92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,851–4,900 of 8,161 in High · page 98 of 164

IDTitleSummary
CVE-2025-55041CVE-2025-55041
CVSS 8.0
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attacker…
CVE-2025-55040CVE-2025-55040
CVSS 8.8
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vuln…
CVE-2025-55034CVE-2025-55034
CVSS 8.2
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force att…
CVE-2025-5503CVE-2025-5503
CVSS 8.8
A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the function formMapReboot of the file /boafrm/…
CVE-2025-55006CVE-2025-55006
CVSS 8.8
Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately …
CVE-2025-54988CVE-2025-54988
CVSS 8.4
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML Exter…
CVE-2025-54968CVE-2025-54968
CVSS 8.8
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remo…
CVE-2025-54964CVE-2025-54964
CVSS 8.4
An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If…
CVE-2025-54955CVE-2025-54955
CVSS 8.1
OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account …
CVE-2025-54920CVE-2025-54920
CVSS 8.8
This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summ…
CVE-2025-5492CVE-2025-5492
CVSS 8.8
A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnerability is the function sub_456DE8 of th…
CVE-2025-54918CVE-2025-54918
CVSS 8.8
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-54910CVE-2025-54910
CVSS 8.4
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-5491CVE-2025-5491
CVSS 8.8
Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functi…
CVE-2025-54897CVE-2025-54897
CVSS 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-54886CVE-2025-54886
CVSS 8.4
skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain a…
CVE-2025-54878CVE-2025-54878
CVSS 8.6
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between …
CVE-2025-5485CVE-2025-5485
CVSS 8.6
User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. A malici…
CVE-2025-5484CVE-2025-5484
CVSS 8.3
A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier prin…
CVE-2025-5483CVE-2025-5483
CVSS 8.1
The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wizard/inc/wp_user.php file in versions 1…
CVE-2025-54820CVE-2025-54820
CVSS 8.1
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManag…
CVE-2025-5482CVE-2025-5482
CVSS 8.8
The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege escalation via account takeover in all v…
CVE-2025-54818CVE-2025-54818
CVSS 8.0
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying syst…
CVE-2025-54815CVE-2025-54815
CVSS 8.8
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.
CVE-2025-54810CVE-2025-54810
CVSS 8.0
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying syst…
CVE-2025-54788CVE-2025-54788
CVSS 8.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows…
CVE-2025-54785CVE-2025-54785
CVSS 8.8
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is…
CVE-2025-54782CVE-2025-54782
CVSS 8.8
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability w…
CVE-2025-5478CVE-2025-5478
CVSS 8.8
Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute ar…
CVE-2025-54769CVE-2025-54769
CVSS 8.8
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This ca…
CVE-2025-54761CVE-2025-54761
CVSS 8.0
An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.
CVE-2025-5476CVE-2025-5476
CVSS 8.8
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication…
CVE-2025-54757CVE-2025-54757
CVSS 8.0
Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an…
CVE-2025-54756CVE-2025-54756
CVSS 8.4
BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of…
CVE-2025-54754CVE-2025-54754
CVSS 8.0
An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available sof…
CVE-2025-54752CVE-2025-54752
CVSS 8.0
Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it…
CVE-2025-54742CVE-2025-54742
CVSS 8.8
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a thro…
CVE-2025-54735CVE-2025-54735
CVSS 8.8
Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a through <…
CVE-2025-54731CVE-2025-54731
CVSS 8.1
Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showcase allows Object Injection.This issue …
CVE-2025-5473CVE-2025-5473
CVSS 8.8
GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in…
CVE-2025-54719CVE-2025-54719
CVSS 8.8
Deserialization of Untrusted Data vulnerability in NooTheme Yogi - Health Beauty & Yoga noo-yogi allows Object Injection.This issue affects Yogi - Health Beaut…
CVE-2025-54716CVE-2025-54716
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme Ireca ireca allows PHP Local …
CVE-2025-54709CVE-2025-54709
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala. This issue affects Sala: f…
CVE-2025-54690CVE-2025-54690
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek Xinterio xinterio allows PHP…
CVE-2025-54689CVE-2025-54689
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local Fil…
CVE-2025-54627CVE-2025-54627
CVSS 8.8
Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-5459CVE-2025-5459
CVSS 8.8puppet
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It a…
CVE-2025-54550CVE-2025-54550
CVSS 8.1apache
The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to…
CVE-2025-54536CVE-2025-54536
CVSS 8.8
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
CVE-2025-54528CVE-2025-54528
CVSS 8.8
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.