CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-52558

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from …

Jun 23, 2025
CVE-2025-2828
10.0 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because …

Jun 23, 2025
CVE-2025-23092
7.2 HIGH

Mitel OpenScape Accounting Management through V5 R1.1.0 could allow an authenticated attacker with administrative privileges to conduct a path traversal attack due to insufficient sanitization …

Jun 23, 2025
CVE-2025-49574
6.4 MEDIUM

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential …

Jun 23, 2025
CVE-2025-48026
7.5 HIGH

A vulnerability in the WebApl component of Mitel OpenScape Xpressions through V7R1 FR5 HF43 P913 could allow an unauthenticated attacker to conduct a path traversal …

Jun 23, 2025
CVE-2025-44528
7.5 HIGH

An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of Service (DoS) via sending a crafted LL_Pause_Enc_Req …

Jun 23, 2025
CVE-2023-47030
9.8 CRITICAL

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a …

Jun 23, 2025
CVE-2021-47688
5.7 MEDIUM

In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be …

Jun 23, 2025
CVE-2025-6547

Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pbkdf2: <=3.1.2.

Jun 23, 2025
CVE-2025-6545

Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from …

Jun 23, 2025
CVE-2025-6518
6.3 MEDIUM

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py …

Jun 23, 2025
CVE-2025-50349
7.5 HIGH

PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.

Jun 23, 2025
CVE-2025-50348
7.5 HIGH

PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.

Jun 23, 2025
CVE-2025-49144
7.3 HIGH

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that …

Jun 23, 2025
CVE-2025-6517
6.3 MEDIUM

A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.java of …

Jun 23, 2025
CVE-2025-49126
8.8 HIGH

Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site …

Jun 23, 2025
CVE-2023-47029
9.8 CRITICAL

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to …

Jun 23, 2025
CVE-2025-6516
5.3 MEDIUM

A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5F_addr_decode_len of the file /hdf5/src/H5Fint.c. The …

Jun 23, 2025
CVE-2025-6511
8.8 HIGH

A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_410090. The manipulation leads to stack-based buffer overflow. It …

Jun 23, 2025
CVE-2025-52969

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 23, 2025
CVE-2023-47031
9.8 CRITICAL

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization …

Jun 23, 2025
CVE-2025-6510
8.8 HIGH

A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is the function sub_415EF8. The manipulation leads …

Jun 23, 2025
CVE-2025-6509
3.5 LOW

A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been declared as problematic. Affected by this vulnerability is the function echo of …

Jun 23, 2025
CVE-2025-4563
2.7 LOW

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the …

Jun 23, 2025
CVE-2023-50450
8.4 HIGH

An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges.

Jun 23, 2025
CVE-2023-47295
9.8 CRITICAL

A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that …

Jun 23, 2025
CVE-2023-47294
8.1 HIGH

An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.

Jun 23, 2025
CVE-2023-47032
9.8 CRITICAL

Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function.

Jun 23, 2025
CVE-2025-52968
2.7 LOW

xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate …

Jun 23, 2025
CVE-2025-52967
5.8 MEDIUM

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

Jun 23, 2025
CVE-2025-52879
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible

Jun 23, 2025
CVE-2025-52878
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions

Jun 23, 2025
CVE-2025-52877
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

Jun 23, 2025
CVE-2025-52876
5.4 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

Jun 23, 2025
CVE-2025-52875
5.4 MEDIUM

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

Jun 23, 2025
CVE-2025-48700
6.1 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI …

Jun 23, 2025
CVE-2025-46101
9.8 CRITICAL

SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain …

Jun 23, 2025
CVE-2023-48978
9.8 CRITICAL

An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP …

Jun 23, 2025
CVE-2023-47298
4.3 MEDIUM

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of …

Jun 23, 2025
CVE-2023-47297
9.8 CRITICAL

A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.

Jun 23, 2025
CVE-2025-52542

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 23, 2025
CVE-2025-2172

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command …

Jun 23, 2025
CVE-2025-2171

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the …

Jun 23, 2025
CVE-2025-6513
9.3 CRITICAL

Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.

Jun 23, 2025
CVE-2025-6512
10.0 CRITICAL

On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server …

Jun 23, 2025
CVE-2025-52922
7.4 HIGH

Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully …

Jun 23, 2025
CVE-2025-52921
9.9 CRITICAL

In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by …

Jun 23, 2025
CVE-2025-52920
6.4 MEDIUM

Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit …

Jun 23, 2025
CVE-2025-23049

Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.

Jun 23, 2025
CVE-2025-52939

Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C. This issue affects NotepadNext: through v0.11.

Jun 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.