CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6569
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 24, 2025
CVE-2025-6568
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formIpv6Setup of the component HTTP …

Jun 24, 2025
CVE-2025-6567
7.3 HIGH

A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 24, 2025
CVE-2025-36537
7.0 HIGH

Incorrect Permission Assignment for Critical Resource in the TeamViewer Client (Full and Host) of TeamViewer Remote and Tensor prior Version 15.67 on Windows allows a …

Jun 24, 2025
CVE-2025-32978
7.5 HIGH

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch …

Jun 24, 2025
CVE-2025-32977
9.6 CRITICAL

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch …

Jun 24, 2025
CVE-2025-32976
8.8 HIGH

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch …

Jun 24, 2025
CVE-2025-32975
10.0 CRITICAL KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch …

Jun 24, 2025
CVE-2025-6032
8.3 HIGH

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI …

Jun 24, 2025
CVE-2025-5318
8.1 HIGH

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to …

Jun 24, 2025
CVE-2025-27828
7.1 HIGH

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4 could allow an unauthenticated …

Jun 24, 2025
CVE-2025-27827
7.1 HIGH

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to conduct an information disclosure attack …

Jun 24, 2025
CVE-2025-6566
5.3 MEDIUM

A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the function deserializeArray of the file …

Jun 24, 2025
CVE-2025-6565
8.8 HIGH

A vulnerability was found in Netgear WNCE3001 1.0.0.50. It has been classified as critical. This affects the function http_d of the component HTTP POST Request …

Jun 24, 2025
CVE-2025-6436
8.1 HIGH

Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Jun 24, 2025
CVE-2025-6435
8.1 HIGH

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been …

Jun 24, 2025
CVE-2025-6434
4.3 MEDIUM

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick …

Jun 24, 2025
CVE-2025-6433
9.8 CRITICAL

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that …

Jun 24, 2025
CVE-2025-6432
8.6 HIGH

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not …

Jun 24, 2025
CVE-2025-6431
6.5 MEDIUM

When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could …

Jun 24, 2025
CVE-2025-6430
6.1 MEDIUM

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` …

Jun 24, 2025
CVE-2025-6429
6.5 MEDIUM

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could …

Jun 24, 2025
CVE-2025-6428
4.3 MEDIUM

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to …

Jun 24, 2025
CVE-2025-6427
9.1 CRITICAL

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from …

Jun 24, 2025
CVE-2025-6426
8.8 HIGH

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of …

Jun 24, 2025
CVE-2025-6425
4.3 MEDIUM

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private …

Jun 24, 2025
CVE-2025-6424
9.8 CRITICAL

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, …

Jun 24, 2025
CVE-2025-39205
6.5 MEDIUM

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to …

Jun 24, 2025
CVE-2025-39204
6.5 MEDIUM

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning …

Jun 24, 2025
CVE-2025-39203
6.5 MEDIUM

A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can …

Jun 24, 2025
CVE-2025-39202
7.3 HIGH

A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite …

Jun 24, 2025
CVE-2025-39201
6.1 MEDIUM

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of …

Jun 24, 2025
CVE-2025-2403
7.5 HIGH

A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO series device that if exploited could …

Jun 24, 2025
CVE-2025-1718
6.5 MEDIUM

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk …

Jun 24, 2025
CVE-2025-6206
7.5 HIGH

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file …

Jun 24, 2025
CVE-2025-3092
7.5 HIGH

An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.

Jun 24, 2025
CVE-2025-3091
7.5 HIGH

An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s …

Jun 24, 2025
CVE-2025-5258
6.4 MEDIUM

The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due …

Jun 24, 2025
CVE-2025-50213
9.8 CRITICAL

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: …

Jun 24, 2025
CVE-2025-3090
8.2 HIGH

An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.

Jun 24, 2025
CVE-2025-2962
7.5 HIGH

A denial-of-service issue in the dns implemenation could cause an infinite loop.

Jun 24, 2025
CVE-2025-48890
9.8 CRITICAL

WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a …

Jun 24, 2025
CVE-2025-43879
9.8 CRITICAL

WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the telnet function. If a …

Jun 24, 2025
CVE-2025-43877
5.4 MEDIUM

WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be executed on the web browser of the user who …

Jun 24, 2025
CVE-2025-41427
8.8 HIGH

WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If …

Jun 24, 2025
CVE-2025-36519
4.3 MEDIUM

Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially …

Jun 24, 2025
CVE-2025-52570

Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary amount of simultaneously incoming connections …

Jun 24, 2025
CVE-2025-52568

NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory corruption, …

Jun 24, 2025
CVE-2025-52566
8.6 HIGH

llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer …

Jun 24, 2025
CVE-2025-47943
6.3 MEDIUM

Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, …

Jun 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.