91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,551–4,600 of 8,161 in High · page 92 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-58896 | CVE-2025-58896 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Otaku otaku allows PHP Lo… |
| CVE-2025-58895 | CVE-2025-58895 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Integro integro allows PH… |
| CVE-2025-58894 | CVE-2025-58894 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Good Mood good-mood allows… |
| CVE-2025-58893 | CVE-2025-58893 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Alright alright allows PHP… |
| CVE-2025-58892 | CVE-2025-58892 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Tourimo tourimo allows PH… |
| CVE-2025-58891 | CVE-2025-58891 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Sanger sanger allows PHP … |
| CVE-2025-58890 | CVE-2025-58890 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Playful playful allows PH… |
| CVE-2025-58889 | CVE-2025-58889 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Towny towny allows PHP Loc… |
| CVE-2025-58888 | CVE-2025-58888 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes The Flash theflash allows… |
| CVE-2025-58885 | CVE-2025-58885 CVSS 8.1ancorathemes | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pathfinder pathfinder all… |
| CVE-2025-58881 | CVE-2025-58881 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus New Simple Gallery new-simple-gallery allows Bli… |
| CVE-2025-58879 | CVE-2025-58879 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Festy festy allows PHP Lo… |
| CVE-2025-58833 | CVE-2025-58833 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in INVELITY Invelity MyGLS connect invelity-mygls-connect allows Object Injection.This issue affects Invelity M… |
| CVE-2025-58803 | CVE-2025-58803 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Algenix algenix allows PHP… |
| CVE-2025-58770 | CVE-2025-58770 CVSS 8.8ami | APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploi… |
| CVE-2025-5877 | CVE-2025-5877 CVSS 8.1 | A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of… |
| CVE-2025-58757 | CVE-2025-58757 CVSS 8.8 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in `monai… |
| CVE-2025-58756 | CVE-2025-58756 CVSS 8.8 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map… |
| CVE-2025-58755 | CVE-2025-58755 CVSS 8.8 | MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to pro… |
| CVE-2025-5875 | CVE-2025-5875 CVSS 8.8 | A vulnerability classified as critical has been found in TP-LINK Technologies TL-IPC544EP-W4 1.0.9 Build 240428 Rel 69493n. Affected is the function sub_69064 … |
| CVE-2025-58745 | CVE-2025-58745 CVSS 8.8 | WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA o… |
| CVE-2025-58718 | CVE-2025-58718 CVSS 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2025-58716 | CVE-2025-58716 CVSS 8.8 | Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
| CVE-2025-58715 | CVE-2025-58715 CVSS 8.8 | Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
| CVE-2025-58710 | CVE-2025-58710 CVSS 8.8 | Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: from n/a th… |
| CVE-2025-58709 | CVE-2025-58709 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Legacy legacy allows PHP L… |
| CVE-2025-58708 | CVE-2025-58708 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes 777 triple-seven allows PH… |
| CVE-2025-58706 | CVE-2025-58706 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Woo Hoo woohoo allows PHP … |
| CVE-2025-58692 | CVE-2025-58692 CVSS 8.8 | An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 throu… |
| CVE-2025-58686 | CVE-2025-58686 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce perfect-woocomm… |
| CVE-2025-58619 | CVE-2025-58619 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in sbouey Falang multilanguage falang allows Object Injection.This issue affects Falang multilanguage: from n/a… |
| CVE-2025-58592 | CVE-2025-58592 CVSS 8.1 | Deserialization of Untrusted Data vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Object Injection.This issue affects TranslatePr… |
| CVE-2025-5859 | CVE-2025-5859 CVSS 8.8 | A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unkno… |
| CVE-2025-5858 | CVE-2025-5858 CVSS 8.8 | A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the f… |
| CVE-2025-5857 | CVE-2025-5857 CVSS 8.8 | A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the f… |
| CVE-2025-5854 | CVE-2025-5854 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16. Affected by this issue is the function fromadvsetlanip of the file … |
| CVE-2025-5853 | CVE-2025-5853 CVSS 8.8 | A vulnerability classified as critical was found in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /gof… |
| CVE-2025-5852 | CVE-2025-5852 CVSS 8.8 | A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function formSetPPTPUserList of the file /goform/setPptpUserLis… |
| CVE-2025-5851 | CVE-2025-5851 CVSS 8.8 | A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been rated as critical. This issue affects the function fromadvsetlanip of the file /goform/A… |
| CVE-2025-5850 | CVE-2025-5850 CVSS 8.8 | A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been declared as critical. This vulnerability affects the function formsetschedled of the fil… |
| CVE-2025-5849 | CVE-2025-5849 CVSS 8.8 | A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been classified as critical. This affects the function formSetSafeWanWebMan of the file /gofo… |
| CVE-2025-5848 | CVE-2025-5848 CVSS 8.8 | A vulnerability was found in Tenda AC15 15.03.05.19_multi and classified as critical. Affected by this issue is the function formSetPPTPUserList of the file /g… |
| CVE-2025-5847 | CVE-2025-5847 CVSS 8.8 | A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the … |
| CVE-2025-58469 | CVE-2025-58469 CVSS 8.8 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain pri… |
| CVE-2025-58455 | CVE-2025-58455 CVSS 8.0 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault … |
| CVE-2025-58454 | CVE-2025-58454 CVSS 8.2 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior inthe endpoint /WeGIA/html/… |
| CVE-2025-58453 | CVE-2025-58453 CVSS 8.2 | WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior in the endpoint /WeGIA/html… |
| CVE-2025-58437 | CVE-2025-58437 CVSS 8.1 | Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3, 2.25.0 and 2.25.1, Coder can be comp… |
| CVE-2025-58423 | CVE-2025-58423 CVSS 8.8advantech | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories,… |
| CVE-2025-58411 | CVE-2025-58411 CVSS 8.8 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a pot… |