91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,401–4,450 of 8,161 in High · page 89 of 164

IDTitleSummary
CVE-2025-60060CVE-2025-60060
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Pubzinne pubzinne allows P…
CVE-2025-60059CVE-2025-60059
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows …
CVE-2025-60058CVE-2025-60058
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes DetailX detailx allows PH…
CVE-2025-60057CVE-2025-60057
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes DJ Rainflow dj-rainflow a…
CVE-2025-60056CVE-2025-60056
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Winger winger allows PHP …
CVE-2025-60055CVE-2025-60055
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Fabrica fabrica allows PH…
CVE-2025-60054CVE-2025-60054
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes OnLeash onleash allows PH…
CVE-2025-60053CVE-2025-60053
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MaxCube maxcube allows PH…
CVE-2025-60052CVE-2025-60052
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes W&D wd allows PHP Local F…
CVE-2025-60051CVE-2025-60051
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Rare Radio rareradio allo…
CVE-2025-60050CVE-2025-60050
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Panda panda allows PHP Loc…
CVE-2025-60049CVE-2025-60049
CVSS 8.1axiomthemes
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Soleil soleil allows PHP L…
CVE-2025-60048CVE-2025-60048
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Tripster tripster allows P…
CVE-2025-60047CVE-2025-60047
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes IPharm ipharm allows PHP L…
CVE-2025-60046CVE-2025-60046
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes HeartStar heartstar allows…
CVE-2025-60044CVE-2025-60044
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Fribbo fribbo allows PHP …
CVE-2025-60043CVE-2025-60043
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wanderic wanderic allows …
CVE-2025-60042CVE-2025-60042
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Chinchilla chinchilla all…
CVE-2025-60041CVE-2025-60041
CVSS 8.8
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all allows Password Recovery Exploitation.T…
CVE-2025-60038CVE-2025-60038
CVSS 8.8
A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated…
CVE-2025-60037CVE-2025-60037
CVSS 8.8
A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated…
CVE-2025-60036CVE-2025-60036
CVSS 8.8
A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw …
CVE-2025-60035CVE-2025-60035
CVSS 8.8
A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw…
CVE-2025-60024CVE-2025-60024
CVSS 8.8fortinet
Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 th…
CVE-2025-60017CVE-2025-60017
CVSS 8.2
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within rest…
CVE-2025-6001CVE-2025-6001
CVSS 8.3
A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacke…
CVE-2025-59974CVE-2025-59974
CVSS 8.4juniper
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to in…
CVE-2025-5997CVE-2025-5997
CVSS 8.8
Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro: before 7.5.4.2.
CVE-2025-59968CVE-2025-59968
CVSS 8.6
A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify …
CVE-2025-59945CVE-2025-59945
CVSS 8.1
SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) users can …
CVE-2025-59939CVE-2025-59939
CVSS 8.8
WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks in the control.php endpoint with the f…
CVE-2025-59932CVE-2025-59932
CVSS 8.2
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests w…
CVE-2025-59894CVE-2025-59894
CVSS 8.0
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause…
CVE-2025-59893CVE-2025-59893
CVSS 8.0
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause…
CVE-2025-59892CVE-2025-59892
CVSS 8.0
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause…
CVE-2025-59891CVE-2025-59891
CVSS 8.0
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause…
CVE-2025-59889CVE-2025-59889
CVSS 8.6
Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the softw…
CVE-2025-59887CVE-2025-59887
CVSS 8.6eaton
Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to…
CVE-2025-59886CVE-2025-59886
CVSS 8.8
Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device execut…
CVE-2025-5987CVE-2025-5987
CVSS 8.1libssh
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detecte…
CVE-2025-59845CVE-2025-59845
CVSS 8.2
Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and…
CVE-2025-59840CVE-2025-59840
CVSS 8.1
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 6.2.0, appl…
CVE-2025-59831CVE-2025-59831
CVSS 8.8
git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerabil…
CVE-2025-59817CVE-2025-59817
CVSS 8.4
This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploi…
CVE-2025-59815CVE-2025-59815
CVSS 8.4
This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting shell acce…
CVE-2025-59814CVE-2025-59814
CVSS 8.8
This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them to read t…
CVE-2025-5978CVE-2025-5978
CVSS 8.8
A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer.…
CVE-2025-59713CVE-2025-59713
CVSS 8.1
Snipe-IT before 8.1.18 allows unsafe deserialization.
CVE-2025-59711CVE-2025-59711
CVSS 8.3kovai
An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism, an authenticated attacker is able to w…
CVE-2025-59710CVE-2025-59710
CVSS 8.8kovai
An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading,…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.