91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,801–4,850 of 8,161 in High · page 97 of 164

IDTitleSummary
CVE-2025-55741CVE-2025-55741
CVSS 8.1
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete pr…
CVE-2025-55731CVE-2025-55731
CVSS 8.8
Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injec…
CVE-2025-5571CVE-2025-5571
CVSS 8.8
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSystemAdmin of the file /setSystemAdmin. …
CVE-2025-55708CVE-2025-55708
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-ne…
CVE-2025-5569CVE-2025-5569
CVSS 8.8
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getL…
CVE-2025-5566CVE-2025-5566
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Notice Board System 1.0. This affects an unknown part of the file /search-notice.php. The m…
CVE-2025-5558CVE-2025-5558
CVSS 8.8
A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This issue affects some unknown processing…
CVE-2025-55573CVE-2025-55573
CVSS 8.8
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2025-5557CVE-2025-5557
CVSS 8.8
A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This vulnerability affects unknown co…
CVE-2025-5556CVE-2025-5556
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Teacher Subject Allocation Management System 1.0. This affects an unknown part of th…
CVE-2025-5554CVE-2025-5554
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Rail Pass Management System 1.0. Affected by this issue is some unknown functio…
CVE-2025-5552CVE-2025-5552
CVSS 8.8
A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknown code of the file /dev-api/groovy/exec…
CVE-2025-5546CVE-2025-5546
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /expense-r…
CVE-2025-55454CVE-2025-55454
CVSS 8.8
An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploadin…
CVE-2025-55422CVE-2025-55422
CVSS 8.8foxcms
In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.
CVE-2025-55420CVE-2025-55420
CVSS 8.8
A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected…
CVE-2025-55409CVE-2025-55409
CVSS 8.8foxcms
FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code.
CVE-2025-55383CVE-2025-55383
CVSS 8.6
Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any location on the…
CVE-2025-55370CVE-2025-55370
CVSS 8.8jishenghua
Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID d…
CVE-2025-55368CVE-2025-55368
CVSS 8.8jishenghua
Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier statu…
CVE-2025-55345CVE-2025-55345
CVSS 8.8
Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code ex…
CVE-2025-55298CVE-2025-55298
CVSS 8.8
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format st…
CVE-2025-55297CVE-2025-55297
CVSS 8.8
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: …
CVE-2025-55292CVE-2025-55292
CVSS 8.2
Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC add…
CVE-2025-55278CVE-2025-55278
CVSS 8.1
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their …
CVE-2025-55275CVE-2025-55275
CVSS 8.1
HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an …
CVE-2025-55271CVE-2025-55271
CVSS 8.8
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an attacker …
CVE-2025-5527CVE-2025-5527
CVSS 8.8
A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the fil…
CVE-2025-5525CVE-2025-5525
CVSS 8.1
A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/ut…
CVE-2025-55227CVE-2025-55227
CVSS 8.8
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a ne…
CVE-2025-55211CVE-2025-55211
CVSS 8.8
FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) c…
CVE-2025-5521CVE-2025-5521
CVSS 4.35kcrm
A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of…
CVE-2025-55165CVE-2025-55165
CVSS 8.2
Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.3, the deb…
CVE-2025-55162CVE-2025-55162
CVSS 8.8
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1…
CVE-2025-55158CVE-2025-55158
CVSS 8.8
Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operatio…
CVE-2025-55157CVE-2025-55157
CVSS 8.8
Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during eva…
CVE-2025-55147CVE-2025-55147
CVSS 8.8
CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Sec…
CVE-2025-55145CVE-2025-55145
CVSS 8.9
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivan…
CVE-2025-55142CVE-2025-55142
CVSS 8.8
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivant…
CVE-2025-55141CVE-2025-55141
CVSS 8.8
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivant…
CVE-2025-55118CVE-2025-55118
CVSS 8.9
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * …
CVE-2025-55116CVE-2025-55116
CVSS 8.8
A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerabil…
CVE-2025-55115CVE-2025-55115
CVSS 8.8
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerabilit…
CVE-2025-55069CVE-2025-55069
CVSS 8.3
A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies…
CVE-2025-55068CVE-2025-55068
CVSS 8.2
Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time t…
CVE-2025-55061CVE-2025-55061
CVSS 8.8
CWE-434 Unrestricted Upload of File with Dangerous Type
CVE-2025-55057CVE-2025-55057
CVSS 4.5maxum
Multiple CWE-352 Cross-Site Request Forgery (CSRF)
CVE-2025-55047CVE-2025-55047
CVSS 8.4
CWE-798 Use of Hard-coded Credentials
CVE-2025-55046CVE-2025-55046
CVSS 8.1
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a sim…
CVE-2025-55044CVE-2025-55044
CVSS 8.8
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CS…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.