CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6554
8.1 HIGH KEV

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security …

Jun 30, 2025
CVE-2025-6929
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-53004
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's Redshift Data Source …

Jun 30, 2025
CVE-2025-49521
8.8 HIGH

A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. …

Jun 30, 2025
CVE-2025-49520
8.8 HIGH

A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows …

Jun 30, 2025
CVE-2025-32463
9.3 CRITICAL KEV

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

Jun 30, 2025
CVE-2025-32462
2.8 LOW

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to …

Jun 30, 2025
CVE-2025-52997
5.9 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52996
3.1 LOW

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In …

Jun 30, 2025
CVE-2025-52995
8.0 HIGH

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52901
4.5 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52491
5.8 MEDIUM

Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

Jun 30, 2025
CVE-2025-49493
5.8 MEDIUM

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

Jun 30, 2025
CVE-2025-36593
8.8 HIGH

Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access …

Jun 30, 2025
CVE-2025-6925
5.3 MEDIUM

A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java …

Jun 30, 2025
CVE-2025-6917
7.3 HIGH

A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/registration.php. The …

Jun 30, 2025
CVE-2025-52898
8.8 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access …

Jun 30, 2025
CVE-2025-6916
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of …

Jun 30, 2025
CVE-2025-6915
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by this issue is some unknown functionality of …

Jun 30, 2025
CVE-2025-52896
5.4 MEDIUM

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading …

Jun 30, 2025
CVE-2025-52895
7.5 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could …

Jun 30, 2025
CVE-2025-47871
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving …

Jun 30, 2025
CVE-2025-46702
5.4 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions …

Jun 30, 2025
CVE-2025-45931
9.8 CRITICAL

An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file

Jun 30, 2025
CVE-2025-45143
7.0 HIGH

string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.

Jun 30, 2025
CVE-2025-26074
9.8 CRITICAL

Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.

Jun 30, 2025
CVE-2025-6914
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability is an unknown functionality of the file /edit-student.php. …

Jun 30, 2025
CVE-2025-6913
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation …

Jun 30, 2025
CVE-2025-53017

Rejected reason: Reason: This candidate was issued in error.

Jun 30, 2025
CVE-2025-53001

Rejected reason: Reason: This candidate was issued in error.

Jun 30, 2025
CVE-2024-12915
4.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS.This issue affects Library Software: …

Jun 30, 2025
CVE-2025-6912
6.3 MEDIUM

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-6911
6.3 MEDIUM

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /manage-subjects.php. …

Jun 30, 2025
CVE-2025-2895
5.4 MEDIUM

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote attacker could inject …

Jun 30, 2025
CVE-2024-53621
7.5 HIGH

A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to cause a Denial of Service (DoS) via a crafted …

Jun 30, 2025
CVE-2023-47310
6.5 MEDIUM

A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.

Jun 30, 2025
CVE-2025-6910
6.3 MEDIUM

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been classified as critical. This affects an unknown part of the file /session.php. …

Jun 30, 2025
CVE-2025-6909
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Jun 30, 2025
CVE-2025-6908
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file …

Jun 30, 2025
CVE-2025-6907
7.3 HIGH

A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unknown code of the file /book_car.php. The manipulation of …

Jun 30, 2025
CVE-2025-6906
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Car Rental System 1.0. This affects an unknown part of the file /login.php. The manipulation …

Jun 30, 2025
CVE-2025-6905
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-4407
6.7 MEDIUM

Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.

Jun 30, 2025
CVE-2025-6904
7.3 HIGH

A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jun 30, 2025
CVE-2025-6903
7.3 HIGH

A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 30, 2025
CVE-2025-40710

Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when accessing third-party web applications through the VPN tunnel. …

Jun 30, 2025
CVE-2025-6902
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /php_action/editUser.php. …

Jun 30, 2025
CVE-2025-6901
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/removeUser.php. The …

Jun 30, 2025
CVE-2025-53416
7.8 HIGH

Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Jun 30, 2025
CVE-2025-41439
6.1 MEDIUM

A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary …

Jun 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.