91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,151–4,200 of 8,161 in High · page 84 of 164

IDTitleSummary
CVE-2025-63434CVE-2025-63434
CVSS 8.8
The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages conta…
CVE-2025-63409CVE-2025-63409
CVSS 8.8gcomtw
Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and ext…
CVE-2025-63406CVE-2025-63406
CVSS 8.8
An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in…
CVE-2025-6337CVE-2025-6337
CVSS 8.8
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared as critical. Affected by this vulnerab…
CVE-2025-6334CVE-2025-6334
CVSS 8.8
A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function strncpy of the component Query String …
CVE-2025-6333CVE-2025-6333
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/adm…
CVE-2025-6332CVE-2025-6332
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functio…
CVE-2025-6331CVE-2025-6331
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of t…
CVE-2025-63307CVE-2025-63307
CVSS 8.1
alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files t…
CVE-2025-63298CVE-2025-63298
CVSS 8.2
A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authen…
CVE-2025-6329CVE-2025-6329
CVSS 8.1
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the…
CVE-2025-6328CVE-2025-6328
CVSS 8.8
A vulnerability was found in D-Link DIR-815 1.01. It has been declared as critical. This vulnerability affects the function sub_403794 of the file hedwig.cgi. …
CVE-2025-6326CVE-2025-6326
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Inset inset allows PHP Lo…
CVE-2025-6321CVE-2025-6321
CVSS 8.8
A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown function…
CVE-2025-6320CVE-2025-6320
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System 1.0. Affected is an unknown function of the file /admin…
CVE-2025-6319CVE-2025-6319
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. This issue affects some unknown processing of…
CVE-2025-6309CVE-2025-6309
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionalit…
CVE-2025-6308CVE-2025-6308
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/b…
CVE-2025-6302CVE-2025-6302
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the function setStaticDhcpConfig of the fi…
CVE-2025-62992CVE-2025-62992
CVSS 8.1
Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/…
CVE-2025-6297CVE-2025-6297
CVSS 8.2debian
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is document…
CVE-2025-6292CVE-2025-6292
CVSS 8.8
A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of the component HTTP POST…
CVE-2025-6291CVE-2025-6291
CVSS 8.8
A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file of the component HTTP POST Request Handl…
CVE-2025-62868CVE-2025-62868
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local …
CVE-2025-6279CVE-2025-6279
CVSS 8.0
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools…
CVE-2025-62786CVE-2025-62786
CVSS 8.1
Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions…
CVE-2025-62777CVE-2025-62777
CVSS 8.8
Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to the affect…
CVE-2025-62775CVE-2025-62775
CVSS 8.0
Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
CVE-2025-62751CVE-2025-62751
CVSS 4.3extendthemes
Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vire…
CVE-2025-62730CVE-2025-62730
CVSS 8.8
SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, …
CVE-2025-62726CVE-2025-62726
CVSS 8.8
n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both …
CVE-2025-62716CVE-2025-62716
CVSS 8.1
Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to …
CVE-2025-62712CVE-2025-62712
CVSS 8.1
JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts…
CVE-2025-62709CVE-2025-62709
CVSS 8.8
ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build …
CVE-2025-62703CVE-2025-62703
CVSS 8.8
Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewrites. In v…
CVE-2025-62673CVE-2025-62673
CVSS 8.0tp-link
Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or poten…
CVE-2025-62643CVE-2025-62643
CVSS 3.4rbi
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.
CVE-2025-62642CVE-2025-62642
CVSS 5.8rbi
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user accoun…
CVE-2025-62641CVE-2025-62641
CVSS 8.2oracle
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi…
CVE-2025-62618CVE-2025-62618
CVSS 8.0
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because E…
CVE-2025-62610CVE-2025-62610
CVSS 8.1hono
Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does …
CVE-2025-62606CVE-2025-62606
CVSS 8.8
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL in…
CVE-2025-62590CVE-2025-62590
CVSS 8.2oracle
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi…
CVE-2025-62589CVE-2025-62589
CVSS 8.2oracle
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi…
CVE-2025-62588CVE-2025-62588
CVSS 8.2oracle
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi…
CVE-2025-62587CVE-2025-62587
CVSS 8.2oracle
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi…
CVE-2025-62577CVE-2025-62577
CVSS 8.8
ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management serv…
CVE-2025-62575CVE-2025-62575
CVSS 8.3mirion
NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have t…
CVE-2025-62550CVE-2025-62550
CVSS 8.8
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
CVE-2025-62549CVE-2025-62549
CVSS 8.8microsoft
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.