | CVE-2025-64511 CVSS 7.4maxkb | MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python c… |
| CVE-2025-64496 | CVE-2025-64496 CVSS 8.0 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerab… |
| CVE-2025-64492 | CVE-2025-64492 CVSS 8.8 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind S… |
| CVE-2025-64490 | CVE-2025-64490 CVSS 8.3 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0… |
| CVE-2025-64489 | CVE-2025-64489 CVSS 8.8 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0… |
| CVE-2025-64488 | CVE-2025-64488 CVSS 8.8 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through… |
| CVE-2025-64484 | CVE-2025-64484 CVSS 8.5 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load … |
| CVE-2025-6445 | CVE-2025-6445 CVSS 8.1 | ServiceStack FindType Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected… |
| CVE-2025-64447 | CVE-2025-64447 CVSS 8.1fortinet | A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb … |
| CVE-2025-64425 | CVE-2025-64425 CVSS 8.1coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an… |
| CVE-2025-64424 | CVE-2025-64424 CVSS 8.8coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a … |
| CVE-2025-64423 | CVE-2025-64423 CVSS 8.8coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a … |
| CVE-2025-64421 | CVE-2025-64421 CVSS 8.0coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a … |
| CVE-2025-64420 | CVE-2025-64420 CVSS 9.9coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434,… |
| CVE-2025-64419 | CVE-2025-64419 CVSS 9.6coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from doc… |
| CVE-2025-64403 | CVE-2025-64403 CVSS 8.1 | Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache Op… |
| CVE-2025-64377 | CVE-2025-64377 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CridioStudio ListingPro listingpro all… |
| CVE-2025-64373 | CVE-2025-64373 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in shinetheme Traveler traveler allows PH… |
| CVE-2025-64371 | CVE-2025-64371 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.T… |
| CVE-2025-6436 | CVE-2025-6436 CVSS 8.1mozilla | Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
| CVE-2025-64353 | CVE-2025-64353 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3. |
| CVE-2025-6435 | CVE-2025-6435 CVSS 8.1mozilla | If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file … |
| CVE-2025-64349 | CVE-2025-64349 CVSS 8.8 | ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take… |
| CVE-2025-64328 | Sangoma FreePBX OS Command Injection Vulnerability KEVCVSS 7.2Sangoma | Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticate… |
| CVE-2025-6432 | CVE-2025-6432 CVSS 8.6mozilla | When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not respondin… |
| CVE-2025-64309 | CVE-2025-64309 CVSS 7.4 | The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a… |
| CVE-2025-64287 | CVE-2025-64287 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Alloggio - Hotel Booking a… |
| CVE-2025-64266 | CVE-2025-64266 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection… |
| CVE-2025-6426 | CVE-2025-6426 CVSS 8.8mozilla | The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of… |
| CVE-2025-6423 | CVE-2025-6423 CVSS 8.8 | The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_upload_file() f… |
| CVE-2025-64223 | CVE-2025-64223 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign PenNews pennews allows PHP… |
| CVE-2025-6422 | CVE-2025-6422 CVSS 8.8 | A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functional… |
| CVE-2025-64205 | CVE-2025-64205 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local… |
| CVE-2025-64184 | CVE-2025-64184 CVSS 8.8 | Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different as… |
| CVE-2025-64175 | CVE-2025-64175 CVSS 8.8 | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-ac… |
| CVE-2025-6417 | CVE-2025-6417 CVSS 8.8 | A vulnerability has been found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. Affected by this vulnerability is an unknown functio… |
| CVE-2025-6416 | CVE-2025-6416 CVSS 8.8 | A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /admi… |
| CVE-2025-6415 | CVE-2025-6415 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.1. This issue affects some unknown processing o… |