91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,351–4,400 of 8,161 in High · page 88 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-60679 | CVE-2025-60679 CVSS 8.8dlink | A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which ha… |
| CVE-2025-60595 | CVE-2025-60595 CVSS 8.2 | SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. |
| CVE-2025-6057 | CVE-2025-6057 CVSS 8.8 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all vers… |
| CVE-2025-60507 | CVE-2025-60507 CVSS 8.9 | Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded J… |
| CVE-2025-60503 | CVE-2025-60503 CVSS 8.7 | A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase func… |
| CVE-2025-60455 | CVE-2025-60455 CVSS 8.4 | Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing att… |
| CVE-2025-6043 | CVE-2025-6043 CVSS 8.1 | The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing capabilit… |
| CVE-2025-60425 | CVE-2025-60425 CVSS 8.6 | Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attac… |
| CVE-2025-6038 | CVE-2025-6038 CVSS 8.8 | The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password up… |
| CVE-2025-60378 | CVE-2025-60378 CVSS 8.1fairsketch | Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content r… |
| CVE-2025-60344 | CVE-2025-60344 CVSS 8.6 | A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used f… |
| CVE-2025-6032 | CVE-2025-6032 CVSS 8.3 | A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue… |
| CVE-2025-60311 | CVE-2025-60311 CVSS 8.8 | ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page |
| CVE-2025-60305 | CVE-2025-60305 CVSS 8.8senior-walter | SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege … |
| CVE-2025-60239 | CVE-2025-60239 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codexpert, Inc CoSchool LMS coschool allows Blind SQL Inj… |
| CVE-2025-60234 | CVE-2025-60234 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Property: fro… |
| CVE-2025-60228 | CVE-2025-60228 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a throug… |
| CVE-2025-60227 | CVE-2025-60227 CVSS 8.6thimpress | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pipes allows Path Traversal.This issue af… |
| CVE-2025-60222 | CVE-2025-60222 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This issue affect… |
| CVE-2025-60215 | CVE-2025-60215 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4. |
| CVE-2025-60212 | CVE-2025-60212 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in designthemes VEDA veda allows Object Injection.This issue affects VEDA: from n/a through <= 4.2. |
| CVE-2025-60211 | CVE-2025-60211 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields allows Pr… |
| CVE-2025-60208 | CVE-2025-60208 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This is… |
| CVE-2025-60199 | CVE-2025-60199 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx InHype - Blog & Magazine WordPr… |
| CVE-2025-60198 | CVE-2025-60198 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dedalx Saxon - Viral Content Blog & Ma… |
| CVE-2025-60197 | CVE-2025-60197 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in owenr88 Simple Contact Forms simple-co… |
| CVE-2025-60190 | CVE-2025-60190 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hinnerk Altenburg Immocaster WordPress… |
| CVE-2025-6013 | CVE-2025-6013 CVSS 8.1 | Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs th… |
| CVE-2025-60126 | CVE-2025-60126 CVSS 8.8 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider testimoni… |
| CVE-2025-60118 | CVE-2025-60118 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Potenzaglobalsolutions PGS Core pgs-core allows SQL Injec… |
| CVE-2025-60116 | CVE-2025-60116 CVSS 8.8 | Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post allows Exploiting Incorrectly Configured … |
| CVE-2025-60111 | CVE-2025-60111 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core javo-core allows Authentication Bypass.This issue affects Javo Core: from n/a through <… |
| CVE-2025-60110 | CVE-2025-60110 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup AllInOne - Banner Rotator all-in-one-bannerR… |
| CVE-2025-60109 | CVE-2025-60109 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider all… |
| CVE-2025-60108 | CVE-2025-60108 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Thumbn… |
| CVE-2025-60107 | CVE-2025-60107 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Playli… |
| CVE-2025-60087 | CVE-2025-60087 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC Addons fo… |
| CVE-2025-60084 | CVE-2025-60084 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Object I… |
| CVE-2025-60083 | CVE-2025-60083 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF Invoice Builder for WooCommerce pdf-for-woocommerce allows Object Injection.This issue affec… |
| CVE-2025-60082 | CVE-2025-60082 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Object Injection.This issue affects PDF for WPForms: from… |
| CVE-2025-60081 | CVE-2025-60081 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Object Injection.This issue affects PDF for… |
| CVE-2025-60072 | CVE-2025-60072 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Processby Anchor smooth scroll anchor-… |
| CVE-2025-60071 | CVE-2025-60071 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in don-themes Riode riode allows PHP Loca… |
| CVE-2025-60069 | CVE-2025-60069 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP… |
| CVE-2025-60067 | CVE-2025-60067 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Giardino giardino allows P… |
| CVE-2025-60066 | CVE-2025-60066 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Katelyn katelyn allows PHP… |
| CVE-2025-60065 | CVE-2025-60065 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Pinevale pinevale allows P… |
| CVE-2025-60064 | CVE-2025-60064 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Renewal renewal allows PHP… |
| CVE-2025-60063 | CVE-2025-60063 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Rosalinda rosalinda allows… |
| CVE-2025-60061 | CVE-2025-60061 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Kicker kicker allows PHP L… |