91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,101–4,150 of 8,161 in High · page 83 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-64140 | CVE-2025-64140 CVSS 8.8jenkins | Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permiss… |
| CVE-2025-6414 | CVE-2025-6414 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Art Gallery Management System 1.1. This vulnerability affects unknown code of the file /admin/ch… |
| CVE-2025-6413 | CVE-2025-6413 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.1. This affects an unknown part of the file /admin/changeim… |
| CVE-2025-64124 | CVE-2025-64124 CVSS 8.8nuvationenergy | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows… |
| CVE-2025-64120 | CVE-2025-64120 CVSS 8.8nuvationenergy | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows… |
| CVE-2025-6412 | CVE-2025-6412 CVSS 8.8 | A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality … |
| CVE-2025-64112 | CVE-2025-64112 CVSS 8.0 | Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with… |
| CVE-2025-6411 | CVE-2025-6411 CVSS 8.8 | A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown funct… |
| CVE-2025-64109 | CVE-2025-64109 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta allowed an attacker to achieve remote code… |
| CVE-2025-64108 | CVE-2025-64108 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent s… |
| CVE-2025-64107 | CVE-2025-64107 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects path manipu… |
| CVE-2025-64106 | CVE-2025-64106 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation enables speci… |
| CVE-2025-64101 | CVE-2025-64101 CVSS 8.8 | Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mecha… |
| CVE-2025-6410 | CVE-2025-6410 CVSS 8.8 | A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected is an unknown function of the file /adm… |
| CVE-2025-64096 | CVE-2025-64096 CVSS 8.8 | CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between … |
| CVE-2025-64091 | CVE-2025-64091 CVSS 8.8 | This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device. |
| CVE-2025-64090 | CVE-2025-64090 CVSS 8.8 | This vulnerability allows authenticated attackers to execute commands via the hostname of the device. |
| CVE-2025-64066 | CVE-2025-64066 CVSS 8.6 | Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authoriza… |
| CVE-2025-64065 | CVE-2025-64065 CVSS 8.8 | The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user imperso… |
| CVE-2025-64064 | CVE-2025-64064 CVSS 8.8 | Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROF… |
| CVE-2025-64062 | CVE-2025-64062 CVSS 8.8 | The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated… |
| CVE-2025-64057 | CVE-2025-64057 CVSS 8.3fanvil | Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and pot… |
| CVE-2025-6402 | CVE-2025-6402 CVSS 8.8 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/f… |
| CVE-2025-6400 | CVE-2025-6400 CVSS 8.8 | A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /… |
| CVE-2025-6399 | CVE-2025-6399 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6… |
| CVE-2025-6397 | CVE-2025-6397 CVSS 8.6 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Hosting Website Design Website Software all… |
| CVE-2025-63916 | CVE-2025-63916 CVSS 8.1 | MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supp… |
| CVE-2025-63835 | CVE-2025-63835 CVSS 8.8 | A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform… |
| CVE-2025-6381 | CVE-2025-6381 CVSS 8.8 | The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file… |
| CVE-2025-6379 | CVE-2025-6379 CVSS 8.8 | The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_live_fn() fu… |
| CVE-2025-63748 | CVE-2025-63748 CVSS 8.8testmanagement | QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restri… |
| CVE-2025-6374 | CVE-2025-6374 CVSS 8.8 | A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSetACLFilter of the file /goform/formSetAC… |
| CVE-2025-6373 | CVE-2025-6373 CVSS 8.8 | A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWizard1 of the file /gofor… |
| CVE-2025-63721 | CVE-2025-63721 CVSS 8.8 | HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit the /rule/add API and thereby achieve R… |
| CVE-2025-6372 | CVE-2025-6372 CVSS 8.8 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the file /goform/formSetWi… |
| CVE-2025-63712 | CVE-2025-63712 CVSS 8.8 | Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to d… |
| CVE-2025-6371 | CVE-2025-6371 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetEnableWizard of the… |
| CVE-2025-63705 | CVE-2025-63705 CVSS 8.8 | NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js. |
| CVE-2025-6370 | CVE-2025-6370 CVSS 8.8 | A vulnerability classified as critical was found in D-Link DIR-619L 2.06B01. Affected by this vulnerability is the function formWlanGuestSetup of the file /gof… |
| CVE-2025-6369 | CVE-2025-6369 CVSS 8.8 | A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasysetup of the file /goform/formdumpeasyse… |
| CVE-2025-63680 | CVE-2025-63680 CVSS 8.6nero | Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallback exten… |
| CVE-2025-6368 | CVE-2025-6368 CVSS 8.8 | A vulnerability was found in D-Link DIR-619L 2.06B01. It has been rated as critical. This issue affects the function formSetEmail of the file /goform/formSetEm… |
| CVE-2025-63675 | CVE-2025-63675 CVSS 8.8 | cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py. |
| CVE-2025-6367 | CVE-2025-6367 CVSS 8.8 | A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unknown code of the file /goform/formSetDoma… |
| CVE-2025-6366 | CVE-2025-6366 CVSS 8.8 | The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not properly v… |
| CVE-2025-63611 | CVE-2025-63611 CVSS 8.7 | Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php a… |
| CVE-2025-63535 | CVE-2025-63535 CVSS 8.8 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersuppl… |
| CVE-2025-63532 | CVE-2025-63532 CVSS 8.8 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-s… |
| CVE-2025-63529 | CVE-2025-63529 CVSS 8.8 | A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier … |
| CVE-2025-63525 | CVE-2025-63525 CVSS 8.8 | An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request t… |