91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,401–4,450 of 8,161 in High · page 89 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-60060 | CVE-2025-60060 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Pubzinne pubzinne allows P… |
| CVE-2025-60059 | CVE-2025-60059 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows … |
| CVE-2025-60058 | CVE-2025-60058 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes DetailX detailx allows PH… |
| CVE-2025-60057 | CVE-2025-60057 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes DJ Rainflow dj-rainflow a… |
| CVE-2025-60056 | CVE-2025-60056 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Winger winger allows PHP … |
| CVE-2025-60055 | CVE-2025-60055 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Fabrica fabrica allows PH… |
| CVE-2025-60054 | CVE-2025-60054 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes OnLeash onleash allows PH… |
| CVE-2025-60053 | CVE-2025-60053 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MaxCube maxcube allows PH… |
| CVE-2025-60052 | CVE-2025-60052 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes W&D wd allows PHP Local F… |
| CVE-2025-60051 | CVE-2025-60051 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Rare Radio rareradio allo… |
| CVE-2025-60050 | CVE-2025-60050 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Panda panda allows PHP Loc… |
| CVE-2025-60049 | CVE-2025-60049 CVSS 8.1axiomthemes | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Soleil soleil allows PHP L… |
| CVE-2025-60048 | CVE-2025-60048 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Tripster tripster allows P… |
| CVE-2025-60047 | CVE-2025-60047 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes IPharm ipharm allows PHP L… |
| CVE-2025-60046 | CVE-2025-60046 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes HeartStar heartstar allows… |
| CVE-2025-60044 | CVE-2025-60044 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Fribbo fribbo allows PHP … |
| CVE-2025-60043 | CVE-2025-60043 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wanderic wanderic allows … |
| CVE-2025-60042 | CVE-2025-60042 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Chinchilla chinchilla all… |
| CVE-2025-60041 | CVE-2025-60041 CVSS 8.8 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all allows Password Recovery Exploitation.T… |
| CVE-2025-60038 | CVE-2025-60038 CVSS 8.8 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated… |
| CVE-2025-60037 | CVE-2025-60037 CVSS 8.8 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated… |
| CVE-2025-60036 | CVE-2025-60036 CVSS 8.8 | A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw … |
| CVE-2025-60035 | CVE-2025-60035 CVSS 8.8 | A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw… |
| CVE-2025-60024 | CVE-2025-60024 CVSS 8.8fortinet | Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 th… |
| CVE-2025-60017 | CVE-2025-60017 CVSS 8.2 | Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within rest… |
| CVE-2025-6001 | CVE-2025-6001 CVSS 8.3 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacke… |
| CVE-2025-59974 | CVE-2025-59974 CVSS 8.4juniper | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to in… |
| CVE-2025-5997 | CVE-2025-5997 CVSS 8.8 | Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro: before 7.5.4.2. |
| CVE-2025-59968 | CVE-2025-59968 CVSS 8.6 | A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify … |
| CVE-2025-59945 | CVE-2025-59945 CVSS 8.1 | SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can … |
| CVE-2025-59939 | CVE-2025-59939 CVSS 8.8 | WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks in the control.php endpoint with the f… |
| CVE-2025-59932 | CVE-2025-59932 CVSS 8.2 | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests w… |
| CVE-2025-59894 | CVE-2025-59894 CVSS 8.0 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause… |
| CVE-2025-59893 | CVE-2025-59893 CVSS 8.0 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause… |
| CVE-2025-59892 | CVE-2025-59892 CVSS 8.0 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause… |
| CVE-2025-59891 | CVE-2025-59891 CVSS 8.0 | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause… |
| CVE-2025-59889 | CVE-2025-59889 CVSS 8.6 | Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the softw… |
| CVE-2025-59887 | CVE-2025-59887 CVSS 8.6eaton | Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to… |
| CVE-2025-59886 | CVE-2025-59886 CVSS 8.8 | Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device execut… |
| CVE-2025-5987 | CVE-2025-5987 CVSS 8.1libssh | A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detecte… |
| CVE-2025-59845 | CVE-2025-59845 CVSS 8.2 | Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and… |
| CVE-2025-59840 | CVE-2025-59840 CVSS 8.1 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 6.2.0, appl… |
| CVE-2025-59831 | CVE-2025-59831 CVSS 8.8 | git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerabil… |
| CVE-2025-59817 | CVE-2025-59817 CVSS 8.4 | This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploi… |
| CVE-2025-59815 | CVE-2025-59815 CVSS 8.4 | This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting shell acce… |
| CVE-2025-59814 | CVE-2025-59814 CVSS 8.8 | This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them to read t… |
| CVE-2025-5978 | CVE-2025-5978 CVSS 8.8 | A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer.… |
| CVE-2025-59713 | CVE-2025-59713 CVSS 8.1 | Snipe-IT before 8.1.18 allows unsafe deserialization. |
| CVE-2025-59711 | CVE-2025-59711 CVSS 8.3kovai | An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to w… |
| CVE-2025-59710 | CVE-2025-59710 CVSS 8.8kovai | An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading,… |