91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,451–4,500 of 8,161 in High · page 90 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-5971 | CVE-2025-5971 CVSS 8.8 | A vulnerability was found in code-projects School Fees Payment System 1.0. It has been classified as critical. This affects an unknown part of the file /ajx.ph… |
| CVE-2025-5969 | CVE-2025-5969 CVSS 8.8 | A vulnerability has been found in D-Link DIR-632 FW103B08 and classified as critical. Affected by this vulnerability is the function FUN_00425fd8 of the file /… |
| CVE-2025-59684 | CVE-2025-59684 CVSS 8.8 | DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking. |
| CVE-2025-5966 | CVE-2025-5966 CVSS 8.1 | Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. |
| CVE-2025-5959 | CVE-2025-5959 CVSS 8.8 | Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… |
| CVE-2025-59580 | CVE-2025-59580 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in GoodLayers Goodlayers Core goodlayers-core allows Privilege Escalation.This issue affects Goodlayers Core: from… |
| CVE-2025-5958 | CVE-2025-5958 CVSS 8.8 | Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
| CVE-2025-59572 | CVE-2025-59572 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Forgery.This issue affects WorkScout-Core… |
| CVE-2025-59564 | CVE-2025-59564 CVSS 8.1thememove | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall allows PHP L… |
| CVE-2025-5956 | CVE-2025-5956 CVSS 8.1 | The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_employee()… |
| CVE-2025-59558 | CVE-2025-59558 CVSS 8.1thememove | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Loc… |
| CVE-2025-59555 | CVE-2025-59555 CVSS 8.1thememove | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Medizin medizin allows PHP L… |
| CVE-2025-59550 | CVE-2025-59550 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allows PHP Lo… |
| CVE-2025-5955 | CVE-2025-5955 CVSS 8.1 | The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugi… |
| CVE-2025-59541 | CVE-2025-59541 CVSS 8.1 | Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects insi… |
| CVE-2025-59536 | CVE-2025-59536 CVSS 8.8anthropic | Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claud… |
| CVE-2025-5953 | CVE-2025-5953 CVSS 8.8 | The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and upda… |
| CVE-2025-59518 | CVE-2025-59518 CVSS 8.0 | In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluat… |
| CVE-2025-59500 | CVE-2025-59500 CVSS 7.7microsoft | Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-59499 | CVE-2025-59499 CVSS 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n… |
| CVE-2025-5949 | CVE-2025-5949 CVSS 8.8 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is … |
| CVE-2025-59487 | CVE-2025-59487 CVSS 8.0 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault … |
| CVE-2025-59484 | CVE-2025-59484 CVSS 8.3 | The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that t… |
| CVE-2025-59482 | CVE-2025-59482 CVSS 8.0 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault … |
| CVE-2025-59481 | CVE-2025-59481 CVSS 8.7f5 | A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource adm… |
| CVE-2025-59430 | CVE-2025-59430 CVSS 8.2 | Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitization of URLs protocols in the createLi… |
| CVE-2025-5943 | CVE-2025-5943 CVSS 8.8 | MicroDicom DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary c… |
| CVE-2025-5934 | CVE-2025-5934 CVSS 8.8 | A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function sub_41619C of the file /mtd. The manip… |
| CVE-2025-59334 | CVE-2025-59334 CVSS 8.8 | Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authenticity of … |
| CVE-2025-59333 | CVE-2025-59333 CVSS 8.1 | The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate secu… |
| CVE-2025-59332 | CVE-2025-59332 CVSS 8.6 | 3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser function allow users to provide custom attri… |
| CVE-2025-5931 | CVE-2025-5931 CVSS 8.8 | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due to the p… |
| CVE-2025-59295 | CVE-2025-59295 CVSS 8.8 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. |
| CVE-2025-59292 | CVE-2025-59292 CVSS 8.2microsoft | External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59291 | CVE-2025-59291 CVSS 8.2microsoft | External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59271 | CVE-2025-59271 CVSS 8.7 | Redis Enterprise Elevation of Privilege Vulnerability |
| CVE-2025-59250 | CVE-2025-59250 CVSS 8.1 | Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-59249 | CVE-2025-59249 CVSS 8.8microsoft | Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-59237 | CVE-2025-59237 CVSS 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-59230 | Microsoft Windows Improper Access Control Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to ele… |
| CVE-2025-59228 | CVE-2025-59228 CVSS 8.8 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-59213 | CVE-2025-59213 CVSS 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elev… |
| CVE-2025-59158 | CVE-2025-59158 CVSS 8.0coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 a… |
| CVE-2025-59157 | CVE-2025-59157 CVSS 9.9coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field… |
| CVE-2025-59156 | CVE-2025-59156 CVSS 8.8coollabs | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution … |
| CVE-2025-59151 | CVE-2025-59151 CVSS 8.2pi-hole | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interfa… |
| CVE-2025-59146 | CVE-2025-59146 CVSS 8.5 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vu… |
| CVE-2025-59134 | CVE-2025-59134 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting immiex allows Privilege Escala… |
| CVE-2025-5912 | CVE-2025-5912 CVSS 8.8 | A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the function do_file of the component HTTP P… |
| CVE-2025-5911 | CVE-2025-5911 CVSS 8.8 | A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of … |