91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,301–4,350 of 8,161 in High · page 87 of 164

IDTitleSummary
CVE-2025-61429CVE-2025-61429
CVSS 8.8
An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request.
CVE-2025-61417CVE-2025-61417
CVSS 8.8
Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file …
CVE-2025-6138CVE-2025-6138
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin…
CVE-2025-6137CVE-2025-6137
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cg…
CVE-2025-6130CVE-2025-6130
CVSS 8.8
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the…
CVE-2025-6129CVE-2025-6129
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formSa…
CVE-2025-6128CVE-2025-6128
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWireless…
CVE-2025-61247CVE-2025-61247
CVSS 8.2
indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php.
CVE-2025-6122CVE-2025-6122
CVSS 8.8
A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects an unknown part of the file /table.php.…
CVE-2025-61197CVE-2025-61197
CVSS 8.9
An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 allows a remote att…
CVE-2025-61196CVE-2025-61196
CVSS 8.8
An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter.
CVE-2025-61161CVE-2025-61161
CVSS 8.4
DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\…
CVE-2025-6115CVE-2025-6115
CVSS 8.8
A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function form_macfilter. The manipulation of the…
CVE-2025-6114CVE-2025-6114
CVSS 8.8
A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is the function form_portforwarding of the…
CVE-2025-6113CVE-2025-6113
CVSS 8.8
A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip.…
CVE-2025-6112CVE-2025-6112
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the function fromadvsetlanip of the file /goform/…
CVE-2025-6111CVE-2025-6111
CVSS 8.8
A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromVirtualSer of the file /goform/Virtu…
CVE-2025-6110CVE-2025-6110
CVSS 8.8
A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the file /goform/SafeMacFilter. The manipu…
CVE-2025-61075CVE-2025-61075
CVSS 8.1
Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry o…
CVE-2025-6105CVE-2025-6105
CVSS 8.8
A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.java. The ma…
CVE-2025-6104CVE-2025-6104
CVSS 8.8
A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/p…
CVE-2025-6103CVE-2025-6103
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functio…
CVE-2025-6102CVE-2025-6102
CVSS 8.8
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of t…
CVE-2025-60991CVE-2025-60991
CVSS 8.8
A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the contex…
CVE-2025-60963CVE-2025-60963
CVSS 8.2endruntechnologies
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary…
CVE-2025-60962CVE-2025-60962
CVSS 8.2endruntechnologies
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive in…
CVE-2025-60960CVE-2025-60960
CVSS 8.2endruntechnologies
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary…
CVE-2025-6096CVE-2025-6096
CVSS 8.8
A vulnerability has been found in codesiddhant Jasmin Ransomware up to 1.0.1 and classified as critical. Affected by this vulnerability is an unknown functiona…
CVE-2025-60959CVE-2025-60959
CVSS 8.2endruntechnologies
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive in…
CVE-2025-60956CVE-2025-60956
CVSS 8.0endruntechnologies
Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to exec…
CVE-2025-60954CVE-2025-60954
CVSS 8.3
Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set…
CVE-2025-60947CVE-2025-60947
CVSS 8.8
Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fix…
CVE-2025-60946CVE-2025-60946
CVSS 8.8
Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha.
CVE-2025-6094CVE-2025-6094
CVSS 8.8
A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file app/admi…
CVE-2025-60915CVE-2025-60915
CVSS 8.1
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversa…
CVE-2025-6091CVE-2025-6091
CVSS 8.8
A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of t…
CVE-2025-6090CVE-2025-6090
CVSS 8.8
A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function UpdateWanparamsMulti/UpdateIpv6params of the…
CVE-2025-60880CVE-2025-60880
CVSS 8.3
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file co…
CVE-2025-60801CVE-2025-60801
CVSS 8.2
jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.
CVE-2025-6080CVE-2025-6080
CVSS 8.8
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.…
CVE-2025-6079CVE-2025-6079
CVSS 8.8
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the homework.php…
CVE-2025-60786CVE-2025-60786
CVSS 8.8kagilum
A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip…
CVE-2025-60785CVE-2025-60785
CVSS 8.8
A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a cr…
CVE-2025-6076CVE-2025-6076
CVSS 8.8
Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated atta…
CVE-2025-60715CVE-2025-60715
CVSS 8.0
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
CVE-2025-60710Microsoft Windows Link Following Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CVE-2025-60696CVE-2025-60696
CVSS 8.4linksys
A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012). The arplookup fun…
CVE-2025-60692CVE-2025-60692
CVSS 8.4linksys
A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The fu…
CVE-2025-60691CVE-2025-60691
CVSS 8.8linksys
A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functi…
CVE-2025-60690CVE-2025-60690
CVSS 8.8linksys
A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). T…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.