91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,651–4,700 of 8,161 in High · page 94 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-57771 | CVE-2025-57771 CVSS 8.1 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle process substitu… |
| CVE-2025-5777 | CVE-2025-5777 KEVCVSS 7.5citrix | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA … |
| CVE-2025-57765 | CVE-2025-57765 CVSS 8.2 | WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the pre_cadastro_ado… |
| CVE-2025-57764 | CVE-2025-57764 CVSS 8.2 | WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the cargos.php endpo… |
| CVE-2025-57761 | CVE-2025-57761 CVSS 8.8 | WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html/funcionario/dependente_remover.php end… |
| CVE-2025-57760 | CVE-2025-57760 CVSS 8.8 | Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an auth… |
| CVE-2025-57740 | CVE-2025-57740 CVSS 7.5fortinet | An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, … |
| CVE-2025-57709 | CVE-2025-57709 CVSS 8.1 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t… |
| CVE-2025-57707 | CVE-2025-57707 CVSS 8.8 | An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remo… |
| CVE-2025-57685 | CVE-2025-57685 CVSS 8.8 | The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.… |
| CVE-2025-5763 | CVE-2025-5763 CVSS 8.8 | A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the fil… |
| CVE-2025-57625 | CVE-2025-57625 CVSS 8.8 | CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to escalate privi… |
| CVE-2025-5761 | CVE-2025-5761 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing… |
| CVE-2025-57605 | CVE-2025-57605 CVSS 8.8 | Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assignin… |
| CVE-2025-57579 | CVE-2025-57579 CVSS 8.0 | An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password |
| CVE-2025-57578 | CVE-2025-57578 CVSS 8.0 | An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password |
| CVE-2025-57577 | CVE-2025-57577 CVSS 8.0 | An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "p… |
| CVE-2025-57564 | CVE-2025-57564 CVSS 8.2 | CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/insert/elasticsearch/_bu… |
| CVE-2025-57516 | CVE-2025-57516 CVSS 8.2 | OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted D… |
| CVE-2025-5750 | CVE-2025-5750 CVSS 8.8 | WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows netwo… |
| CVE-2025-5749 | CVE-2025-5749 CVSS 8.8 | WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers… |
| CVE-2025-57489 | CVE-2025-57489 CVSS 8.1shirt-pocket | Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of … |
| CVE-2025-57483 | CVE-2025-57483 CVSS 8.1 | A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's… |
| CVE-2025-5748 | CVE-2025-5748 CVSS 8.0 | WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execut… |
| CVE-2025-5747 | CVE-2025-5747 CVSS 8.0 | WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attac… |
| CVE-2025-57457 | CVE-2025-57457 CVSS 8.8 | An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr"… |
| CVE-2025-57439 | CVE-2025-57439 CVSS 8.8 | Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacker can inje… |
| CVE-2025-57434 | CVE-2025-57434 CVSS 8.8 | Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username… |
| CVE-2025-57431 | CVE-2025-57431 CVSS 8.8 | The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update… |
| CVE-2025-57393 | CVE-2025-57393 CVSS 8.8 | A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web… |
| CVE-2025-5739 | CVE-2025-5739 CVSS 8.8 | A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formSaveConfig of … |
| CVE-2025-5738 | CVE-2025-5738 CVSS 8.8 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file… |
| CVE-2025-5737 | CVE-2025-5737 CVSS 8.8 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of… |
| CVE-2025-5736 | CVE-2025-5736 CVSS 8.8 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formNtp… |
| CVE-2025-57350 | CVE-2025-57350 CVSS 8.6 | The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions … |
| CVE-2025-5735 | CVE-2025-5735 CVSS 8.8 | A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formS… |
| CVE-2025-5734 | CVE-2025-5734 CVSS 8.8 | A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affects unknown code of the file /boafrm/for… |
| CVE-2025-5732 | CVE-2025-5732 CVSS 8.8 | A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part. The manipu… |
| CVE-2025-57310 | CVE-2025-57310 CVSS 8.8 | A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admin.php?p=ads&c=1 allowing attackers to e… |
| CVE-2025-57295 | CVE-2025-57295 CVSS 8.0 | H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no passw… |
| CVE-2025-57293 | CVE-2025-57293 CVSS 8.8 | A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt.… |
| CVE-2025-57282 | CVE-2025-57282 CVSS 8.8 | ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection. |
| CVE-2025-5728 | CVE-2025-5728 CVSS 8.8 | A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code of the fil… |
| CVE-2025-57278 | CVE-2025-57278 CVSS 8.8 | The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user aut… |
| CVE-2025-57201 | CVE-2025-57201 CVSS 8.8avtech | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server fu… |
| CVE-2025-57199 | CVE-2025-57199 CVSS 8.8avtech | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetect… |
| CVE-2025-57198 | CVE-2025-57198 CVSS 8.8avtech | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi e… |
| CVE-2025-57151 | CVE-2025-57151 CVSS 8.8 | phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter. |
| CVE-2025-57146 | CVE-2025-57146 CVSS 8.1 | phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter. |
| CVE-2025-57130 | CVE-2025-57130 CVSS 8.3zwiicms | An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their … |