91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,451–4,500 of 8,161 in High · page 90 of 164

IDTitleSummary
CVE-2025-5971CVE-2025-5971
CVSS 8.8
A vulnerability was found in code-projects School Fees Payment System 1.0. It has been classified as critical. This affects an unknown part of the file /ajx.ph…
CVE-2025-5969CVE-2025-5969
CVSS 8.8
A vulnerability has been found in D-Link DIR-632 FW103B08 and classified as critical. Affected by this vulnerability is the function FUN_00425fd8 of the file /…
CVE-2025-59684CVE-2025-59684
CVSS 8.8
DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.
CVE-2025-5966CVE-2025-5966
CVSS 8.1
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
CVE-2025-5959CVE-2025-5959
CVSS 8.8
Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…
CVE-2025-59580CVE-2025-59580
CVSS 8.8
Incorrect Privilege Assignment vulnerability in GoodLayers Goodlayers Core goodlayers-core allows Privilege Escalation.This issue affects Goodlayers Core: from…
CVE-2025-5958CVE-2025-5958
CVSS 8.8
Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…
CVE-2025-59572CVE-2025-59572
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Forgery.This issue affects WorkScout-Core…
CVE-2025-59564CVE-2025-59564
CVSS 8.1thememove
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall allows PHP L…
CVE-2025-5956CVE-2025-5956
CVSS 8.1
The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authorization within the ajax_delete_employee()…
CVE-2025-59558CVE-2025-59558
CVSS 8.1thememove
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Loc…
CVE-2025-59555CVE-2025-59555
CVSS 8.1thememove
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Medizin medizin allows PHP L…
CVE-2025-59550CVE-2025-59550
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allows PHP Lo…
CVE-2025-5955CVE-2025-5955
CVSS 8.1
The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugi…
CVE-2025-59541CVE-2025-59541
CVSS 8.1
Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects insi…
CVE-2025-59536CVE-2025-59536
CVSS 8.8anthropic
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claud…
CVE-2025-5953CVE-2025-5953
CVSS 8.8
The WP Human Resource Management plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the ajax_insert_employee() and upda…
CVE-2025-59518CVE-2025-59518
CVSS 8.0
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluat…
CVE-2025-59500CVE-2025-59500
CVSS 7.7microsoft
Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
CVE-2025-59499CVE-2025-59499
CVSS 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a n…
CVE-2025-5949CVE-2025-5949
CVSS 8.8
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is …
CVE-2025-59487CVE-2025-59487
CVSS 8.0
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault …
CVE-2025-59484CVE-2025-59484
CVSS 8.3
The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that t…
CVE-2025-59482CVE-2025-59482
CVSS 8.0
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault …
CVE-2025-59481CVE-2025-59481
CVSS 8.7f5
A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource adm…
CVE-2025-59430CVE-2025-59430
CVSS 8.2
Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitization of URLs protocols in the createLi…
CVE-2025-5943CVE-2025-5943
CVSS 8.8
MicroDicom DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary c…
CVE-2025-5934CVE-2025-5934
CVSS 8.8
A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function sub_41619C of the file /mtd. The manip…
CVE-2025-59334CVE-2025-59334
CVSS 8.8
Linkr is a lightweight file delivery system that downloads files from a webserver. Linkr versions through 2.0.0 do not verify the integrity or authenticity of …
CVE-2025-59333CVE-2025-59333
CVSS 8.1
The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate secu…
CVE-2025-59332CVE-2025-59332
CVSS 8.6
3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser function allow users to provide custom attri…
CVE-2025-5931CVE-2025-5931
CVSS 8.8
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due to the p…
CVE-2025-59295CVE-2025-59295
CVSS 8.8
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
CVE-2025-59292CVE-2025-59292
CVSS 8.2microsoft
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
CVE-2025-59291CVE-2025-59291
CVSS 8.2microsoft
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
CVE-2025-59271CVE-2025-59271
CVSS 8.7
Redis Enterprise Elevation of Privilege Vulnerability
CVE-2025-59250CVE-2025-59250
CVSS 8.1
Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-59249CVE-2025-59249
CVSS 8.8microsoft
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-59237CVE-2025-59237
CVSS 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-59230Microsoft Windows Improper Access Control Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to ele…
CVE-2025-59228CVE-2025-59228
CVSS 8.8
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-59213CVE-2025-59213
CVSS 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elev…
CVE-2025-59158CVE-2025-59158
CVSS 8.0coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 a…
CVE-2025-59157CVE-2025-59157
CVSS 9.9coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field…
CVE-2025-59156CVE-2025-59156
CVSS 8.8coollabs
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution …
CVE-2025-59151CVE-2025-59151
CVSS 8.2pi-hole
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interfa…
CVE-2025-59146CVE-2025-59146
CVSS 8.5
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vu…
CVE-2025-59134CVE-2025-59134
CVSS 8.8
Incorrect Privilege Assignment vulnerability in Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting immiex allows Privilege Escala…
CVE-2025-5912CVE-2025-5912
CVSS 8.8
A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the function do_file of the component HTTP P…
CVE-2025-5911CVE-2025-5911
CVSS 8.8
A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.