CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6934
9.8 CRITICAL

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to …

Jul 1, 2025
CVE-2025-6081
6.8 MEDIUM

Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earlier allows an attacker can reconfigure the target device to …

Jul 1, 2025
CVE-2025-5967

A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows a malicious user to inject arbitrary HTML into the ENS HX Malware Scan Name field, …

Jul 1, 2025
CVE-2025-6940
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of the file /boafrm/formParentControl of the …

Jul 1, 2025
CVE-2025-6939
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP …

Jul 1, 2025
CVE-2024-49365

tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is …

Jul 1, 2025
CVE-2024-49364

tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing a malicious JSON-stringifiable object, when global …

Jul 1, 2025
CVE-2024-46993

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the …

Jul 1, 2025
CVE-2025-6938
7.3 HIGH

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jul 1, 2025
CVE-2025-53096
5.4 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability …

Jul 1, 2025
CVE-2025-53095
9.6 CRITICAL

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) …

Jul 1, 2025
CVE-2025-53003

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This …

Jul 1, 2025
CVE-2024-46992
7.8 HIGH

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to …

Jul 1, 2025
CVE-2025-6937
7.3 HIGH

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 1, 2025
CVE-2025-53005
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source …

Jul 1, 2025
CVE-2025-36056
5.4 MEDIUM

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable …

Jul 1, 2025
CVE-2025-2141
6.1 MEDIUM

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable …

Jul 1, 2025
CVE-2025-6936
7.3 HIGH

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jul 1, 2025
CVE-2025-6935
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 1, 2025
CVE-2025-6932
3.7 LOW

A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the function g_F_n_GenPassForQlync of the file /bin/httpd of …

Jun 30, 2025
CVE-2025-6931
3.7 LOW

A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulnerability is the function generate_pass_from_mac of the …

Jun 30, 2025
CVE-2025-6930
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/manage-foreigners-ticket.php. The manipulation …

Jun 30, 2025
CVE-2025-6554
8.1 HIGH KEV

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security …

Jun 30, 2025
CVE-2025-6929
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-53004
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's Redshift Data Source …

Jun 30, 2025
CVE-2025-49521
8.8 HIGH

A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. …

Jun 30, 2025
CVE-2025-49520
8.8 HIGH

A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows …

Jun 30, 2025
CVE-2025-32463
9.3 CRITICAL KEV

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

Jun 30, 2025
CVE-2025-32462
2.8 LOW

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to …

Jun 30, 2025
CVE-2025-52997
5.9 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52996
3.1 LOW

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In …

Jun 30, 2025
CVE-2025-52995
8.0 HIGH

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52901
4.5 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52491
5.8 MEDIUM

Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

Jun 30, 2025
CVE-2025-49493
5.8 MEDIUM

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

Jun 30, 2025
CVE-2025-36593
8.8 HIGH

Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access …

Jun 30, 2025
CVE-2025-6925
5.3 MEDIUM

A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java …

Jun 30, 2025
CVE-2025-6917
7.3 HIGH

A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/registration.php. The …

Jun 30, 2025
CVE-2025-52898
8.8 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access …

Jun 30, 2025
CVE-2025-6916
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of …

Jun 30, 2025
CVE-2025-6915
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by this issue is some unknown functionality of …

Jun 30, 2025
CVE-2025-52896
5.4 MEDIUM

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading …

Jun 30, 2025
CVE-2025-52895
7.5 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could …

Jun 30, 2025
CVE-2025-47871
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving …

Jun 30, 2025
CVE-2025-46702
5.4 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions …

Jun 30, 2025
CVE-2025-45931
9.8 CRITICAL

An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file

Jun 30, 2025
CVE-2025-45143
7.0 HIGH

string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.

Jun 30, 2025
CVE-2025-26074
9.8 CRITICAL

Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.

Jun 30, 2025
CVE-2025-6914
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability is an unknown functionality of the file /edit-student.php. …

Jun 30, 2025
CVE-2025-6913
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation …

Jun 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.