91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,751–4,800 of 8,161 in High · page 96 of 164

IDTitleSummary
CVE-2025-56127CVE-2025-56127
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the get_wanobj in…
CVE-2025-56123CVE-2025-56123
CVSS 8.8ruijie
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a craft…
CVE-2025-56122CVE-2025-56122
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST …
CVE-2025-56120CVE-2025-56120
CVSS 8.8
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST req…
CVE-2025-56118CVE-2025-56118
CVSS 8.8
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands via a crafted POST req…
CVE-2025-56117CVE-2025-56117
CVSS 8.8
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the mod…
CVE-2025-56114CVE-2025-56114
CVSS 8.8
OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to t…
CVE-2025-56113CVE-2025-56113
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to execute arbitrary commands via a crafted P…
CVE-2025-56111CVE-2025-56111
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the network_set_wa…
CVE-2025-56110CVE-2025-56110
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_deal_up…
CVE-2025-5611CVE-2025-5611
CVSS 8.8
A vulnerability, which was classified as critical, was found in CodeAstro Real Estate Management System 1.0. This affects an unknown part of the file /submitpr…
CVE-2025-56109CVE-2025-56109
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_wireles…
CVE-2025-56108CVE-2025-56108
CVSS 8.8
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwd…
CVE-2025-56107CVE-2025-56107
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi i…
CVE-2025-56106CVE-2025-56106
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request …
CVE-2025-56102CVE-2025-56102
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request …
CVE-2025-56101CVE-2025-56101
CVSS 8.8
OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to t…
CVE-2025-5610CVE-2025-5610
CVSS 8.8
A vulnerability, which was classified as critical, has been found in CodeAstro Real Estate Management System 1.0. Affected by this issue is some unknown functi…
CVE-2025-56099CVE-2025-56099
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-YST AP_3.0(1)B11P280YST250F allowing attackers to execute arbitrary commands via a crafted POST request to the …
CVE-2025-56098CVE-2025-56098
CVSS 8.8
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the mod…
CVE-2025-56097CVE-2025-56097
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST …
CVE-2025-56096CVE-2025-56096
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the restart_modul…
CVE-2025-56095CVE-2025-56095
CVSS 8.8ruijie
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a craft…
CVE-2025-56094CVE-2025-56094
CVSS 8.8
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the mod…
CVE-2025-56093CVE-2025-56093
CVSS 8.8
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the set…
CVE-2025-56092CVE-2025-56092
CVSS 8.8ruijie
OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the …
CVE-2025-56091CVE-2025-56091
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request …
CVE-2025-56090CVE-2025-56090
CVSS 8.8ruijie
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to execute arbitrary commands via a craft…
CVE-2025-5609CVE-2025-5609
CVSS 8.8
A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function fromadvsetlanip of the file /goform/…
CVE-2025-56089CVE-2025-56089
CVSS 8.8
OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary commands via a crafted POST request to t…
CVE-2025-56088CVE-2025-56088
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_service…
CVE-2025-56087CVE-2025-56087
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_tcpdump i…
CVE-2025-56086CVE-2025-56086
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a c…
CVE-2025-56085CVE-2025-56085
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3.0(1)B11P227_EW1200_11130208RG-EW1200 V1.00 allowing attackers to execute arbitrary commands via a c…
CVE-2025-56084CVE-2025-56084
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST …
CVE-2025-56083CVE-2025-56083
CVSS 8.8
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the mod…
CVE-2025-56082CVE-2025-56082
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the check_changes…
CVE-2025-5608CVE-2025-5608
CVSS 8.8
A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboottimer of the file /goform/SetSysAutoRebb…
CVE-2025-56079CVE-2025-56079
CVSS 8.8ruijie
OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1.00/V2.00/V4.00 allowing attackers to execute arbitrary commands via a crafted POST request t…
CVE-2025-56077CVE-2025-56077
CVSS 8.8
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_s…
CVE-2025-5607CVE-2025-5607
CVSS 8.8
A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPUserList of the file /goform/set…
CVE-2025-55998CVE-2025-55998
CVSS 8.1
A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in th…
CVE-2025-55976CVE-2025-55976
CVSS 8.4
Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly ob…
CVE-2025-55903CVE-2025-55903
CVSS 8.3
A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate mod…
CVE-2025-5590CVE-2025-5590
CVSS 8.8
The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.9 due…
CVE-2025-55849CVE-2025-55849
CVSS 8.4weiphp
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
CVE-2025-55848CVE-2025-55848
CVSS 8.8
An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parameter is not…
CVE-2025-55847CVE-2025-55847
CVSS 8.8
Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie paramet…
CVE-2025-55745CVE-2025-55745
CVSS 8.8
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, …
CVE-2025-55743CVE-2025-55743
CVSS 8.8
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation featur…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.