91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,101–4,150 of 8,161 in High · page 83 of 164

IDTitleSummary
CVE-2025-64140CVE-2025-64140
CVSS 8.8jenkins
Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permiss…
CVE-2025-6414CVE-2025-6414
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Art Gallery Management System 1.1. This vulnerability affects unknown code of the file /admin/ch…
CVE-2025-6413CVE-2025-6413
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.1. This affects an unknown part of the file /admin/changeim…
CVE-2025-64124CVE-2025-64124
CVSS 8.8nuvationenergy
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows…
CVE-2025-64120CVE-2025-64120
CVSS 8.8nuvationenergy
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows…
CVE-2025-6412CVE-2025-6412
CVSS 8.8
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality …
CVE-2025-64112CVE-2025-64112
CVSS 8.0
Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with…
CVE-2025-6411CVE-2025-6411
CVSS 8.8
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown funct…
CVE-2025-64109CVE-2025-64109
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta allowed an attacker to achieve remote code…
CVE-2025-64108CVE-2025-64108
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent s…
CVE-2025-64107CVE-2025-64107
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipu…
CVE-2025-64106CVE-2025-64106
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables speci…
CVE-2025-64101CVE-2025-64101
CVSS 8.8
Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mecha…
CVE-2025-6410CVE-2025-6410
CVSS 8.8
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected is an unknown function of the file /adm…
CVE-2025-64096CVE-2025-64096
CVSS 8.8
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between …
CVE-2025-64091CVE-2025-64091
CVSS 8.8
This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.
CVE-2025-64090CVE-2025-64090
CVSS 8.8
This vulnerability allows authenticated attackers to execute commands via the hostname of the device.
CVE-2025-64066CVE-2025-64066
CVSS 8.6
Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authoriza…
CVE-2025-64065CVE-2025-64065
CVSS 8.8
The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user imperso…
CVE-2025-64064CVE-2025-64064
CVSS 8.8
Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROF…
CVE-2025-64062CVE-2025-64062
CVSS 8.8
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated…
CVE-2025-64057CVE-2025-64057
CVSS 8.3fanvil
Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and pot…
CVE-2025-6402CVE-2025-6402
CVSS 8.8
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/f…
CVE-2025-6400CVE-2025-6400
CVSS 8.8
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /…
CVE-2025-6399CVE-2025-6399
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6…
CVE-2025-6397CVE-2025-6397
CVSS 8.6
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Hosting Website Design Website Software all…
CVE-2025-63916CVE-2025-63916
CVSS 8.1
MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supp…
CVE-2025-63835CVE-2025-63835
CVSS 8.8
A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform…
CVE-2025-6381CVE-2025-6381
CVSS 8.8
The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file…
CVE-2025-6379CVE-2025-6379
CVSS 8.8
The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_live_fn() fu…
CVE-2025-63748CVE-2025-63748
CVSS 8.8testmanagement
QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restri…
CVE-2025-6374CVE-2025-6374
CVSS 8.8
A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSetACLFilter of the file /goform/formSetAC…
CVE-2025-6373CVE-2025-6373
CVSS 8.8
A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWizard1 of the file /gofor…
CVE-2025-63721CVE-2025-63721
CVSS 8.8
HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit the /rule/add API and thereby achieve R…
CVE-2025-6372CVE-2025-6372
CVSS 8.8
A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the file /goform/formSetWi…
CVE-2025-63712CVE-2025-63712
CVSS 8.8
Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to d…
CVE-2025-6371CVE-2025-6371
CVSS 8.8
A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetEnableWizard of the…
CVE-2025-63705CVE-2025-63705
CVSS 8.8
NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
CVE-2025-6370CVE-2025-6370
CVSS 8.8
A vulnerability classified as critical was found in D-Link DIR-619L 2.06B01. Affected by this vulnerability is the function formWlanGuestSetup of the file /gof…
CVE-2025-6369CVE-2025-6369
CVSS 8.8
A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasysetup of the file /goform/formdumpeasyse…
CVE-2025-63680CVE-2025-63680
CVSS 8.6nero
Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallback exten…
CVE-2025-6368CVE-2025-6368
CVSS 8.8
A vulnerability was found in D-Link DIR-619L 2.06B01. It has been rated as critical. This issue affects the function formSetEmail of the file /goform/formSetEm…
CVE-2025-63675CVE-2025-63675
CVSS 8.8
cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.
CVE-2025-6367CVE-2025-6367
CVSS 8.8
A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unknown code of the file /goform/formSetDoma…
CVE-2025-6366CVE-2025-6366
CVSS 8.8
The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly v…
CVE-2025-63611CVE-2025-63611
CVSS 8.7
Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php a…
CVE-2025-63535CVE-2025-63535
CVSS 8.8
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersuppl…
CVE-2025-63532CVE-2025-63532
CVSS 8.8
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-s…
CVE-2025-63529CVE-2025-63529
CVSS 8.8
A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier …
CVE-2025-63525CVE-2025-63525
CVSS 8.8
An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request t…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.