91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,501–4,550 of 8,161 in High · page 91 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-59106 | CVE-2025-59106 CVSS 8.8 | The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privi… |
| CVE-2025-5910 | CVE-2025-5910 CVSS 8.8 | A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functi… |
| CVE-2025-5909 | CVE-2025-5909 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boa… |
| CVE-2025-59088 | CVE-2025-59088 CVSS 8.6 | If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS … |
| CVE-2025-5908 | CVE-2025-5908 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This issue affects some unknown processing … |
| CVE-2025-5907 | CVE-2025-5907 CVSS 8.8 | A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/… |
| CVE-2025-5905 | CVE-2025-5905 CVSS 8.8 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file /c… |
| CVE-2025-59048 | CVE-2025-59048 CVSS 8.1openbao | OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Imp… |
| CVE-2025-5904 | CVE-2025-5904 CVSS 8.8 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the… |
| CVE-2025-5903 | CVE-2025-5903 CVSS 8.8 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstec… |
| CVE-2025-59023 | CVE-2025-59023 CVSS 8.2 | Crafted delegations or IP fragments can poison cached delegations in Recursor. |
| CVE-2025-59022 | CVE-2025-59022 CVSS 8.1 | Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had per… |
| CVE-2025-5902 | CVE-2025-5902 CVSS 8.8 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cg… |
| CVE-2025-59017 | CVE-2025-59017 CVSS 8.8 | Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allo… |
| CVE-2025-5901 | CVE-2025-5901 CVSS 8.8 | A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file … |
| CVE-2025-58995 | CVE-2025-58995 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Leblix leblix allows … |
| CVE-2025-58994 | CVE-2025-58994 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Greenify greenify allows … |
| CVE-2025-58967 | CVE-2025-58967 CVSS 8.1thememove | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Businext businext allows PHP… |
| CVE-2025-58958 | CVE-2025-58958 CVSS 8.1thememove | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepure allows P… |
| CVE-2025-58955 | CVE-2025-58955 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Karzo karzo allows PHP Lo… |
| CVE-2025-58950 | CVE-2025-58950 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Lione lione allows PHP Loc… |
| CVE-2025-58949 | CVE-2025-58949 CVSS 8.1axiomthemes | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Spock spock allows PHP Loc… |
| CVE-2025-58948 | CVE-2025-58948 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Aromatica aromatica allows… |
| CVE-2025-58947 | CVE-2025-58947 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Athos athos allows PHP Loc… |
| CVE-2025-58946 | CVE-2025-58946 CVSS 8.1axiomthemes | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Vocal vocal allows PHP Loc… |
| CVE-2025-58945 | CVE-2025-58945 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes EcoGrow ecogrow allows PHP… |
| CVE-2025-58944 | CVE-2025-58944 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Manufactory manufactory al… |
| CVE-2025-58943 | CVE-2025-58943 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Agricola agricola allows P… |
| CVE-2025-58942 | CVE-2025-58942 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Dwell dwell allows PHP Loc… |
| CVE-2025-58941 | CVE-2025-58941 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Fabric fabric allows PHP L… |
| CVE-2025-58940 | CVE-2025-58940 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Basil basil allows PHP Loc… |
| CVE-2025-5894 | CVE-2025-5894 CVSS 8.8 | Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges to access … |
| CVE-2025-58937 | CVE-2025-58937 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Tacticool tacticool allows… |
| CVE-2025-58936 | CVE-2025-58936 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Catamaran catamaran allows… |
| CVE-2025-58934 | CVE-2025-58934 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes The Gig thegig allows PHP … |
| CVE-2025-58933 | CVE-2025-58933 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Anubis anubis allows PHP L… |
| CVE-2025-58932 | CVE-2025-58932 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Prisma prisma allows PHP L… |
| CVE-2025-58931 | CVE-2025-58931 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Palatio palatio allows PHP… |
| CVE-2025-58930 | CVE-2025-58930 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes FitFlex fitflex allows PHP… |
| CVE-2025-58929 | CVE-2025-58929 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Pantry pantry allows PHP L… |
| CVE-2025-58928 | CVE-2025-58928 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Heart heart allows PHP Loc… |
| CVE-2025-58927 | CVE-2025-58927 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Stallion stallion allows P… |
| CVE-2025-58926 | CVE-2025-58926 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Cerebrum cerebrum allows P… |
| CVE-2025-58925 | CVE-2025-58925 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Neptunus neptunus allows P… |
| CVE-2025-58923 | CVE-2025-58923 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Critique critique allows P… |
| CVE-2025-58913 | CVE-2025-58913 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro videopro allows … |
| CVE-2025-58901 | CVE-2025-58901 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Takeout takeout allows PH… |
| CVE-2025-58900 | CVE-2025-58900 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes UniTravel unitravel allow… |
| CVE-2025-58899 | CVE-2025-58899 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Frame frame allows PHP Lo… |
| CVE-2025-58898 | CVE-2025-58898 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes HealthHub healthhub allow… |