91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,151–4,200 of 8,161 in High · page 84 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-63434 | CVE-2025-63434 CVSS 8.8 | The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages conta… |
| CVE-2025-63409 | CVE-2025-63409 CVSS 8.8gcomtw | Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and ext… |
| CVE-2025-63406 | CVE-2025-63406 CVSS 8.8 | An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in… |
| CVE-2025-6337 | CVE-2025-6337 CVSS 8.8 | A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared as critical. Affected by this vulnerab… |
| CVE-2025-6334 | CVE-2025-6334 CVSS 8.8 | A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function strncpy of the component Query String … |
| CVE-2025-6333 | CVE-2025-6333 CVSS 8.8 | A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/adm… |
| CVE-2025-6332 | CVE-2025-6332 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functio… |
| CVE-2025-6331 | CVE-2025-6331 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of t… |
| CVE-2025-63307 | CVE-2025-63307 CVSS 8.1 | alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files t… |
| CVE-2025-63298 | CVE-2025-63298 CVSS 8.2 | A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authen… |
| CVE-2025-6329 | CVE-2025-6329 CVSS 8.1 | A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the… |
| CVE-2025-6328 | CVE-2025-6328 CVSS 8.8 | A vulnerability was found in D-Link DIR-815 1.01. It has been declared as critical. This vulnerability affects the function sub_403794 of the file hedwig.cgi. … |
| CVE-2025-6326 | CVE-2025-6326 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Inset inset allows PHP Lo… |
| CVE-2025-6321 | CVE-2025-6321 CVSS 8.8 | A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown function… |
| CVE-2025-6320 | CVE-2025-6320 CVSS 8.8 | A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System 1.0. Affected is an unknown function of the file /admin… |
| CVE-2025-6319 | CVE-2025-6319 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. This issue affects some unknown processing of… |
| CVE-2025-6309 | CVE-2025-6309 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionalit… |
| CVE-2025-6308 | CVE-2025-6308 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/b… |
| CVE-2025-6302 | CVE-2025-6302 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the function setStaticDhcpConfig of the fi… |
| CVE-2025-62992 | CVE-2025-62992 CVSS 8.1 | Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/… |
| CVE-2025-6297 | CVE-2025-6297 CVSS 8.2debian | It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is document… |
| CVE-2025-6292 | CVE-2025-6292 CVSS 8.8 | A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of the component HTTP POST… |
| CVE-2025-6291 | CVE-2025-6291 CVSS 8.8 | A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file of the component HTTP POST Request Handl… |
| CVE-2025-62868 | CVE-2025-62868 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local … |
| CVE-2025-6279 | CVE-2025-6279 CVSS 8.0 | A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools… |
| CVE-2025-62786 | CVE-2025-62786 CVSS 8.1 | Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions… |
| CVE-2025-62777 | CVE-2025-62777 CVSS 8.8 | Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to the affect… |
| CVE-2025-62775 | CVE-2025-62775 CVSS 8.0 | Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password. |
| CVE-2025-62751 | CVE-2025-62751 CVSS 4.3extendthemes | Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vire… |
| CVE-2025-62730 | CVE-2025-62730 CVSS 8.8 | SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, … |
| CVE-2025-62726 | CVE-2025-62726 CVSS 8.8 | n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both … |
| CVE-2025-62716 | CVE-2025-62716 CVSS 8.1 | Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_path query parameter allows attackers to … |
| CVE-2025-62712 | CVE-2025-62712 CVSS 8.1 | JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4.10.11-lts… |
| CVE-2025-62709 | CVE-2025-62709 CVSS 8.8 | ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build … |
| CVE-2025-62703 | CVE-2025-62703 CVSS 8.8 | Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewrites. In v… |
| CVE-2025-62673 | CVE-2025-62673 CVSS 8.0tp-link | Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or poten… |
| CVE-2025-62643 | CVE-2025-62643 CVSS 3.4rbi | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages. |
| CVE-2025-62642 | CVE-2025-62642 CVSS 5.8rbi | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user accoun… |
| CVE-2025-62641 | CVE-2025-62641 CVSS 8.2oracle | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi… |
| CVE-2025-62618 | CVE-2025-62618 CVSS 8.0 | ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because E… |
| CVE-2025-62610 | CVE-2025-62610 CVSS 8.1hono | Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does … |
| CVE-2025-62606 | CVE-2025-62606 CVSS 8.8 | my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL in… |
| CVE-2025-62590 | CVE-2025-62590 CVSS 8.2oracle | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi… |
| CVE-2025-62589 | CVE-2025-62589 CVSS 8.2oracle | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi… |
| CVE-2025-62588 | CVE-2025-62588 CVSS 8.2oracle | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi… |
| CVE-2025-62587 | CVE-2025-62587 CVSS 8.2oracle | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easi… |
| CVE-2025-62577 | CVE-2025-62577 CVSS 8.8 | ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management serv… |
| CVE-2025-62575 | CVE-2025-62575 CVSS 8.3mirion | NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have t… |
| CVE-2025-62550 | CVE-2025-62550 CVSS 8.8 | Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. |
| CVE-2025-62549 | CVE-2025-62549 CVSS 8.8microsoft | Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |