91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,301–4,350 of 8,161 in High · page 87 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-61429 | CVE-2025-61429 CVSS 8.8 | An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request. |
| CVE-2025-61417 | CVE-2025-61417 CVSS 8.8 | Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file … |
| CVE-2025-6138 | CVE-2025-6138 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin… |
| CVE-2025-6137 | CVE-2025-6137 CVSS 8.8 | A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cg… |
| CVE-2025-6130 | CVE-2025-6130 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the… |
| CVE-2025-6129 | CVE-2025-6129 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formSa… |
| CVE-2025-6128 | CVE-2025-6128 CVSS 8.8 | A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWireless… |
| CVE-2025-61247 | CVE-2025-61247 CVSS 8.2 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php. |
| CVE-2025-6122 | CVE-2025-6122 CVSS 8.8 | A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects an unknown part of the file /table.php.… |
| CVE-2025-61197 | CVE-2025-61197 CVSS 8.9 | An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 allows a remote att… |
| CVE-2025-61196 | CVE-2025-61196 CVSS 8.8 | An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter. |
| CVE-2025-61161 | CVE-2025-61161 CVSS 8.4 | DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\… |
| CVE-2025-6115 | CVE-2025-6115 CVSS 8.8 | A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function form_macfilter. The manipulation of the… |
| CVE-2025-6114 | CVE-2025-6114 CVSS 8.8 | A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is the function form_portforwarding of the… |
| CVE-2025-6113 | CVE-2025-6113 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip.… |
| CVE-2025-6112 | CVE-2025-6112 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the function fromadvsetlanip of the file /goform/… |
| CVE-2025-6111 | CVE-2025-6111 CVSS 8.8 | A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromVirtualSer of the file /goform/Virtu… |
| CVE-2025-6110 | CVE-2025-6110 CVSS 8.8 | A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the file /goform/SafeMacFilter. The manipu… |
| CVE-2025-61075 | CVE-2025-61075 CVSS 8.1 | Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry o… |
| CVE-2025-6105 | CVE-2025-6105 CVSS 8.8 | A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.java. The ma… |
| CVE-2025-6104 | CVE-2025-6104 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/p… |
| CVE-2025-6103 | CVE-2025-6103 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functio… |
| CVE-2025-6102 | CVE-2025-6102 CVSS 8.8 | A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of t… |
| CVE-2025-60991 | CVE-2025-60991 CVSS 8.8 | A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the contex… |
| CVE-2025-60963 | CVE-2025-60963 CVSS 8.2endruntechnologies | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary… |
| CVE-2025-60962 | CVE-2025-60962 CVSS 8.2endruntechnologies | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive in… |
| CVE-2025-60960 | CVE-2025-60960 CVSS 8.2endruntechnologies | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary… |
| CVE-2025-6096 | CVE-2025-6096 CVSS 8.8 | A vulnerability has been found in codesiddhant Jasmin Ransomware up to 1.0.1 and classified as critical. Affected by this vulnerability is an unknown functiona… |
| CVE-2025-60959 | CVE-2025-60959 CVSS 8.2endruntechnologies | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive in… |
| CVE-2025-60956 | CVE-2025-60956 CVSS 8.0endruntechnologies | Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to exec… |
| CVE-2025-60954 | CVE-2025-60954 CVSS 8.3 | Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set… |
| CVE-2025-60947 | CVE-2025-60947 CVSS 8.8 | Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fix… |
| CVE-2025-60946 | CVE-2025-60946 CVSS 8.8 | Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha. |
| CVE-2025-6094 | CVE-2025-6094 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file app/admi… |
| CVE-2025-60915 | CVE-2025-60915 CVSS 8.1 | An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversa… |
| CVE-2025-6091 | CVE-2025-6091 CVSS 8.8 | A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of t… |
| CVE-2025-6090 | CVE-2025-6090 CVSS 8.8 | A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function UpdateWanparamsMulti/UpdateIpv6params of the… |
| CVE-2025-60880 | CVE-2025-60880 CVSS 8.3 | An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file co… |
| CVE-2025-60801 | CVE-2025-60801 CVSS 8.2 | jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function. |
| CVE-2025-6080 | CVE-2025-6080 CVSS 8.8 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and including, 67.… |
| CVE-2025-6079 | CVE-2025-6079 CVSS 8.8 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the homework.php… |
| CVE-2025-60786 | CVE-2025-60786 CVSS 8.8kagilum | A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted Zip… |
| CVE-2025-60785 | CVE-2025-60785 CVSS 8.8 | A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a cr… |
| CVE-2025-6076 | CVE-2025-6076 CVSS 8.8 | Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated atta… |
| CVE-2025-60715 | CVE-2025-60715 CVSS 8.0 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| CVE-2025-60710 | Microsoft Windows Link Following Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows contains a link following vulnerability that allows for privilege escalation |
| CVE-2025-60696 | CVE-2025-60696 CVSS 8.4linksys | A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012). The arplookup fun… |
| CVE-2025-60692 | CVE-2025-60692 CVSS 8.4linksys | A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The fu… |
| CVE-2025-60691 | CVE-2025-60691 CVSS 8.8linksys | A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functi… |
| CVE-2025-60690 | CVE-2025-60690 CVSS 8.8linksys | A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). T… |