91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,051–4,100 of 8,161 in High · page 82 of 164

IDTitleSummary
CVE-2025-64729CVE-2025-64729
CVSS 8.2
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and…
CVE-2025-64691CVE-2025-64691
CVSS 8.8
The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS sys…
CVE-2025-64678CVE-2025-64678
CVSS 8.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-64677CVE-2025-64677
CVSS 8.2microsoft
Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform…
CVE-2025-64663CVE-2025-64663
CVSS 8.8
Custom Question Answering Elevation of Privilege Vulnerability
CVE-2025-64660CVE-2025-64660
CVSS 8.0
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
CVE-2025-6464CVE-2025-6464
CVSS 8.8
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i…
CVE-2025-6463CVE-2025-6463
CVSS 8.8
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file …
CVE-2025-6459CVE-2025-6459
CVSS 8.8
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in…
CVE-2025-6454CVE-2025-6454
CVSS 8.8
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowe…
CVE-2025-64523CVE-2025-64523
CVSS 8.8
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions pri…
CVE-2025-64519CVE-2025-64519
CVSS 8.8
TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL injection v…
CVE-2025-64511CVE-2025-64511
CVSS 7.4maxkb
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python c…
CVE-2025-64496CVE-2025-64496
CVSS 8.0
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerab…
CVE-2025-64492CVE-2025-64492
CVSS 8.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind S…
CVE-2025-64490CVE-2025-64490
CVSS 8.3
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0…
CVE-2025-64489CVE-2025-64489
CVSS 8.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0…
CVE-2025-64488CVE-2025-64488
CVSS 8.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through…
CVE-2025-64484CVE-2025-64484
CVSS 8.5
OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load …
CVE-2025-6445CVE-2025-6445
CVSS 8.1
ServiceStack FindType Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected…
CVE-2025-64447CVE-2025-64447
CVSS 8.1fortinet
A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb …
CVE-2025-64425CVE-2025-64425
CVSS 8.1coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an…
CVE-2025-64424CVE-2025-64424
CVSS 8.8coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a …
CVE-2025-64423CVE-2025-64423
CVSS 8.8coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a …
CVE-2025-64421CVE-2025-64421
CVSS 8.0coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a …
CVE-2025-64420CVE-2025-64420
CVSS 9.9coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434,…
CVE-2025-64419CVE-2025-64419
CVSS 9.6coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from doc…
CVE-2025-64403CVE-2025-64403
CVSS 8.1
Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing Authorization vulnerability in Apache Op…
CVE-2025-64377CVE-2025-64377
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CridioStudio ListingPro listingpro all…
CVE-2025-64373CVE-2025-64373
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in shinetheme Traveler traveler allows PH…
CVE-2025-64371CVE-2025-64371
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.T…
CVE-2025-6436CVE-2025-6436
CVSS 8.1mozilla
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…
CVE-2025-64353CVE-2025-64353
CVSS 8.8
Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3.
CVE-2025-6435CVE-2025-6435
CVSS 8.1mozilla
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file …
CVE-2025-64349CVE-2025-64349
CVSS 8.8
ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take…
CVE-2025-64328Sangoma FreePBX OS Command Injection Vulnerability
KEVCVSS 7.2Sangoma
Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticate…
CVE-2025-6432CVE-2025-6432
CVSS 8.6mozilla
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not respondin…
CVE-2025-64309CVE-2025-64309
CVSS 7.4
The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a…
CVE-2025-64287CVE-2025-64287
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Alloggio - Hotel Booking a…
CVE-2025-64266CVE-2025-64266
CVSS 8.8
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection…
CVE-2025-6426CVE-2025-6426
CVSS 8.8mozilla
The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of…
CVE-2025-6423CVE-2025-6423
CVSS 8.8
The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_upload_file() f…
CVE-2025-64223CVE-2025-64223
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign PenNews pennews allows PHP…
CVE-2025-6422CVE-2025-6422
CVSS 8.8
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functional…
CVE-2025-64205CVE-2025-64205
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local…
CVE-2025-64184CVE-2025-64184
CVSS 8.8
Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different as…
CVE-2025-64175CVE-2025-64175
CVSS 8.8
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-ac…
CVE-2025-6417CVE-2025-6417
CVSS 8.8
A vulnerability has been found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. Affected by this vulnerability is an unknown functio…
CVE-2025-6416CVE-2025-6416
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /admi…
CVE-2025-6415CVE-2025-6415
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.1. This issue affects some unknown processing o…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.