91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,601–4,650 of 8,161 in High · page 93 of 164

IDTitleSummary
CVE-2025-5839CVE-2025-5839
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file …
CVE-2025-5838CVE-2025-5838
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionalit…
CVE-2025-58370CVE-2025-58370
CVSS 8.1
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic wher…
CVE-2025-5837CVE-2025-5837
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/a…
CVE-2025-58353CVE-2025-58353
CVSS 8.2
Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio sanitize …
CVE-2025-5835CVE-2025-5835
CVSS 8.8
The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_apis() functio…
CVE-2025-58334CVE-2025-58334
CVSS 8.1jetbrains
In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves
CVE-2025-5831CVE-2025-5831
CVSS 8.8
The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function in all ve…
CVE-2025-5830CVE-2025-5830
CVSS 8.8
Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adj…
CVE-2025-5827CVE-2025-5827
CVSS 8.8
Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows networ…
CVE-2025-58250CVE-2025-58250
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo fingo allows Authentication Bypass.This issue affects Findgo: from n/a through <= 1.3.55.
CVE-2025-58244CVE-2025-58244
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This issue affects Constructo: from n/a through <= 4.3.9.
CVE-2025-58225CVE-2025-58225
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Paragon paragon allows PHP…
CVE-2025-5822CVE-2025-5822
CVSS 8.8
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers t…
CVE-2025-58215CVE-2025-58215
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston ziston allows PHP Local …
CVE-2025-58214CVE-2025-58214
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Indutri indutri allows PHP Loca…
CVE-2025-58207CVE-2025-58207
CVSS 8.2
Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp allows Exploiting Incorrectly Configure…
CVE-2025-5820CVE-2025-5820
CVSS 8.8
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on af…
CVE-2025-58180CVE-2025-58180
CVSS 8.8
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows a…
CVE-2025-58176CVE-2025-58176
CVSS 8.8
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click …
CVE-2025-58173CVE-2025-58173
CVSS 8.8
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it…
CVE-2025-58163CVE-2025-58163
CVSS 8.8
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untrusted data vul…
CVE-2025-58159CVE-2025-58159
CVSS 8.8
WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper validatio…
CVE-2025-58158CVE-2025-58158
CVSS 8.8
Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact Registries…
CVE-2025-58150CVE-2025-58150
CVSS 8.8
Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled d…
CVE-2025-58137CVE-2025-58137
CVSS 8.1apache
Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in v…
CVE-2025-58112CVE-2025-58112
CVSS 8.8
Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .r…
CVE-2025-58098CVE-2025-58098
CVSS 8.3apache
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd…
CVE-2025-58077CVE-2025-58077
CVSS 8.0
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault …
CVE-2025-58075CVE-2025-58075
CVSS 8.1
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original…
CVE-2025-58074CVE-2025-58074
CVSS 8.8
A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during…
CVE-2025-58073CVE-2025-58073
CVSS 8.1
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original…
CVE-2025-58060CVE-2025-58060
CVSS 8.0
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set…
CVE-2025-5806CVE-2025-5806
CVSS 8.0
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641…
CVE-2025-58052CVE-2025-58052
CVSS 8.1
Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group man…
CVE-2025-58034Fortinet FortiWeb OS Command Injection Vulnerability
KEVCVSS 7.2Fortinet
Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system…
CVE-2025-58013CVE-2025-58013
CVSS 8.8
Cross-Site Request Forgery (CSRF) vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects CouponXxL: from n/a through <= 4.5.…
CVE-2025-5799CVE-2025-5799
CVSS 8.8
A vulnerability was found in Tenda AC8 16.03.34.09. It has been declared as critical. Affected by this vulnerability is the function fromSetWirelessRepeat of t…
CVE-2025-5798CVE-2025-5798
CVSS 8.8
A vulnerability was found in Tenda AC8 16.03.34.09. It has been classified as critical. Affected is the function fromSetSysTime of the file /goform/SetSysTimeC…
CVE-2025-5795CVE-2025-5795
CVSS 8.8
A vulnerability, which was classified as critical, was found in Tenda AC5 1.0/15.03.06.47. This affects the function fromadvsetlanip of the file /goform/AdvSet…
CVE-2025-5794CVE-2025-5794
CVSS 8.8
A vulnerability, which was classified as critical, has been found in Tenda AC5 15.03.06.47. Affected by this issue is the function formSetPPTPUserList of the f…
CVE-2025-5784CVE-2025-5784
CVSS 8.8
A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the f…
CVE-2025-57833CVE-2025-57833
CVSS 8.1
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, u…
CVE-2025-57822CVE-2025-57822
CVSS 8.2
Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing th…
CVE-2025-57808CVE-2025-57808
CVSS 8.1
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server aut…
CVE-2025-57803CVE-2025-57803
CVSS 8.8
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit…
CVE-2025-57800CVE-2025-57800
CVSS 8.8
Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback U…
CVE-2025-57793CVE-2025-57793
CVSS 8.6
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application co…
CVE-2025-57790CVE-2025-57790
CVSS 8.8
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulner…
CVE-2025-57780CVE-2025-57780
CVSS 8.8
A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges.  A successful explo…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.