91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,701–4,750 of 8,161 in High · page 95 of 164

IDTitleSummary
CVE-2025-5701CVE-2025-5701
CVSS 8.8
The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability che…
CVE-2025-5694CVE-2025-5694
CVSS 8.8
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as critical. Affected by this issue is some unkn…
CVE-2025-5693CVE-2025-5693
CVSS 8.8
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability i…
CVE-2025-5689CVE-2025-5689
CVSS 8.5
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part o…
CVE-2025-56816CVE-2025-56816
CVSS 8.8
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to t…
CVE-2025-56803CVE-2025-56803
CVSS 8.4
Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands …
CVE-2025-5680CVE-2025-5680
CVSS 8.8
A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerability is the …
CVE-2025-5679CVE-2025-5679
CVSS 8.8
A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the function parseStr…
CVE-2025-5674CVE-2025-5674
CVSS 8.8
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionalit…
CVE-2025-5672CVE-2025-5672
CVSS 8.8
A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functional…
CVE-2025-5671CVE-2025-5671
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/…
CVE-2025-56706CVE-2025-56706
CVSS 8.0
Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.
CVE-2025-56704CVE-2025-56704
CVSS 8.8lepton-cms
LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated …
CVE-2025-5670CVE-2025-5670
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing …
CVE-2025-5669CVE-2025-5669
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/u…
CVE-2025-5668CVE-2025-5668
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/readenq…
CVE-2025-5660CVE-2025-5660
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affected by this issue is some unknown functio…
CVE-2025-5659CVE-2025-5659
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown functionality of t…
CVE-2025-56588CVE-2025-56588
CVSS 8.8dolibarr
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field param…
CVE-2025-5658CVE-2025-5658
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/updatec…
CVE-2025-56577CVE-2025-56577
CVSS 8.4
An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryptographic keys.
CVE-2025-5657CVE-2025-5657
CVSS 8.8
A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file …
CVE-2025-5656CVE-2025-5656
CVSS 8.8
A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file …
CVE-2025-56551CVE-2025-56551
CVSS 8.2
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-c…
CVE-2025-5655CVE-2025-5655
CVSS 8.8
A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been classified as critical. This affects an unknown part of the file /admin/ed…
CVE-2025-5654CVE-2025-5654
CVSS 8.8
A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the…
CVE-2025-5653CVE-2025-5653
CVSS 8.8
A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functiona…
CVE-2025-5652CVE-2025-5652
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/…
CVE-2025-56515CVE-2025-56515
CVSS 8.8
File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowin…
CVE-2025-56449CVE-2025-56449
CVSS 8.2
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after …
CVE-2025-56413CVE-2025-56413
CVSS 8.8
OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /…
CVE-2025-56407CVE-2025-56407
CVSS 8.8
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/…
CVE-2025-56400CVE-2025-56400
CVSS 8.8tuya
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mob…
CVE-2025-56399CVE-2025-56399
CVSS 8.8
alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file w…
CVE-2025-56396CVE-2025-56396
CVSS 8.8
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.
CVE-2025-56392CVE-2025-56392
CVSS 8.1
An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perf…
CVE-2025-56383CVE-2025-56383
CVSS 8.4
Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parti…
CVE-2025-5638CVE-2025-5638
CVSS 8.8
A vulnerability has been found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …
CVE-2025-5633CVE-2025-5633
CVSS 8.8
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is …
CVE-2025-5632CVE-2025-5632
CVSS 8.8
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulner…
CVE-2025-56274CVE-2025-56274
CVSS 8.1senior-walter
SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high priv…
CVE-2025-56265CVE-2025-56265
CVSS 8.8
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uplo…
CVE-2025-56263CVE-2025-56263
CVSS 8.8
by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbitrary files. Users can upload files of …
CVE-2025-56224CVE-2025-56224
CVSS 8.1ascertia
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce atta…
CVE-2025-56216CVE-2025-56216
CVSS 8.5
phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.
CVE-2025-5616CVE-2025-5616
CVSS 8.8
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been rated as critical. Affected by this issue is some unknown functionality o…
CVE-2025-5615CVE-2025-5615
CVSS 8.8
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as critical. Affected by this vulnerability is an unknown functi…
CVE-2025-5614CVE-2025-5614
CVSS 8.8
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. Affected is an unknown function of the file /sear…
CVE-2025-56130CVE-2025-56130
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary commands via a crafted POST request to …
CVE-2025-56129CVE-2025-56129
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnos…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.