CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20681
9.8 CRITICAL

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jul 8, 2025
CVE-2025-20680
9.8 CRITICAL

In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Jul 8, 2025
CVE-2025-7156
6.3 MEDIUM

A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the function execute of the file /v1/chat/completions. The manipulation …

Jul 8, 2025
CVE-2025-7146
7.5 HIGH

The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to read arbitrary system file.

Jul 8, 2025
CVE-2025-7155
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects an unknown part of the file /Dashboard …

Jul 8, 2025
CVE-2025-7154
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK N200RE 9.3.5u.6095_B20200916/9.3.5u.6139_B20201216. Affected by this issue is the function sub_41A0F8 of the file …

Jul 8, 2025
CVE-2025-43001
6.9 MEDIUM

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting …

Jul 8, 2025
CVE-2025-42992
6.9 MEDIUM

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical …

Jul 8, 2025
CVE-2025-42986
4.3 MEDIUM

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function …

Jul 8, 2025
CVE-2025-42985
6.1 MEDIUM

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could …

Jul 8, 2025
CVE-2025-42981
6.1 MEDIUM

Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at …

Jul 8, 2025
CVE-2025-42980
9.1 CRITICAL

SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead …

Jul 8, 2025
CVE-2025-42979
5.6 MEDIUM

The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an …

Jul 8, 2025
CVE-2025-42978
3.5 LOW

The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for …

Jul 8, 2025
CVE-2025-42974
4.3 MEDIUM

Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally …

Jul 8, 2025
CVE-2025-42973
5.4 MEDIUM

Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status …

Jul 8, 2025
CVE-2025-42971
4.0 MEDIUM

A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it …

Jul 8, 2025
CVE-2025-42970
5.8 MEDIUM

SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. …

Jul 8, 2025
CVE-2025-42969
6.1 MEDIUM

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when …

Jul 8, 2025
CVE-2025-42968
5.0 MEDIUM

SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and …

Jul 8, 2025
CVE-2025-42967
9.9 CRITICAL

SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report …

Jul 8, 2025
CVE-2025-42966
9.1 CRITICAL

SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted …

Jul 8, 2025
CVE-2025-42965
4.1 MEDIUM

SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times …

Jul 8, 2025
CVE-2025-42964
9.1 CRITICAL

SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a …

Jul 8, 2025
CVE-2025-42963
9.1 CRITICAL

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can …

Jul 8, 2025
CVE-2025-42962
6.1 MEDIUM

SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script …

Jul 8, 2025
CVE-2025-42961
4.9 MEDIUM

Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of …

Jul 8, 2025
CVE-2025-42960
4.3 MEDIUM

SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This …

Jul 8, 2025
CVE-2025-42959
8.1 HIGH

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused …

Jul 8, 2025
CVE-2025-42954
2.7 LOW

SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any …

Jul 8, 2025
CVE-2025-42953
8.1 HIGH

SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity …

Jul 8, 2025
CVE-2025-42952
7.7 HIGH

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system …

Jul 8, 2025
CVE-2025-31326
4.1 MEDIUM

SAP�BusinessObjects Business�Intelligence Platform (Web Intelligence) is vulnerable to HTML Injection, allowing an attacker with basic user privileges to inject malicious code into specific input fields. …

Jul 8, 2025
CVE-2025-7153
3.5 LOW

A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jul 8, 2025
CVE-2025-7152
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unknown function of the file /admin/candidates_add.php. The …

Jul 8, 2025
CVE-2025-7151
6.3 MEDIUM

A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jul 7, 2025
CVE-2025-7150
6.3 MEDIUM

A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 7, 2025
CVE-2025-7149
6.3 MEDIUM

A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jul 7, 2025
CVE-2025-7148
3.5 LOW

A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Jul 7, 2025
CVE-2025-7147
7.3 HIGH

A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 7, 2025
CVE-2025-7144
2.4 LOW

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /panel/admin-profile.php …

Jul 7, 2025
CVE-2025-7143
2.4 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/edit-tax.php …

Jul 7, 2025
CVE-2025-7142
2.4 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality …

Jul 7, 2025
CVE-2025-53543
4.2 MEDIUM

Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response …

Jul 7, 2025
CVE-2025-53540

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Several OTA update examples and the HTTPUpdateServer implementation are vulnerable …

Jul 7, 2025
CVE-2025-53539
7.5 HIGH

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. fastapi-guard's penetration attempts detection uses …

Jul 7, 2025
CVE-2025-53496
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MediaSearch Extension allows Stored XSS.This issue affects …

Jul 7, 2025
CVE-2025-7141
2.4 LOW

A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jul 7, 2025
CVE-2025-7140
2.4 LOW

A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-staff.php of …

Jul 7, 2025
CVE-2025-6044
6.1 MEDIUM

An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the garaged stylus devices allows a physical attacker to …

Jul 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.