92,393 indexed

CVECVE vulnerabilities

92,393 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 4,901–4,950 of 8,161 in High · page 99 of 164

IDTitleSummary
CVE-2025-54497CVE-2025-54497
CVSS 8.1
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and …
CVE-2025-54470CVE-2025-54470
CVSS 8.6
This vulnerability affects NeuVector deployments only when the Report anonymous cluster data option is enabled. When this option is enabled, NeuVector sends an…
CVE-2025-54441CVE-2025-54441
CVSS 8.8
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Se…
CVE-2025-54439CVE-2025-54439
CVSS 8.8
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Se…
CVE-2025-54417CVE-2025-54417
CVSS 8.8
Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-2…
CVE-2025-54406CVE-2025-54406
CVSS 8.8planet
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP reque…
CVE-2025-54405CVE-2025-54405
CVSS 8.8planet
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP reque…
CVE-2025-54404CVE-2025-54404
CVSS 8.8planet
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead …
CVE-2025-54403CVE-2025-54403
CVSS 8.8planet
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead …
CVE-2025-54402CVE-2025-54402
CVSS 8.8planet
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTT…
CVE-2025-54401CVE-2025-54401
CVSS 8.8planet
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTT…
CVE-2025-54400CVE-2025-54400
CVSS 8.8planet
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTT…
CVE-2025-5440CVE-2025-5440
CVSS 8.8
A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003…
CVE-2025-54399CVE-2025-54399
CVSS 8.8planet
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTT…
CVE-2025-5439CVE-2025-5439
CVSS 8.8
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rat…
CVE-2025-54382CVE-2025-54382
CVSS 8.8
Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry …
CVE-2025-5438CVE-2025-5438
CVSS 8.8
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been dec…
CVE-2025-54378CVE-2025-54378
CVSS 8.3
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and below …
CVE-2025-54374CVE-2025-54374
CVSS 8.8mayneyao
Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code execution vulnerability. An attacker c…
CVE-2025-54366CVE-2025-54366
CVSS 8.8
FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a critical d…
CVE-2025-54317CVE-2025-54317
CVSS 8.4
An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Templa…
CVE-2025-54313Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
KEVCVSS 7.5Prettier
Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the…
CVE-2025-5431CVE-2025-5431
CVSS 8.8
A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of the file /department-profile.php. The man…
CVE-2025-54307CVE-2025-54307
CVSS 8.8
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offli…
CVE-2025-54289CVE-2025-54289
CVSS 8.1
Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions…
CVE-2025-54286CVE-2025-54286
CVSS 8.8
Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user c…
CVE-2025-54264CVE-2025-54264
CVSS 8.1adobe
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) Cross…
CVE-2025-54263CVE-2025-54263
CVSS 8.1adobe
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability.…
CVE-2025-54256CVE-2025-54256
CVSS 8.6
Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in arbitrary code execution i…
CVE-2025-54254CVE-2025-54254
CVSS 8.6
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could …
CVE-2025-5419Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
KEVCVSS 8.8Google
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a craft…
CVE-2025-54153CVE-2025-54153
CVSS 8.8
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to…
CVE-2025-54136CVE-2025-54136
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying an …
CVE-2025-54131CVE-2025-54131
CVSS 8.8
Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with a backtick (`) or $(c…
CVE-2025-54113CVE-2025-54113
CVSS 8.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-54110CVE-2025-54110
CVSS 8.8
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-54106CVE-2025-54106
CVSS 8.8
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-54079CVE-2025-54079
CVSS 8.8
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio…
CVE-2025-54075CVE-2025-54075
CVSS 8.3
MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored…
CVE-2025-54072CVE-2025-54072
CVSS 8.1
yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option is used on Windows with the default plac…
CVE-2025-54062CVE-2025-54062
CVSS 8.8
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio…
CVE-2025-54061CVE-2025-54061
CVSS 8.8
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio…
CVE-2025-54060CVE-2025-54060
CVSS 8.8
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio…
CVE-2025-5406CVE-2025-5406
CVSS 8.8
A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an unknown f…
CVE-2025-54058CVE-2025-54058
CVSS 8.8
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versio…
CVE-2025-54031CVE-2025-54031
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard al…
CVE-2025-5403CVE-2025-5403
CVSS 8.8
A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This affects an unknown part of…
CVE-2025-54026CVE-2025-54026
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBase Theme Classes gymbase_classes allows…
CVE-2025-54007CVE-2025-54007
CVSS 8.8
Deserialization of Untrusted Data vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Object Injection.This issue affects Post Grid an…
CVE-2025-54003CVE-2025-54003
CVSS 8.1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Depot depot allows PHP L…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.