92,393 indexed
CVECVE vulnerabilities
92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 4,901–4,950 of 8,161 in High · page 99 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-54497 | CVE-2025-54497 CVSS 8.1 | Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and … |
| CVE-2025-54470 | CVE-2025-54470 CVSS 8.6 | This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends an… |
| CVE-2025-54441 | CVE-2025-54441 CVSS 8.8 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Se… |
| CVE-2025-54439 | CVE-2025-54439 CVSS 8.8 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Se… |
| CVE-2025-54417 | CVE-2025-54417 CVSS 8.8 | Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-2… |
| CVE-2025-54406 | CVE-2025-54406 CVSS 8.8planet | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP reque… |
| CVE-2025-54405 | CVE-2025-54405 CVSS 8.8planet | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP reque… |
| CVE-2025-54404 | CVE-2025-54404 CVSS 8.8planet | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead … |
| CVE-2025-54403 | CVE-2025-54403 CVSS 8.8planet | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead … |
| CVE-2025-54402 | CVE-2025-54402 CVSS 8.8planet | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTT… |
| CVE-2025-54401 | CVE-2025-54401 CVSS 8.8planet | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTT… |
| CVE-2025-54400 | CVE-2025-54400 CVSS 8.8planet | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTT… |
| CVE-2025-5440 | CVE-2025-5440 CVSS 8.8 | A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003… |
| CVE-2025-54399 | CVE-2025-54399 CVSS 8.8planet | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTT… |
| CVE-2025-5439 | CVE-2025-5439 CVSS 8.8 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rat… |
| CVE-2025-54382 | CVE-2025-54382 CVSS 8.8 | Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry … |
| CVE-2025-5438 | CVE-2025-5438 CVSS 8.8 | A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been dec… |
| CVE-2025-54378 | CVE-2025-54378 CVSS 8.3 | HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below … |
| CVE-2025-54374 | CVE-2025-54374 CVSS 8.8mayneyao | Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code execution vulnerability. An attacker c… |
| CVE-2025-54366 | CVE-2025-54366 CVSS 8.8 | FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a critical d… |
| CVE-2025-54317 | CVE-2025-54317 CVSS 8.4 | An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Templa… |
| CVE-2025-54313 | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability KEVCVSS 7.5Prettier | Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the… |
| CVE-2025-5431 | CVE-2025-5431 CVSS 8.8 | A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of the file /department-profile.php. The man… |
| CVE-2025-54307 | CVE-2025-54307 CVSS 8.8 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offli… |
| CVE-2025-54289 | CVE-2025-54289 CVSS 8.1 | Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions… |
| CVE-2025-54286 | CVE-2025-54286 CVSS 8.8 | Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user c… |
| CVE-2025-54264 | CVE-2025-54264 CVSS 8.1adobe | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) Cross… |
| CVE-2025-54263 | CVE-2025-54263 CVSS 8.1adobe | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability.… |
| CVE-2025-54256 | CVE-2025-54256 CVSS 8.6 | Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in arbitrary code execution i… |
| CVE-2025-54254 | CVE-2025-54254 CVSS 8.6 | Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could … |
| CVE-2025-5419 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability KEVCVSS 8.8Google | Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a craft… |
| CVE-2025-54153 | CVE-2025-54153 CVSS 8.8 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to… |
| CVE-2025-54136 | CVE-2025-54136 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an … |
| CVE-2025-54131 | CVE-2025-54131 CVSS 8.8 | Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick (`) or $(c… |
| CVE-2025-54113 | CVE-2025-54113 CVSS 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-54110 | CVE-2025-54110 CVSS 8.8 | Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54106 | CVE-2025-54106 CVSS 8.8 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-54079 | CVE-2025-54079 CVSS 8.8 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio… |
| CVE-2025-54075 | CVE-2025-54075 CVSS 8.3 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored… |
| CVE-2025-54072 | CVE-2025-54072 CVSS 8.1 | yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option is used on Windows with the default plac… |
| CVE-2025-54062 | CVE-2025-54062 CVSS 8.8 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio… |
| CVE-2025-54061 | CVE-2025-54061 CVSS 8.8 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio… |
| CVE-2025-54060 | CVE-2025-54060 CVSS 8.8 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio… |
| CVE-2025-5406 | CVE-2025-5406 CVSS 8.8 | A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an unknown f… |
| CVE-2025-54058 | CVE-2025-54058 CVSS 8.8 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio… |
| CVE-2025-54031 | CVE-2025-54031 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard al… |
| CVE-2025-5403 | CVE-2025-5403 CVSS 8.8 | A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This affects an unknown part of… |
| CVE-2025-54026 | CVE-2025-54026 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBase Theme Classes gymbase_classes allows… |
| CVE-2025-54007 | CVE-2025-54007 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Object Injection.This issue affects Post Grid an… |
| CVE-2025-54003 | CVE-2025-54003 CVSS 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Depot depot allows PHP L… |