91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,651–4,700 of 8,161 in High · page 94 of 164

IDTitleSummary
CVE-2025-57771CVE-2025-57771
CVSS 8.1
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fails to properly handle process substitu…
CVE-2025-5777CVE-2025-5777
KEVCVSS 7.5citrix
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA …
CVE-2025-57765CVE-2025-57765
CVSS 8.2
WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the pre_cadastro_ado…
CVE-2025-57764CVE-2025-57764
CVSS 8.2
WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the cargos.php endpo…
CVE-2025-57761CVE-2025-57761
CVSS 8.8
WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html/funcionario/dependente_remover.php end…
CVE-2025-57760CVE-2025-57760
CVSS 8.8
Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an auth…
CVE-2025-57740CVE-2025-57740
CVSS 7.5fortinet
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, …
CVE-2025-57709CVE-2025-57709
CVSS 8.1
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability t…
CVE-2025-57707CVE-2025-57707
CVSS 8.8
An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remo…
CVE-2025-57685CVE-2025-57685
CVSS 8.8
The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, BL-X26_AC8 v1.2.8, and BL-LTE300_DA4 V1.…
CVE-2025-5763CVE-2025-5763
CVSS 8.8
A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the fil…
CVE-2025-57625CVE-2025-57625
CVSS 8.8
CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to escalate privi…
CVE-2025-5761CVE-2025-5761
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing…
CVE-2025-57605CVE-2025-57605
CVSS 8.8
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assignin…
CVE-2025-57579CVE-2025-57579
CVSS 8.0
An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password
CVE-2025-57578CVE-2025-57578
CVSS 8.0
An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password
CVE-2025-57577CVE-2025-57577
CVSS 8.0
An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "p…
CVE-2025-57564CVE-2025-57564
CVSS 8.2
CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/insert/elasticsearch/_bu…
CVE-2025-57516CVE-2025-57516
CVSS 8.2
OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted D…
CVE-2025-5750CVE-2025-5750
CVSS 8.8
WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows netwo…
CVE-2025-5749CVE-2025-5749
CVSS 8.8
WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers…
CVE-2025-57489CVE-2025-57489
CVSS 8.1shirt-pocket
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of …
CVE-2025-57483CVE-2025-57483
CVSS 8.1
A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's…
CVE-2025-5748CVE-2025-5748
CVSS 8.0
WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execut…
CVE-2025-5747CVE-2025-5747
CVSS 8.0
WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attac…
CVE-2025-57457CVE-2025-57457
CVSS 8.8
An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr"…
CVE-2025-57439CVE-2025-57439
CVSS 8.8
Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacker can inje…
CVE-2025-57434CVE-2025-57434
CVSS 8.8
Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username…
CVE-2025-57431CVE-2025-57431
CVSS 8.8
The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update…
CVE-2025-57393CVE-2025-57393
CVSS 8.8
A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web…
CVE-2025-5739CVE-2025-5739
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formSaveConfig of …
CVE-2025-5738CVE-2025-5738
CVSS 8.8
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file…
CVE-2025-5737CVE-2025-5737
CVSS 8.8
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of…
CVE-2025-5736CVE-2025-5736
CVSS 8.8
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formNtp…
CVE-2025-57350CVE-2025-57350
CVSS 8.6
The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions …
CVE-2025-5735CVE-2025-5735
CVSS 8.8
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formS…
CVE-2025-5734CVE-2025-5734
CVSS 8.8
A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affects unknown code of the file /boafrm/for…
CVE-2025-5732CVE-2025-5732
CVSS 8.8
A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part. The manipu…
CVE-2025-57310CVE-2025-57310
CVSS 8.8
A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admin.php?p=ads&c=1 allowing attackers to e…
CVE-2025-57295CVE-2025-57295
CVSS 8.0
H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no passw…
CVE-2025-57293CVE-2025-57293
CVSS 8.8
A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt.…
CVE-2025-57282CVE-2025-57282
CVSS 8.8
ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
CVE-2025-5728CVE-2025-5728
CVSS 8.8
A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code of the fil…
CVE-2025-57278CVE-2025-57278
CVSS 8.8
The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user aut…
CVE-2025-57201CVE-2025-57201
CVSS 8.8avtech
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server fu…
CVE-2025-57199CVE-2025-57199
CVSS 8.8avtech
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetect…
CVE-2025-57198CVE-2025-57198
CVSS 8.8avtech
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi e…
CVE-2025-57151CVE-2025-57151
CVSS 8.8
phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.
CVE-2025-57146CVE-2025-57146
CVSS 8.1
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.
CVE-2025-57130CVE-2025-57130
CVSS 8.3zwiicms
An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their …
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.