91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,201–4,250 of 8,161 in High · page 85 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-62525 | CVE-2025-62525 CVSS 8.8 | OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory usin… |
| CVE-2025-62518 | CVE-2025-62518 CVSS 8.1 | astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability … |
| CVE-2025-62510 | CVE-2025-62510 CVSS 8.1filerise | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibilit… |
| CVE-2025-62509 | CVE-2025-62509 CVSS 8.1filerise | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRi… |
| CVE-2025-62507 | CVE-2025-62507 CVSS 8.8 | Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigg… |
| CVE-2025-62506 | CVE-2025-62506 CVSS 8.1 | MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege escalation vulnerability allows service a… |
| CVE-2025-62501 | CVE-2025-62501 CVSS 8.1 | SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a specially cr… |
| CVE-2025-62498 | CVE-2025-62498 CVSS 8.8 | A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who ca… |
| CVE-2025-62496 | CVE-2025-62496 CVSS 8.8 | A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an exc… |
| CVE-2025-62495 | CVE-2025-62495 CVSS 8.8 | An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size… |
| CVE-2025-62494 | CVE-2025-62494 CVSS 8.8 | A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if the left-h… |
| CVE-2025-62491 | CVE-2025-62491 CVSS 8.8 | A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promises (ts->re… |
| CVE-2025-62490 | CVE-2025-62490 CVSS 8.8 | In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a value is n… |
| CVE-2025-62456 | CVE-2025-62456 CVSS 8.8microsoft | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. |
| CVE-2025-62452 | CVE-2025-62452 CVSS 8.0 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2025-62425 | CVE-2025-62425 CVSS 8.3 | MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in … |
| CVE-2025-62422 | CVE-2025-62422 CVSS 8.8 | DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerab… |
| CVE-2025-62420 | CVE-2025-62420 CVSS 8.8 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database con… |
| CVE-2025-62406 | CVE-2025-62406 CVSS 8.8 | Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-rese… |
| CVE-2025-62405 | CVE-2025-62405 CVSS 8.0 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault … |
| CVE-2025-62404 | CVE-2025-62404 CVSS 8.0 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault … |
| CVE-2025-6238 | CVE-2025-6238 CVSS 8.0 | The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' para… |
| CVE-2025-62360 | CVE-2025-62360 CVSS 8.8wegia | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in … |
| CVE-2025-62291 | CVE-2025-62291 CVSS 8.1 | In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause … |
| CVE-2025-62235 | CVE-2025-62235 CVSS 8.1 | Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-b… |
| CVE-2025-62228 | CVE-2025-62228 CVSS 8.8apache | Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even thro… |
| CVE-2025-62222 | CVE-2025-62222 CVSS 8.8 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacke… |
| CVE-2025-62221 | Microsoft Windows Use After Free Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. |
| CVE-2025-62220 | CVE-2025-62220 CVSS 8.8 | Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. |
| CVE-2025-62215 | Microsoft Windows Race Condition Vulnerability KEVCVSS 7.0Microsoft | Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful expl… |
| CVE-2025-62211 | CVE-2025-62211 CVSS 8.7 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to pe… |
| CVE-2025-62210 | CVE-2025-62210 CVSS 8.7 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to pe… |
| CVE-2025-62204 | CVE-2025-62204 CVSS 8.0 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-6218 | RARLAB WinRAR Path Traversal Vulnerability KEVCVSS 7.8RARLAB | RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user. |
| CVE-2025-62179 | CVE-2025-62179 CVSS 8.8wegia | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in… |
| CVE-2025-62177 | CVE-2025-62177 CVSS 8.8wegia | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in… |
| CVE-2025-62169 | CVE-2025-62169 CVSS 8.1 | OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and… |
| CVE-2025-62164 | CVE-2025-62164 CVSS 8.8 | vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead t… |
| CVE-2025-62156 | CVE-2025-62156 CVSS 8.1argoproj | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 th… |
| CVE-2025-62155 | CVE-2025-62155 CVSS 8.5 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulner… |
| CVE-2025-62093 | CVE-2025-62093 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image&Video FullScreen Background lbg_fullsc… |
| CVE-2025-6207 | CVE-2025-6207 CVSS 8.8 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' functi… |
| CVE-2025-62067 | CVE-2025-62067 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Savory savory.This issue… |
| CVE-2025-62055 | CVE-2025-62055 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Academist academist.This… |
| CVE-2025-62053 | CVE-2025-62053 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez.This issue af… |
| CVE-2025-62045 | CVE-2025-62045 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for… |
| CVE-2025-6204 | Dassault Systèmes DELMIA Apriso Code Injection Vulnerability KEVCVSS 8.0Dassault Systèmes | Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. |
| CVE-2025-62035 | CVE-2025-62035 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
| CVE-2025-62034 | CVE-2025-62034 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
| CVE-2025-62029 | CVE-2025-62029 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themesion Grevo grevo.This issue affec… |