91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,701–4,750 of 8,161 in High · page 95 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-5701 | CVE-2025-5701 CVSS 8.8 | The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability che… |
| CVE-2025-5694 | CVE-2025-5694 CVSS 8.8 | A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as critical. Affected by this issue is some unkn… |
| CVE-2025-5693 | CVE-2025-5693 CVSS 8.8 | A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability i… |
| CVE-2025-5689 | CVE-2025-5689 CVSS 8.5 | A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part o… |
| CVE-2025-56816 | CVE-2025-56816 CVSS 8.8 | Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to t… |
| CVE-2025-56803 | CVE-2025-56803 CVSS 8.4 | Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands … |
| CVE-2025-5680 | CVE-2025-5680 CVSS 8.8 | A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerability is the … |
| CVE-2025-5679 | CVE-2025-5679 CVSS 8.8 | A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the function parseStr… |
| CVE-2025-5674 | CVE-2025-5674 CVSS 8.8 | A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionalit… |
| CVE-2025-5672 | CVE-2025-5672 CVSS 8.8 | A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functional… |
| CVE-2025-5671 | CVE-2025-5671 CVSS 8.8 | A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/… |
| CVE-2025-56706 | CVE-2025-56706 CVSS 8.0 | Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function. |
| CVE-2025-56704 | CVE-2025-56704 CVSS 8.8lepton-cms | LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated … |
| CVE-2025-5670 | CVE-2025-5670 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing … |
| CVE-2025-5669 | CVE-2025-5669 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/u… |
| CVE-2025-5668 | CVE-2025-5668 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/readenq… |
| CVE-2025-5660 | CVE-2025-5660 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affected by this issue is some unknown functio… |
| CVE-2025-5659 | CVE-2025-5659 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown functionality of t… |
| CVE-2025-56588 | CVE-2025-56588 CVSS 8.8dolibarr | Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field param… |
| CVE-2025-5658 | CVE-2025-5658 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/updatec… |
| CVE-2025-56577 | CVE-2025-56577 CVSS 8.4 | An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryptographic keys. |
| CVE-2025-5657 | CVE-2025-5657 CVSS 8.8 | A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file … |
| CVE-2025-5656 | CVE-2025-5656 CVSS 8.8 | A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file … |
| CVE-2025-56551 | CVE-2025-56551 CVSS 8.2 | An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-c… |
| CVE-2025-5655 | CVE-2025-5655 CVSS 8.8 | A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been classified as critical. This affects an unknown part of the file /admin/ed… |
| CVE-2025-5654 | CVE-2025-5654 CVSS 8.8 | A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the… |
| CVE-2025-5653 | CVE-2025-5653 CVSS 8.8 | A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functiona… |
| CVE-2025-5652 | CVE-2025-5652 CVSS 8.8 | A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/… |
| CVE-2025-56515 | CVE-2025-56515 CVSS 8.8 | File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowin… |
| CVE-2025-56449 | CVE-2025-56449 CVSS 8.2 | A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after … |
| CVE-2025-56413 | CVE-2025-56413 CVSS 8.8 | OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /… |
| CVE-2025-56407 | CVE-2025-56407 CVSS 8.8 | A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/… |
| CVE-2025-56400 | CVE-2025-56400 CVSS 8.8tuya | Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mob… |
| CVE-2025-56399 | CVE-2025-56399 CVSS 8.8 | alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file w… |
| CVE-2025-56396 | CVE-2025-56396 CVSS 8.8 | An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user. |
| CVE-2025-56392 | CVE-2025-56392 CVSS 8.1 | An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perf… |
| CVE-2025-56383 | CVE-2025-56383 CVSS 8.4 | Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parti… |
| CVE-2025-5638 | CVE-2025-5638 CVSS 8.8 | A vulnerability has been found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of … |
| CVE-2025-5633 | CVE-2025-5633 CVSS 8.8 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is … |
| CVE-2025-5632 | CVE-2025-5632 CVSS 8.8 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulner… |
| CVE-2025-56274 | CVE-2025-56274 CVSS 8.1senior-walter | SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high priv… |
| CVE-2025-56265 | CVE-2025-56265 CVSS 8.8 | An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uplo… |
| CVE-2025-56263 | CVE-2025-56263 CVSS 8.8 | by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbitrary files. Users can upload files of … |
| CVE-2025-56224 | CVE-2025-56224 CVSS 8.1ascertia | A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce atta… |
| CVE-2025-56216 | CVE-2025-56216 CVSS 8.5 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter. |
| CVE-2025-5616 | CVE-2025-5616 CVSS 8.8 | A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been rated as critical. Affected by this issue is some unknown functionality o… |
| CVE-2025-5615 | CVE-2025-5615 CVSS 8.8 | A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as critical. Affected by this vulnerability is an unknown functi… |
| CVE-2025-5614 | CVE-2025-5614 CVSS 8.8 | A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. Affected is an unknown function of the file /sear… |
| CVE-2025-56130 | CVE-2025-56130 CVSS 8.8 | OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary commands via a crafted POST request to … |
| CVE-2025-56129 | CVE-2025-56129 CVSS 8.8 | OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnos… |