CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4779
6.1 MEDIUM

lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attacker can inject malicious JavaScript into the `v1/runs/ingest` endpoint by adding …

Jul 7, 2025
CVE-2025-3777
3.5 LOW

Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL …

Jul 7, 2025
CVE-2025-3705
6.8 MEDIUM

A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS …

Jul 7, 2025
CVE-2025-3626
9.1 CRITICAL

A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command …

Jul 7, 2025
CVE-2025-3467
5.4 MEDIUM

An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by …

Jul 7, 2025
CVE-2025-3466
7.2 HIGH

langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability …

Jul 7, 2025
CVE-2025-3264
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_imports()` function within `dynamic_module_utils.py`. This vulnerability …

Jul 7, 2025
CVE-2025-3263
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically in the `get_configuration_file()` function within the `transformers.configuration_utils` module. …

Jul 7, 2025
CVE-2025-3262
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository, specifically in version 4.49.0. The vulnerability is due to inefficient regular …

Jul 7, 2025
CVE-2025-3225
7.5 HIGH

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. …

Jul 7, 2025
CVE-2025-3046
7.5 HIGH

A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails …

Jul 7, 2025
CVE-2025-3044
5.3 MEDIUM

A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. …

Jul 7, 2025
CVE-2024-43334
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavias Zilom zilom allows Reflected XSS.This issue affects Zilom: from n/a through < …

Jul 7, 2025
CVE-2025-7121
6.3 MEDIUM

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects an unknown part of the file /users/complaint-details.php. …

Jul 7, 2025
CVE-2025-7120
7.3 HIGH

A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jul 7, 2025
CVE-2025-3920

A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account …

Jul 7, 2025
CVE-2025-7119
7.3 HIGH

A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 7, 2025
CVE-2025-7118
8.8 HIGH

A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affects some unknown processing of the …

Jul 7, 2025
CVE-2025-7117
8.8 HIGH

A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation …

Jul 7, 2025
CVE-2025-7116
8.8 HIGH

A vulnerability classified as critical has been found in UTT 进取 750W up to 3.2.2-191225. This affects an unknown part of the file /goform/Fast_wireless_conf. The …

Jul 7, 2025
CVE-2025-41672
10.0 CRITICAL

A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.

Jul 7, 2025
CVE-2025-7115
7.3 HIGH

A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issue is the function PUT of …

Jul 7, 2025
CVE-2025-7114
7.3 HIGH

A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulnerability is the function POST of …

Jul 7, 2025
CVE-2025-7113
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9.0. It has been classified as problematic. Affected is an unknown function of the file /module/ComponenteCurricular/edit?id=ID of the …

Jul 7, 2025
CVE-2025-7112
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown processing of the file /intranet/educar_funcao_det.php?cod_funcao=COD&ref_cod_instituicao=COD of the component …

Jul 7, 2025
CVE-2025-7111
3.5 LOW

A vulnerability has been found in Portabilis i-Educar 2.9.0 and classified as problematic. This vulnerability affects unknown code of the file /intranet/educar_curso_det.php?cod_curso=ID of the component …

Jul 7, 2025
CVE-2025-53473
7.3 HIGH

Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulnerability is exploited, unintended requests may be sent to …

Jul 7, 2025
CVE-2025-48501
9.8 CRITICAL

An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be …

Jul 7, 2025
CVE-2025-24508
6.4 MEDIUM

Extraction of Account Connectivity Credentials (ACCs) from the IT Management Agent secure storage

Jul 7, 2025
CVE-2025-7110
3.5 LOW

A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9.0. This affects an unknown part of the file /intranet/educar_escola_lst.php of the component …

Jul 7, 2025
CVE-2025-7145
7.2 HIGH

ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermediate privileges to inject arbitrary OS commands and …

Jul 7, 2025
CVE-2025-7109
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file …

Jul 7, 2025
CVE-2025-7108
5.4 MEDIUM

A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vulnerability is the function deleteFile of the file /Digital-Infrastructure-9.6.7/y9-digitalbase-webapp/y9-module-filemanager/risenet-y9boot-webapp-filemanager/src/main/java/net/risesoft/y9public/controller/Y9FileController.java. …

Jul 7, 2025
CVE-2025-7107
5.3 MEDIUM

A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation …

Jul 7, 2025
CVE-2025-53186
5.9 MEDIUM

Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.

Jul 7, 2025
CVE-2025-53185
6.6 MEDIUM

Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Successful exploitation of this …

Jul 7, 2025
CVE-2025-53184
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53183
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53182
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53181
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53180
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53179
6.5 MEDIUM

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

Jul 7, 2025
CVE-2025-53178
4.8 MEDIUM

Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.

Jul 7, 2025
CVE-2025-53177
3.9 LOW

Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule syncing function of watches.

Jul 7, 2025
CVE-2025-53176
3.3 LOW

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53175
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53174
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53173
5.3 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53172
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025
CVE-2025-53171
4.0 MEDIUM

Stack overflow risk when vector images are parsed during file preview Impact: Successful exploitation of this vulnerability may affect the file preview function.

Jul 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.