CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-34089

An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in versions up to and …

Jul 3, 2025
CVE-2025-34088
8.8 HIGH

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands …

Jul 3, 2025
CVE-2025-34087
8.8 HIGH

An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain …

Jul 3, 2025
CVE-2025-34086
8.8 HIGH

Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with …

Jul 3, 2025
CVE-2025-34082

A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Shadow services. The flaw arises due to …

Jul 3, 2025
CVE-2025-34061

A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. The backdoor listens for base64-encoded …

Jul 3, 2025
CVE-2025-45809
5.4 MEDIUM

SQL Injection vulnerability in BerriAI LiteLLM before 1.81.0 allows attackers to execute arbitrary commands via the key parameter to the "/key/block" and "/key/unblock" API endpoints.

Jul 3, 2025
CVE-2025-23968
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud …

Jul 3, 2025
CVE-2025-6926
8.8 HIGH

Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from …

Jul 3, 2025
CVE-2025-6074
6.5 MEDIUM

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains …

Jul 3, 2025
CVE-2025-6073
7.5 HIGH

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to …

Jul 3, 2025
CVE-2025-6072
7.5 HIGH

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to …

Jul 3, 2025
CVE-2025-6071
5.3 MEDIUM

Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to salted information to decrypt MQTT information. This …

Jul 3, 2025
CVE-2025-53502
6.5 MEDIUM

Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - FeaturedFeeds Extension: 1.39.X, 1.42.X, 1.43.X.

Jul 3, 2025
CVE-2025-53501
8.8 HIGH

Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto …

Jul 3, 2025
CVE-2025-53500
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects …

Jul 3, 2025
CVE-2025-53489
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - GoogleDocs4MW Extension allows Cross-Site Scripting (XSS).This issue …

Jul 3, 2025
CVE-2025-49846

wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view …

Jul 3, 2025
CVE-2025-48939
4.2 MEDIUM

tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that …

Jul 3, 2025
CVE-2025-53490
5.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue …

Jul 3, 2025
CVE-2025-45938
5.4 MEDIUM

Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName parameter.

Jul 3, 2025
CVE-2025-5961
7.2 HIGH

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

Jul 3, 2025
CVE-2025-50263
8.1 HIGH

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the list parameter.

Jul 3, 2025
CVE-2025-50262
7.5 HIGH

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetQosBand function via the list parameter.

Jul 3, 2025
CVE-2025-50260
7.5 HIGH

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetFirewallCfg function via the firewallEn parameter.

Jul 3, 2025
CVE-2025-50258
8.1 HIGH

Tenda AC6 v15.03.05.16_multi is vulnerable to Buffer Overflow in the SetSysTimeCfg function via the time parameter.

Jul 3, 2025
CVE-2025-43713
6.5 MEDIUM

ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated …

Jul 3, 2025
CVE-2025-49618
5.8 MEDIUM

In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.

Jul 3, 2025
CVE-2025-49595
4.9 MEDIUM

n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs …

Jul 3, 2025
CVE-2025-49032
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Gutenberg Blocks advanced-gutenberg allows Stored XSS.This issue affects Gutenberg Blocks: from n/a …

Jul 3, 2025
CVE-2025-3702
5.4 MEDIUM

Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Melapress File Monitor: from n/a through …

Jul 3, 2025
CVE-2025-2932
8.8 HIGH

The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'font_upload_handler' function in all versions up …

Jul 3, 2025
CVE-2025-2537
6.4 MEDIUM

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScript library (version 3.1) in various versions due to insufficient …

Jul 3, 2025
CVE-2025-6563

A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the …

Jul 3, 2025
CVE-2025-40723

Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation …

Jul 3, 2025
CVE-2025-40722

Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation …

Jul 3, 2025
CVE-2025-2540
6.4 MEDIUM

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled prettyPhoto library (version 3.1.6) in various versions due to insufficient input …

Jul 3, 2025
CVE-2025-27461
7.6 HIGH

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

Jul 3, 2025
CVE-2025-27460
7.6 HIGH

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access …

Jul 3, 2025
CVE-2025-27459
4.4 MEDIUM

The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.

Jul 3, 2025
CVE-2025-27458
6.5 MEDIUM

The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from …

Jul 3, 2025
CVE-2025-27457
6.5 MEDIUM

All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.

Jul 3, 2025
CVE-2025-27456
7.5 HIGH

The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to …

Jul 3, 2025
CVE-2025-27455
4.3 MEDIUM

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking …

Jul 3, 2025
CVE-2025-27454
4.3 MEDIUM

The application is vulnerable to cross-site request forgery. An attacker can trick a valid, logged in user into submitting a web request that they did …

Jul 3, 2025
CVE-2025-27453
5.3 MEDIUM

The HttpOnly flag is set to false on the PHPSESSION cookie. Therefore, the cookie can be accessed by other sources such as JavaScript.

Jul 3, 2025
CVE-2025-27452
5.3 MEDIUM

The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for …

Jul 3, 2025
CVE-2025-27451
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Jul 3, 2025
CVE-2025-27450
6.5 MEDIUM

The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker can trick a user to establish an unencrypted HTTP connection to …

Jul 3, 2025
CVE-2025-27449
7.5 HIGH

The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

Jul 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.