91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,251–4,300 of 8,161 in High · page 86 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-62014 | CVE-2025-62014 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme ITok itok.This issue affects… |
| CVE-2025-62010 | CVE-2025-62010 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Famita famita allows PHP Loc… |
| CVE-2025-62008 | CVE-2025-62008 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.This issue affects Product Table For Woo… |
| CVE-2025-62007 | CVE-2025-62007 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a … |
| CVE-2025-62002 | CVE-2025-62002 CVSS 8.1 | BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) … |
| CVE-2025-62001 | CVE-2025-62001 CVSS 8.8 | BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain… |
| CVE-2025-61983 | CVE-2025-61983 CVSS 8.0 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault … |
| CVE-2025-61973 | CVE-2025-61973 CVSS 8.8 | A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL f… |
| CVE-2025-61958 | CVE-2025-61958 CVSS 8.7f5 | A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions … |
| CVE-2025-61955 | CVE-2025-61955 CVSS 8.8 | A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges. A successful expl… |
| CVE-2025-61944 | CVE-2025-61944 CVSS 8.0 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault … |
| CVE-2025-61940 | CVE-2025-61940 CVSS 8.3mirion | NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User access in the client application is res… |
| CVE-2025-61930 | CVE-2025-61930 CVSS 8.8 | Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password chan… |
| CVE-2025-6192 | CVE-2025-6192 CVSS 8.8 | Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (C… |
| CVE-2025-6191 | CVE-2025-6191 CVSS 8.8 | Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML… |
| CVE-2025-6190 | CVE-2025-6190 CVSS 8.8 | The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the rp_user_profile() AJAX handler in … |
| CVE-2025-61884 | CVE-2025-61884 KEVCVSS 7.5oracle | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. … |
| CVE-2025-61880 | CVE-2025-61880 CVSS 8.8 | In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution. |
| CVE-2025-6184 | CVE-2025-6184 CVSS 8.8 | The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used in the g… |
| CVE-2025-61821 | CVE-2025-61821 CVSS 6.8adobe | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that co… |
| CVE-2025-61813 | CVE-2025-61813 CVSS 7.4adobe | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that co… |
| CVE-2025-61812 | CVE-2025-61812 CVSS 8.4adobe | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker… |
| CVE-2025-61810 | CVE-2025-61810 CVSS 8.4adobe | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code … |
| CVE-2025-61787 | CVE-2025-61787 CVSS 8.1deno | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when … |
| CVE-2025-61784 | CVE-2025-61784 CVSS 7.6hiyouga | LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows … |
| CVE-2025-61773 | CVE-2025-61773 CVSS 8.1 | pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input vali… |
| CVE-2025-61763 | CVE-2025-61763 CVSS 8.1oracle | Vulnerability in Oracle Essbase (component: Essbase Web Platform). The supported version that is affected is 21.7.3.0.0. Easily exploitable vulnerability all… |
| CVE-2025-61751 | CVE-2025-61751 CVSS 8.1oracle | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). … |
| CVE-2025-61732 | CVE-2025-61732 CVSS 8.6golang | A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary. |
| CVE-2025-61687 | CVE-2025-61687 CVSS 8.3flowiseai | Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI allows authe… |
| CVE-2025-61673 | CVE-2025-61673 CVSS 8.6 | Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authentication bypass vulnerability when confi… |
| CVE-2025-6165 | CVE-2025-6165 CVSS 8.8 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/f… |
| CVE-2025-6164 | CVE-2025-6164 CVSS 8.8 | A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an unknown part of the file /boafrm/formMul… |
| CVE-2025-6163 | CVE-2025-6163 CVSS 8.8 | A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is some unknown functionality of the file… |
| CVE-2025-6162 | CVE-2025-6162 CVSS 8.8 | A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionalit… |
| CVE-2025-61593 | CVE-2025-61593 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e… |
| CVE-2025-61592 | CVE-2025-61592 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current work… |
| CVE-2025-61591 | CVE-2025-61591 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker … |
| CVE-2025-6158 | CVE-2025-6158 CVSS 8.8 | A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the component HTTP POST Request Handler. Th… |
| CVE-2025-6156 | CVE-2025-6156 CVSS 8.8 | A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unkno… |
| CVE-2025-61553 | CVE-2025-61553 CVSS 8.2 | An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to c… |
| CVE-2025-61536 | CVE-2025-61536 CVSS 8.2 | FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. A… |
| CVE-2025-6150 | CVE-2025-6150 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this vulnerability is an unknown functionality of the file /… |
| CVE-2025-6149 | CVE-2025-6149 CVSS 8.8 | A vulnerability classified as critical has been found in TOTOLINK A3002R 4.0.0-B20230531.1404. Affected is an unknown function of the file /boafrm/formSysLog o… |
| CVE-2025-6148 | CVE-2025-6148 CVSS 8.8 | A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. It has been rated as critical. This issue affects some unknown processing of the file /boaf… |
| CVE-2025-6147 | CVE-2025-6147 CVSS 8.8 | A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm… |
| CVE-2025-6146 | CVE-2025-6146 CVSS 8.8 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. This affects an unknown part of the file /boafrm/formSysLog… |
| CVE-2025-6145 | CVE-2025-6145 CVSS 8.8 | A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the fi… |
| CVE-2025-6144 | CVE-2025-6144 CVSS 8.8 | A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionalit… |
| CVE-2025-6143 | CVE-2025-6143 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/fo… |