CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49713
8.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Jul 2, 2025
CVE-2025-45813
9.8 CRITICAL

ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

Jul 2, 2025
CVE-2025-52841
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This issue affects Laundry: 2.3.0.

Jul 2, 2025
CVE-2025-45814
9.8 CRITICAL

Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking …

Jul 2, 2025
CVE-2025-45424
5.3 MEDIUM

Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.

Jul 2, 2025
CVE-2025-20309
10.0 CRITICAL

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote …

Jul 2, 2025
CVE-2025-20307
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks …

Jul 2, 2025
CVE-2025-6943
3.8 LOW

Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.

Jul 2, 2025
CVE-2025-6942
3.8 LOW

The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow …

Jul 2, 2025
CVE-2025-53359

ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EIP-2) was only checked for "legacy" transactions, but …

Jul 2, 2025
CVE-2025-53358
6.5 MEDIUM

kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/index/file/ui.py, the index_fn method accepts both URLs and local file …

Jul 2, 2025
CVE-2025-52886
5.9 MEDIUM

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to …

Jul 2, 2025
CVE-2025-20310
6.1 MEDIUM

A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting …

Jul 2, 2025
CVE-2025-20308
6.0 MEDIUM

A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as …

Jul 2, 2025
CVE-2025-6725
5.4 MEDIUM

In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a …

Jul 2, 2025
CVE-2025-53494
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TwoColConflict Extension allows Stored XSS.This issue affects …

Jul 2, 2025
CVE-2025-53493
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects …

Jul 2, 2025
CVE-2025-53492
3.7 LOW

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects …

Jul 2, 2025
CVE-2025-53110

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could …

Jul 2, 2025
CVE-2025-53109

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could …

Jul 2, 2025
CVE-2025-53108

HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible for updating and …

Jul 2, 2025
CVE-2025-53006
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" …

Jul 2, 2025
CVE-2025-52891
6.5 MEDIUM

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an empty …

Jul 2, 2025
CVE-2025-38093
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: x1e80100: Add GPU cooling Unlike the CPU, the GPU does not throttle …

Jul 2, 2025
CVE-2025-38092
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_list() The list_first_entry() macro never returns NULL. If the list is …

Jul 2, 2025
CVE-2025-38091
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check stream id dml21 wrapper to get plane_id [Why & How] Fix a false …

Jul 2, 2025
CVE-2025-53106
8.8 HIGH

Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated …

Jul 2, 2025
CVE-2025-49588

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and …

Jul 2, 2025
CVE-2025-45029
6.5 MEDIUM

WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cgi.

Jul 2, 2025
CVE-2025-34073

An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary operating system commands via the username parameter in …

Jul 2, 2025
CVE-2025-34072

A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automatic link unfurling. When an AI agent using the Slack …

Jul 2, 2025
CVE-2025-34071
9.8 CRITICAL

A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade …

Jul 2, 2025
CVE-2025-34070
9.8 CRITICAL

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible …

Jul 2, 2025
CVE-2025-34069
9.8 CRITICAL

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The …

Jul 2, 2025
CVE-2025-34067

An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable …

Jul 2, 2025
CVE-2025-34057

An information disclosure vulnerability exists in Ruijie NBR series routers (known to affect NBR2000G, NBR1300G, and NBR1000 models) via the /WEB_VMS/LEVEL15/ endpoint. By crafting a …

Jul 2, 2025
CVE-2025-27026
4.9 MEDIUM

A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticated administrator to make other management interfaces unavailable …

Jul 2, 2025
CVE-2025-46647
5.3 MEDIUM

A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use …

Jul 2, 2025
CVE-2024-35164
6.8 MEDIUM

The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a …

Jul 2, 2025
CVE-2025-39362
6.5 MEDIUM

Missing Authorization vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce.This issue affects Mollie Payments for WooCommerce: from n/a through <= 8.0.2.

Jul 2, 2025
CVE-2025-4946
8.1 HIGH

The Vikinger theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the vikinger_delete_activity_media_ajax() function in all versions up …

Jul 2, 2025
CVE-2025-2330
6.4 MEDIUM

The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button+modal' widget in all versions up …

Jul 2, 2025
CVE-2025-27025
8.8 HIGH

The target device exposes a service on a specific TCP port with a configured endpoint. The access to that endpoint is granted using a Basic …

Jul 2, 2025
CVE-2025-27024
6.5 MEDIUM

Unrestricted access to OS file system in SFTP service in Infinera G42 version R6.1.3 allows remote authenticated users to read/write OS files via SFTP connections. …

Jul 2, 2025
CVE-2025-27023
6.5 MEDIUM

Lack or insufficent input validation in WebGUI CLI web in Infinera G42 version R6.1.3 allows remote authenticated users to read all OS files via crafted …

Jul 2, 2025
CVE-2025-27022
7.5 HIGH

A path traversal vulnerability of the WebGUI HTTP endpoint in Infinera G42 version R6.1.3 allows remote authenticated users to download all OS files via HTTP …

Jul 2, 2025
CVE-2025-27021
7.0 HIGH

The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/write physical memory via …

Jul 2, 2025
CVE-2025-24335
2.0 LOW

Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used …

Jul 2, 2025
CVE-2025-24334
3.3 LOW

The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release version by sending a specific …

Jul 2, 2025
CVE-2025-24333
6.4 MEDIUM

Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use …

Jul 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.