91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,201–4,250 of 8,161 in High · page 85 of 164

IDTitleSummary
CVE-2025-62525CVE-2025-62525
CVSS 8.8
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory usin…
CVE-2025-62518CVE-2025-62518
CVSS 8.1
astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability …
CVE-2025-62510CVE-2025-62510
CVSS 8.1filerise
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder visibilit…
CVE-2025-62509CVE-2025-62509
CVSS 8.1filerise
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRi…
CVE-2025-62507CVE-2025-62507
CVSS 8.8
Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigg…
CVE-2025-62506CVE-2025-62506
CVSS 8.1
MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege escalation vulnerability allows service a…
CVE-2025-62501CVE-2025-62501
CVSS 8.1
SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a specially cr…
CVE-2025-62498CVE-2025-62498
CVSS 8.8
A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who ca…
CVE-2025-62496CVE-2025-62496
CVSS 8.8
A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an exc…
CVE-2025-62495CVE-2025-62495
CVSS 8.8
An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size…
CVE-2025-62494CVE-2025-62494
CVSS 8.8
A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if the left-h…
CVE-2025-62491CVE-2025-62491
CVSS 8.8
A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promises (ts->re…
CVE-2025-62490CVE-2025-62490
CVSS 8.8
In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a value is n…
CVE-2025-62456CVE-2025-62456
CVSS 8.8microsoft
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
CVE-2025-62452CVE-2025-62452
CVSS 8.0
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
CVE-2025-62425CVE-2025-62425
CVSS 8.3
MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in …
CVE-2025-62422CVE-2025-62422
CVSS 8.8
DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerab…
CVE-2025-62420CVE-2025-62420
CVSS 8.8
DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database con…
CVE-2025-62406CVE-2025-62406
CVSS 8.8
Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-rese…
CVE-2025-62405CVE-2025-62405
CVSS 8.0
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault …
CVE-2025-62404CVE-2025-62404
CVSS 8.0
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault …
CVE-2025-6238CVE-2025-6238
CVSS 8.0
The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' para…
CVE-2025-62360CVE-2025-62360
CVSS 8.8wegia
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in …
CVE-2025-62291CVE-2025-62291
CVSS 8.1
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause …
CVE-2025-62235CVE-2025-62235
CVSS 8.1
Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-b…
CVE-2025-62228CVE-2025-62228
CVSS 8.8apache
Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even thro…
CVE-2025-62222CVE-2025-62222
CVSS 8.8
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacke…
CVE-2025-62221Microsoft Windows Use After Free Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
CVE-2025-62220CVE-2025-62220
CVSS 8.8
Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.
CVE-2025-62215Microsoft Windows Race Condition Vulnerability
KEVCVSS 7.0Microsoft
Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful expl…
CVE-2025-62211CVE-2025-62211
CVSS 8.7
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to pe…
CVE-2025-62210CVE-2025-62210
CVSS 8.7
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to pe…
CVE-2025-62204CVE-2025-62204
CVSS 8.0
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-6218RARLAB WinRAR Path Traversal Vulnerability
KEVCVSS 7.8RARLAB
RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-62179CVE-2025-62179
CVSS 8.8wegia
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in…
CVE-2025-62177CVE-2025-62177
CVSS 8.8wegia
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in…
CVE-2025-62169CVE-2025-62169
CVSS 8.1
OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and…
CVE-2025-62164CVE-2025-62164
CVSS 8.8
vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead t…
CVE-2025-62156CVE-2025-62156
CVSS 8.1argoproj
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 th…
CVE-2025-62155CVE-2025-62155
CVSS 8.5
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulner…
CVE-2025-62093CVE-2025-62093
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Image&Video FullScreen Background lbg_fullsc…
CVE-2025-6207CVE-2025-6207
CVSS 8.8
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' functi…
CVE-2025-62067CVE-2025-62067
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Savory savory.This issue…
CVE-2025-62055CVE-2025-62055
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Academist academist.This…
CVE-2025-62053CVE-2025-62053
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez houzez.This issue af…
CVE-2025-62045CVE-2025-62045
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for…
CVE-2025-6204Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
KEVCVSS 8.0Dassault Systèmes
Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
CVE-2025-62035CVE-2025-62035
CVSS 8.8
Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
CVE-2025-62034CVE-2025-62034
CVSS 8.8
Incorrect Privilege Assignment vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.
CVE-2025-62029CVE-2025-62029
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themesion Grevo grevo.This issue affec…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.