CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40711
9.8 CRITICAL

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases …

Jul 8, 2025
CVE-2025-7175
6.3 MEDIUM

A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/users_photo.php. The …

Jul 8, 2025
CVE-2025-7174
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknown processing of the file /teacher-issue-book.php. The manipulation …

Jul 8, 2025
CVE-2025-41224
8.8 HIGH

A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.10.0), RUGGEDCOM RS416NCv2 V5.X (All versions …

Jul 8, 2025
CVE-2025-41223
4.8 MEDIUM

A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOM i803 (All versions), RUGGEDCOM M2100 (All …

Jul 8, 2025
CVE-2025-41222
5.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOM i803 (All versions), RUGGEDCOM M2100 (All …

Jul 8, 2025
CVE-2025-40742
5.3 MEDIUM

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All …

Jul 8, 2025
CVE-2025-40741
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain a stack based overflow vulnerability while …

Jul 8, 2025
CVE-2025-40740
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past …

Jul 8, 2025
CVE-2025-40739
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past …

Jul 8, 2025
CVE-2025-40738
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP …

Jul 8, 2025
CVE-2025-40737
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly validate file paths when extracting uploaded ZIP …

Jul 8, 2025
CVE-2025-40736
9.8 CRITICAL

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative …

Jul 8, 2025
CVE-2025-40735
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injection. This could allow an unauthenticated …

Jul 8, 2025
CVE-2025-40593
6.5 MEDIUM

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files …

Jul 8, 2025
CVE-2025-27127
4.3 MEDIUM

A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All …

Jul 8, 2025
CVE-2025-23365
7.8 HIGH

A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files …

Jul 8, 2025
CVE-2025-23364
6.2 MEDIUM

A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. This could allow an attacker …

Jul 8, 2025
CVE-2025-21009
5.5 MEDIUM

Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Jul 8, 2025
CVE-2025-21008
5.5 MEDIUM

Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Jul 8, 2025
CVE-2025-21007
5.5 MEDIUM

Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Jul 8, 2025
CVE-2025-21006
7.0 HIGH

Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.

Jul 8, 2025
CVE-2025-21005
5.5 MEDIUM

Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.

Jul 8, 2025
CVE-2025-21004
6.2 MEDIUM

Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off …

Jul 8, 2025
CVE-2025-21003
4.0 MEDIUM

Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.

Jul 8, 2025
CVE-2025-21002
6.2 MEDIUM

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.

Jul 8, 2025
CVE-2025-21001
6.2 MEDIUM

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.

Jul 8, 2025
CVE-2025-21000
6.2 MEDIUM

Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.

Jul 8, 2025
CVE-2025-20999
4.1 MEDIUM

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

Jul 8, 2025
CVE-2025-20998
5.5 MEDIUM

Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.

Jul 8, 2025
CVE-2025-20997
6.2 MEDIUM

Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.

Jul 8, 2025
CVE-2025-20983
6.4 MEDIUM

Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Jul 8, 2025
CVE-2025-20982
6.4 MEDIUM

Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Jul 8, 2025
CVE-2024-31854
8.1 HIGH

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a …

Jul 8, 2025
CVE-2024-31853
8.1 HIGH

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connection to the TLS server of a …

Jul 8, 2025
CVE-2023-52236
7.0 HIGH

A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOM i803 (All versions), RUGGEDCOM M2100 (All …

Jul 8, 2025
CVE-2025-7173
7.3 HIGH

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-student.php. The manipulation …

Jul 8, 2025
CVE-2025-7172
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Crime Reporting System 1.0. This affects an unknown part of the file /headlogin.php. The …

Jul 8, 2025
CVE-2025-6744
7.3 HIGH

The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the …

Jul 8, 2025
CVE-2025-7171
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Crime Reporting System 1.0. Affected by this issue is some unknown functionality of …

Jul 8, 2025
CVE-2025-7170
7.3 HIGH

A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. …

Jul 8, 2025
CVE-2025-7169
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknown function of the file /complainer_page.php. The manipulation …

Jul 8, 2025
CVE-2025-7168
7.3 HIGH

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 8, 2025
CVE-2025-38237
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() In fimc_is_hw_change_mode(), the function changes camera …

Jul 8, 2025
CVE-2025-38236
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs. Jann Horn reported a use-after-free in unix_stream_read_generic(). The …

Jul 8, 2025
CVE-2025-7346

Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages

Jul 8, 2025
CVE-2025-7167
6.3 MEDIUM

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. …

Jul 8, 2025
CVE-2025-7166
6.3 MEDIUM

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an unknown part of the file /single.php. …

Jul 8, 2025
CVE-2025-6746
8.8 HIGH

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes …

Jul 8, 2025
CVE-2025-6743
6.4 MEDIUM

The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attribute in all versions up to, and including, 8.2.3 due …

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.