CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38238
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out When both the RHBA and …

Jul 9, 2025
CVE-2025-7379

A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of the original tab, leading …

Jul 9, 2025
CVE-2025-3499
10.0 CRITICAL

The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through …

Jul 9, 2025
CVE-2025-3498
9.9 CRITICAL

An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. The device has …

Jul 9, 2025
CVE-2025-3497
8.7 HIGH

The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, …

Jul 9, 2025
CVE-2025-27028
6.8 MEDIUM

The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging …

Jul 9, 2025
CVE-2025-27027
4.1 MEDIUM

A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of …

Jul 9, 2025
CVE-2025-7378

An improper Input Validation vulnerability allows injecting arbitrary values of the NAS configuration file in ASUSTOR ADM. This could potentially lead to system misconfiguration and …

Jul 9, 2025
CVE-2025-7220
7.3 HIGH

A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 9, 2025
CVE-2025-7219
7.3 HIGH

A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=delete_allowances. …

Jul 9, 2025
CVE-2025-7218
7.3 HIGH

A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_position. The …

Jul 9, 2025
CVE-2025-6742
7.5 HIGH

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …

Jul 9, 2025
CVE-2025-6691
8.1 HIGH

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation …

Jul 9, 2025
CVE-2025-7217
7.3 HIGH

A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=save_position. The …

Jul 9, 2025
CVE-2025-7216
7.3 HIGH

A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /application/common.php of …

Jul 9, 2025
CVE-2025-7215
1.6 LOW

A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of …

Jul 9, 2025
CVE-2025-7214
1.6 LOW

A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is an unknown functionality of the file /etc/shadow …

Jul 9, 2025
CVE-2025-7059
6.4 MEDIUM

The Simple Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slideshow’ parameter in all versions up to, and including, 1.3.1 …

Jul 9, 2025
CVE-2025-4606
9.8 CRITICAL

The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and …

Jul 9, 2025
CVE-2025-7213
6.4 MEDIUM

A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The …

Jul 9, 2025
CVE-2025-7212
6.3 MEDIUM

A vulnerability was found in itsourcecode Insurance Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing of …

Jul 9, 2025
CVE-2025-7211
7.3 HIGH

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cart_add.php. The …

Jul 9, 2025
CVE-2025-53688

Rejected reason: Not used

Jul 9, 2025
CVE-2025-53687

Rejected reason: Not used

Jul 9, 2025
CVE-2025-53686

Rejected reason: Not used

Jul 9, 2025
CVE-2025-53685

Rejected reason: Not used

Jul 9, 2025
CVE-2025-53684

Rejected reason: Not used

Jul 9, 2025
CVE-2025-53683

Rejected reason: Not used

Jul 9, 2025
CVE-2025-53682

Rejected reason: Not used

Jul 9, 2025
CVE-2025-7210
6.3 MEDIUM

A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 9, 2025
CVE-2025-5678
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘redirectURL’ parameter …

Jul 9, 2025
CVE-2025-7209
3.3 LOW

A vulnerability has been found in 9fans plan9port up to 9da5b44 and classified as problematic. Affected by this vulnerability is the function value_decode in the …

Jul 9, 2025
CVE-2025-7208
5.5 MEDIUM

A vulnerability was found in 9fans plan9port up to 9da5b44. It has been classified as critical. This affects the function edump in the library /src/plan9port/src/libsec/port/x509.c. …

Jul 9, 2025
CVE-2025-7207
3.3 LOW

A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the …

Jul 9, 2025
CVE-2025-34085

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2020-36847.

Jul 9, 2025
CVE-2025-34084

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2020-36848.

Jul 9, 2025
CVE-2025-34083

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2020-36849.

Jul 9, 2025
CVE-2025-34077

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted …

Jul 9, 2025
CVE-2025-7206
9.8 CRITICAL

A vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file switch_language.cgi of …

Jul 9, 2025
CVE-2025-4855
9.8 CRITICAL

The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in …

Jul 9, 2025
CVE-2025-4828
9.8 CRITICAL

The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions …

Jul 9, 2025
CVE-2025-3780
6.5 MEDIUM

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to …

Jul 9, 2025
CVE-2025-7200
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in krishna9772 Pharmacy Management System up to a2efc8442931ec9308f3b4cf4778e5701153f4e5. Affected is an unknown function of the file …

Jul 8, 2025
CVE-2025-7199
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Library System 1.0. This issue affects some unknown processing of the file /notapprove.php. …

Jul 8, 2025
CVE-2025-47133
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jul 8, 2025
CVE-2025-47132
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jul 8, 2025
CVE-2025-47131
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jul 8, 2025
CVE-2025-47130
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Jul 8, 2025
CVE-2025-47129
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jul 8, 2025
CVE-2025-47128
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.