CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-56731
10.0 CRITICAL

Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote …

Jun 24, 2025
CVE-2025-6560
9.8 CRITICAL

Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and …

Jun 24, 2025
CVE-2025-6559
9.8 CRITICAL

Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on …

Jun 24, 2025
CVE-2025-6552
4.3 MEDIUM

A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the …

Jun 24, 2025
CVE-2025-52979

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52978

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52977

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52976

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52975

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52974

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52973

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52972

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52971

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52574
7.5 HIGH

SysmonElixir is a system monitor HTTP service in Elixir. Prior to version 1.0.1, the /read endpoint reads any file from the server's /etc/passwd by default. …

Jun 24, 2025
CVE-2025-52560
8.1 HIGH

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be sent with URLs …

Jun 24, 2025
CVE-2025-48470
4.1 MEDIUM

Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, …

Jun 24, 2025
CVE-2025-48469
9.6 CRITICAL

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public update page, potentially leading to backdoor installation or privilege …

Jun 24, 2025
CVE-2025-48468
6.4 MEDIUM

Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.

Jun 24, 2025
CVE-2025-48467
6.5 MEDIUM

Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to remote denial-of-service and system unavailability.

Jun 24, 2025
CVE-2025-48466
8.1 HIGH

Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of …

Jun 24, 2025
CVE-2025-48463
3.1 LOW

Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on the exposed data as the vulnerable product uses …

Jun 24, 2025
CVE-2025-48462
4.2 MEDIUM

Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block other users from logging in, thereby preventing legitimate …

Jun 24, 2025
CVE-2025-48461
5.0 MEDIUM

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially …

Jun 24, 2025
CVE-2025-6551
3.5 LOW

A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. The manipulation of …

Jun 24, 2025
CVE-2025-6536
3.3 LOW

A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected by this vulnerability is the function tm_to_datetime in the library …

Jun 24, 2025
CVE-2025-34041

An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The …

Jun 24, 2025
CVE-2025-34040

An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart …

Jun 24, 2025
CVE-2025-34039

A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access …

Jun 24, 2025
CVE-2025-34038
7.5 HIGH

A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from the sql parameter into …

Jun 24, 2025
CVE-2025-6535
6.3 MEDIUM

A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file novel-admin/src/main/resources/mybatis/system/UserMapper.xml …

Jun 24, 2025
CVE-2025-6534
4.2 MEDIUM

A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of …

Jun 24, 2025
CVE-2025-34037

An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The …

Jun 24, 2025
CVE-2025-34036
9.8 CRITICAL

An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP …

Jun 24, 2025
CVE-2025-34035
9.8 CRITICAL

An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed …

Jun 24, 2025
CVE-2025-34034
8.8 HIGH

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user …

Jun 24, 2025
CVE-2025-34033
8.8 HIGH

An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. …

Jun 24, 2025
CVE-2025-34032
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application …

Jun 24, 2025
CVE-2025-34031
7.5 HIGH

A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes …

Jun 24, 2025
CVE-2025-6533
5.6 MEDIUM

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of …

Jun 24, 2025
CVE-2025-6532
4.3 MEDIUM

A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerability is an unknown functionality of the component …

Jun 24, 2025
CVE-2025-6531
4.3 MEDIUM

A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability affects unknown code of the component …

Jun 24, 2025
CVE-2025-6530
4.8 MEDIUM

A vulnerability was found in 70mai M300 up to 20250611. It has been classified as problematic. This affects an unknown part of the file demo.sh …

Jun 23, 2025
CVE-2025-6529
8.8 HIGH

A vulnerability was found in 70mai M300 up to 20250611 and classified as critical. Affected by this issue is some unknown functionality of the component …

Jun 23, 2025
CVE-2025-6528
4.3 MEDIUM

A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jun 23, 2025
CVE-2025-6527
3.1 LOW

A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown function of the component Web Server. …

Jun 23, 2025
CVE-2025-6526
3.1 LOW

A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects some unknown processing of the component …

Jun 23, 2025
CVE-2025-6525
4.3 MEDIUM

A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code of the file /cgi-bin/Config.cgi?action=set of the component …

Jun 23, 2025
CVE-2025-6524
3.1 LOW

A vulnerability classified as problematic has been found in 70mai 1S up to 20250611. This affects an unknown part of the component Video Services. The …

Jun 23, 2025
CVE-2025-52562
10.0 CRITICAL

Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a directory traversal vulnerability in the LocaleController …

Jun 23, 2025
CVE-2025-52561

HTMLSanitizer.jl is a Whitelist-based HTML sanitizer. Prior to version 0.2.1, when adding the style tag to the whitelist, content inside the tag is incorrectly unescaped, …

Jun 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.