91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,601–4,650 of 8,161 in High · page 93 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-5839 | CVE-2025-5839 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file … |
| CVE-2025-5838 | CVE-2025-5838 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionalit… |
| CVE-2025-58370 | CVE-2025-58370 CVSS 8.1 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic wher… |
| CVE-2025-5837 | CVE-2025-5837 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/a… |
| CVE-2025-58353 | CVE-2025-58353 CVSS 8.2 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio sanitize … |
| CVE-2025-5835 | CVE-2025-5835 CVSS 8.8 | The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis() functio… |
| CVE-2025-58334 | CVE-2025-58334 CVSS 8.1jetbrains | In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves |
| CVE-2025-5831 | CVE-2025-5831 CVSS 8.8 | The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function in all ve… |
| CVE-2025-5830 | CVE-2025-5830 CVSS 8.8 | Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adj… |
| CVE-2025-5827 | CVE-2025-5827 CVSS 8.8 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows networ… |
| CVE-2025-58250 | CVE-2025-58250 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo fingo allows Authentication Bypass.This issue affects Findgo: from n/a through <= 1.3.55. |
| CVE-2025-58244 | CVE-2025-58244 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This issue affects Constructo: from n/a through <= 4.3.9. |
| CVE-2025-58225 | CVE-2025-58225 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Paragon paragon allows PHP… |
| CVE-2025-5822 | CVE-2025-5822 CVSS 8.8 | Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers t… |
| CVE-2025-58215 | CVE-2025-58215 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston ziston allows PHP Local … |
| CVE-2025-58214 | CVE-2025-58214 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri indutri allows PHP Loca… |
| CVE-2025-58207 | CVE-2025-58207 CVSS 8.2 | Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Exploiting Incorrectly Configure… |
| CVE-2025-5820 | CVE-2025-5820 CVSS 8.8 | Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on af… |
| CVE-2025-58180 | CVE-2025-58180 CVSS 8.8 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows a… |
| CVE-2025-58176 | CVE-2025-58176 CVSS 8.8 | Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click … |
| CVE-2025-58173 | CVE-2025-58173 CVSS 8.8 | FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it… |
| CVE-2025-58163 | CVE-2025-58163 CVSS 8.8 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untrusted data vul… |
| CVE-2025-58159 | CVE-2025-58159 CVSS 8.8 | WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper validatio… |
| CVE-2025-58158 | CVE-2025-58158 CVSS 8.8 | Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact Registries… |
| CVE-2025-58150 | CVE-2025-58150 CVSS 8.8 | Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled d… |
| CVE-2025-58137 | CVE-2025-58137 CVSS 8.1apache | Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in v… |
| CVE-2025-58112 | CVE-2025-58112 CVSS 8.8 | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .r… |
| CVE-2025-58098 | CVE-2025-58098 CVSS 8.3apache | Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd… |
| CVE-2025-58077 | CVE-2025-58077 CVSS 8.0 | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault … |
| CVE-2025-58075 | CVE-2025-58075 CVSS 8.1 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original… |
| CVE-2025-58074 | CVE-2025-58074 CVSS 8.8 | A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during… |
| CVE-2025-58073 | CVE-2025-58073 CVSS 8.1 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original… |
| CVE-2025-58060 | CVE-2025-58060 CVSS 8.0 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set… |
| CVE-2025-5806 | CVE-2025-5806 CVSS 8.0 | Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641… |
| CVE-2025-58052 | CVE-2025-58052 CVSS 8.1 | Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group man… |
| CVE-2025-58034 | Fortinet FortiWeb OS Command Injection Vulnerability KEVCVSS 7.2Fortinet | Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system… |
| CVE-2025-58013 | CVE-2025-58013 CVSS 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects CouponXxL: from n/a through <= 4.5.… |
| CVE-2025-5799 | CVE-2025-5799 CVSS 8.8 | A vulnerability was found in Tenda AC8 16.03.34.09. It has been declared as critical. Affected by this vulnerability is the function fromSetWirelessRepeat of t… |
| CVE-2025-5798 | CVE-2025-5798 CVSS 8.8 | A vulnerability was found in Tenda AC8 16.03.34.09. It has been classified as critical. Affected is the function fromSetSysTime of the file /goform/SetSysTimeC… |
| CVE-2025-5795 | CVE-2025-5795 CVSS 8.8 | A vulnerability, which was classified as critical, was found in Tenda AC5 1.0/15.03.06.47. This affects the function fromadvsetlanip of the file /goform/AdvSet… |
| CVE-2025-5794 | CVE-2025-5794 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in Tenda AC5 15.03.06.47. Affected by this issue is the function formSetPPTPUserList of the f… |
| CVE-2025-5784 | CVE-2025-5784 CVSS 8.8 | A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the f… |
| CVE-2025-57833 | CVE-2025-57833 CVSS 8.1 | An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, u… |
| CVE-2025-57822 | CVE-2025-57822 CVSS 8.2 | Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing th… |
| CVE-2025-57808 | CVE-2025-57808 CVSS 8.1 | ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server aut… |
| CVE-2025-57803 | CVE-2025-57803 CVSS 8.8 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit… |
| CVE-2025-57800 | CVE-2025-57800 CVSS 8.8 | Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback U… |
| CVE-2025-57793 | CVE-2025-57793 CVSS 8.6 | Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application co… |
| CVE-2025-57790 | CVE-2025-57790 CVSS 8.8 | A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulner… |
| CVE-2025-57780 | CVE-2025-57780 CVSS 8.8 | A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges. A successful explo… |