91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,801–4,850 of 8,161 in High · page 97 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-55741 | CVE-2025-55741 CVSS 8.1 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete pr… |
| CVE-2025-55731 | CVE-2025-55731 CVSS 8.8 | Frappe is a full-stack web application framework. A carefully crafted request could extract data that the user would normally not have access to, via SQL injec… |
| CVE-2025-5571 | CVE-2025-5571 CVSS 8.8 | A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSystemAdmin of the file /setSystemAdmin. … |
| CVE-2025-55708 | CVE-2025-55708 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-ne… |
| CVE-2025-5569 | CVE-2025-5569 CVSS 8.8 | A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getL… |
| CVE-2025-5566 | CVE-2025-5566 CVSS 8.8 | A vulnerability classified as critical has been found in PHPGurukul Notice Board System 1.0. This affects an unknown part of the file /search-notice.php. The m… |
| CVE-2025-5558 | CVE-2025-5558 CVSS 8.8 | A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This issue affects some unknown processing… |
| CVE-2025-55573 | CVE-2025-55573 CVSS 8.8 | QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2025-5557 | CVE-2025-5557 CVSS 8.8 | A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as critical. This vulnerability affects unknown co… |
| CVE-2025-5556 | CVE-2025-5556 CVSS 8.8 | A vulnerability, which was classified as critical, was found in PHPGurukul Teacher Subject Allocation Management System 1.0. This affects an unknown part of th… |
| CVE-2025-5554 | CVE-2025-5554 CVSS 8.8 | A vulnerability, which was classified as critical, has been found in PHPGurukul Rail Pass Management System 1.0. Affected by this issue is some unknown functio… |
| CVE-2025-5552 | CVE-2025-5552 CVSS 8.8 | A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknown code of the file /dev-api/groovy/exec… |
| CVE-2025-5546 | CVE-2025-5546 CVSS 8.8 | A vulnerability classified as critical was found in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /expense-r… |
| CVE-2025-55454 | CVE-2025-55454 CVSS 8.8 | An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploadin… |
| CVE-2025-55422 | CVE-2025-55422 CVSS 8.8foxcms | In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus. |
| CVE-2025-55420 | CVE-2025-55420 CVSS 8.8 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected… |
| CVE-2025-55409 | CVE-2025-55409 CVSS 8.8foxcms | FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code. |
| CVE-2025-55383 | CVE-2025-55383 CVSS 8.6 | Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any location on the… |
| CVE-2025-55370 | CVE-2025-55370 CVSS 8.8jishenghua | Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID d… |
| CVE-2025-55368 | CVE-2025-55368 CVSS 8.8jishenghua | Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier statu… |
| CVE-2025-55345 | CVE-2025-55345 CVSS 8.8 | Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code ex… |
| CVE-2025-55298 | CVE-2025-55298 CVSS 8.8 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format st… |
| CVE-2025-55297 | CVE-2025-55297 CVSS 8.8 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulnerable to memory overflows in two areas: … |
| CVE-2025-55292 | CVE-2025-55292 CVSS 8.2 | Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC add… |
| CVE-2025-55278 | CVE-2025-55278 CVSS 8.1 | Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accepted without proper validation of their … |
| CVE-2025-55275 | CVE-2025-55275 CVSS 8.1 | HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an … |
| CVE-2025-55271 | CVE-2025-55271 CVSS 8.8 | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an attacker … |
| CVE-2025-5527 | CVE-2025-5527 CVSS 8.8 | A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the fil… |
| CVE-2025-5525 | CVE-2025-5525 CVSS 8.1 | A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/ut… |
| CVE-2025-55227 | CVE-2025-55227 CVSS 8.8 | Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a ne… |
| CVE-2025-55211 | CVE-2025-55211 CVSS 8.8 | FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) c… |
| CVE-2025-5521 | CVE-2025-5521 CVSS 4.35kcrm | A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of… |
| CVE-2025-55165 | CVE-2025-55165 CVSS 8.2 | Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.3, the deb… |
| CVE-2025-55162 | CVE-2025-55162 CVSS 8.8 | Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1… |
| CVE-2025-55158 | CVE-2025-55158 CVSS 8.8 | Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operatio… |
| CVE-2025-55157 | CVE-2025-55157 CVSS 8.8 | Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during eva… |
| CVE-2025-55147 | CVE-2025-55147 CVSS 8.8 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Sec… |
| CVE-2025-55145 | CVE-2025-55145 CVSS 8.9 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivan… |
| CVE-2025-55142 | CVE-2025-55142 CVSS 8.8 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivant… |
| CVE-2025-55141 | CVE-2025-55141 CVSS 8.8 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivant… |
| CVE-2025-55118 | CVE-2025-55118 CVSS 8.9 | Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * … |
| CVE-2025-55116 | CVE-2025-55116 CVSS 8.8 | A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerabil… |
| CVE-2025-55115 | CVE-2025-55115 CVSS 8.8 | A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerabilit… |
| CVE-2025-55069 | CVE-2025-55069 CVSS 8.3 | A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies… |
| CVE-2025-55068 | CVE-2025-55068 CVSS 8.2 | Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time t… |
| CVE-2025-55061 | CVE-2025-55061 CVSS 8.8 | CWE-434 Unrestricted Upload of File with Dangerous Type |
| CVE-2025-55057 | CVE-2025-55057 CVSS 4.5maxum | Multiple CWE-352 Cross-Site Request Forgery (CSRF) |
| CVE-2025-55047 | CVE-2025-55047 CVSS 8.4 | CWE-798 Use of Hard-coded Credentials |
| CVE-2025-55046 | CVE-2025-55046 CVSS 8.1 | MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a sim… |
| CVE-2025-55044 | CVE-2025-55044 CVSS 8.8 | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CS… |