91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,251–4,300 of 8,161 in High · page 86 of 164

IDTitleSummary
CVE-2025-62014CVE-2025-62014
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme ITok itok.This issue affects…
CVE-2025-62010CVE-2025-62010
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Famita famita allows PHP Loc…
CVE-2025-62008CVE-2025-62008
CVSS 8.8
Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.This issue affects Product Table For Woo…
CVE-2025-62007CVE-2025-62007
CVSS 8.8
Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a …
CVE-2025-62002CVE-2025-62002
CVSS 8.1
BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) …
CVE-2025-62001CVE-2025-62001
CVSS 8.8
BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain…
CVE-2025-61983CVE-2025-61983
CVSS 8.0
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault …
CVE-2025-61973CVE-2025-61973
CVSS 8.8
A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL f…
CVE-2025-61958CVE-2025-61958
CVSS 8.7f5
A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions …
CVE-2025-61955CVE-2025-61955
CVSS 8.8
A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges.  A successful expl…
CVE-2025-61944CVE-2025-61944
CVSS 8.0
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault …
CVE-2025-61940CVE-2025-61940
CVSS 8.3mirion
NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is res…
CVE-2025-61930CVE-2025-61930
CVSS 8.8
Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password chan…
CVE-2025-6192CVE-2025-6192
CVSS 8.8
Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (C…
CVE-2025-6191CVE-2025-6191
CVSS 8.8
Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML…
CVE-2025-6190CVE-2025-6190
CVSS 8.8
The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the rp_user_profile() AJAX handler in …
CVE-2025-61884CVE-2025-61884
KEVCVSS 7.5oracle
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. …
CVE-2025-61880CVE-2025-61880
CVSS 8.8
In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
CVE-2025-6184CVE-2025-6184
CVSS 8.8
The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used in the g…
CVE-2025-61821CVE-2025-61821
CVSS 6.8adobe
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that co…
CVE-2025-61813CVE-2025-61813
CVSS 7.4adobe
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that co…
CVE-2025-61812CVE-2025-61812
CVSS 8.4adobe
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker…
CVE-2025-61810CVE-2025-61810
CVSS 8.4adobe
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code …
CVE-2025-61787CVE-2025-61787
CVSS 8.1deno
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when …
CVE-2025-61784CVE-2025-61784
CVSS 7.6hiyouga
LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows …
CVE-2025-61773CVE-2025-61773
CVSS 8.1
pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input vali…
CVE-2025-61763CVE-2025-61763
CVSS 8.1oracle
Vulnerability in Oracle Essbase (component: Essbase Web Platform). The supported version that is affected is 21.7.3.0.0. Easily exploitable vulnerability all…
CVE-2025-61751CVE-2025-61751
CVSS 8.1oracle
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). …
CVE-2025-61732CVE-2025-61732
CVSS 8.6golang
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVE-2025-61687CVE-2025-61687
CVSS 8.3flowiseai
Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI allows authe…
CVE-2025-61673CVE-2025-61673
CVSS 8.6
Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authentication bypass vulnerability when confi…
CVE-2025-6165CVE-2025-6165
CVSS 8.8
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/f…
CVE-2025-6164CVE-2025-6164
CVSS 8.8
A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an unknown part of the file /boafrm/formMul…
CVE-2025-6163CVE-2025-6163
CVSS 8.8
A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is some unknown functionality of the file…
CVE-2025-6162CVE-2025-6162
CVSS 8.8
A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionalit…
CVE-2025-61593CVE-2025-61593
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e…
CVE-2025-61592CVE-2025-61592
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current work…
CVE-2025-61591CVE-2025-61591
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker …
CVE-2025-6158CVE-2025-6158
CVSS 8.8
A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the component HTTP POST Request Handler. Th…
CVE-2025-6156CVE-2025-6156
CVSS 8.8
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unkno…
CVE-2025-61553CVE-2025-61553
CVSS 8.2
An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to c…
CVE-2025-61536CVE-2025-61536
CVSS 8.2
FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. A…
CVE-2025-6150CVE-2025-6150
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this vulnerability is an unknown functionality of the file /…
CVE-2025-6149CVE-2025-6149
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK A3002R 4.0.0-B20230531.1404. Affected is an unknown function of the file /boafrm/formSysLog o…
CVE-2025-6148CVE-2025-6148
CVSS 8.8
A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. It has been rated as critical. This issue affects some unknown processing of the file /boaf…
CVE-2025-6147CVE-2025-6147
CVSS 8.8
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm…
CVE-2025-6146CVE-2025-6146
CVSS 8.8
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. This affects an unknown part of the file /boafrm/formSysLog…
CVE-2025-6145CVE-2025-6145
CVSS 8.8
A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the fi…
CVE-2025-6144CVE-2025-6144
CVSS 8.8
A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionalit…
CVE-2025-6143CVE-2025-6143
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/fo…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.