CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6272
3.3 LOW

A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads …

Jun 19, 2025
CVE-2025-6271
3.3 LOW

A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the …

Jun 19, 2025
CVE-2025-36050
6.2 MEDIUM

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.

Jun 19, 2025
CVE-2025-33121
7.1 HIGH

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote …

Jun 19, 2025
CVE-2025-33117
9.1 CRITICAL

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a …

Jun 19, 2025
CVE-2025-6270
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5FS__sect_find_node of the …

Jun 19, 2025
CVE-2025-50200
5.5 MEDIUM

RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ …

Jun 19, 2025
CVE-2025-6269
5.3 MEDIUM

A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5C__reconstruct_cache_entry of the file H5Cimage.c. The …

Jun 19, 2025
CVE-2025-52464
8.3 HIGH

Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure of several hardware vendors was resulting in …

Jun 19, 2025
CVE-2006-2192

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 19, 2025
CVE-2025-6268
4.3 MEDIUM

A vulnerability classified as problematic has been found in Luna Imaging up to 7.5.5.6. Affected is an unknown function of the file /luna/servlet/view/search. The manipulation …

Jun 19, 2025
CVE-2025-49014

jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has …

Jun 19, 2025
CVE-2025-48886
4.8 MEDIUM

Hydra is a layer-two scalability solution for Cardano. Prior to version 0.22.0, the process assumes L1 event finality and does not consider failed transactions. Currently, …

Jun 19, 2025
CVE-2025-6267
6.3 MEDIUM

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated as critical. This issue affects some unknown processing …

Jun 19, 2025
CVE-2024-24916
6.5 MEDIUM

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

Jun 19, 2025
CVE-2025-4738
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software MY ERP allows SQL Injection.This issue affects MY ERP: …

Jun 19, 2025
CVE-2025-6266
6.3 MEDIUM

A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Performing manipulation …

Jun 19, 2025
CVE-2025-6019
7.0 HIGH

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions …

Jun 19, 2025
CVE-2025-32896
6.5 MEDIUM

# Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` …

Jun 19, 2025
CVE-2005-2347

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 19, 2025
CVE-2025-5234
6.4 MEDIUM

The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in all versions up to, and including, 1.0.4 due …

Jun 19, 2025
CVE-2025-5071
8.8 HIGH

The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the …

Jun 19, 2025
CVE-2025-49763
7.5 HIGH

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use …

Jun 19, 2025
CVE-2025-31698
7.5 HIGH

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to …

Jun 19, 2025
CVE-2016-3399

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 19, 2025
CVE-2025-4965
6.4 MEDIUM

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Builder feature in all versions up …

Jun 19, 2025
CVE-2025-4571
5.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized view and modification of data due to an insufficient capability …

Jun 19, 2025
CVE-2025-5490
5.5 MEDIUM

The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.4 due to …

Jun 19, 2025
CVE-2025-5524
4.9 MEDIUM

The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up to, and including, 4.0.9 due …

Jun 19, 2025
CVE-2025-52474
9.8 CRITICAL

WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified in the id parameter of the /WeGIA/controle/control.php …

Jun 19, 2025
CVE-2025-50201
9.8 CRITICAL

WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was identified in the /html/configuracao/debug_info.php endpoint. The branch …

Jun 19, 2025
CVE-2025-4479
6.4 MEDIUM

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in all …

Jun 19, 2025
CVE-2025-4367
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 …

Jun 19, 2025
CVE-2025-6201
6.4 MEDIUM

The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 19, 2025
CVE-2025-52467
9.1 CRITICAL

pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to commit 8eb3567, the pgai repository was …

Jun 19, 2025
CVE-2025-50183
6.5 MEDIUM

OpenList Frontend is a UI component for OpenList. Prior to version 4.0.0-rc.4, a vulnerability exists in the file preview/browsing feature of the application, where files …

Jun 19, 2025
CVE-2025-4661
2.3 LOW

A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended …

Jun 19, 2025
CVE-2025-50182
5.3 MEDIUM

urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and …

Jun 19, 2025
CVE-2025-50181
5.3 MEDIUM

urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager …

Jun 19, 2025
CVE-2025-24291
6.1 MEDIUM

The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection …

Jun 19, 2025
CVE-2025-24288
9.8 CRITICAL

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most …

Jun 19, 2025
CVE-2025-24287
6.1 MEDIUM

A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.

Jun 19, 2025
CVE-2025-24286
7.2 HIGH

A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.

Jun 19, 2025
CVE-2025-23173
7.5 HIGH

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed …

Jun 19, 2025
CVE-2025-23172
7.2 HIGH

The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities …

Jun 19, 2025
CVE-2025-23171
7.2 HIGH

The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. …

Jun 19, 2025
CVE-2025-23170
6.7 MEDIUM

The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, …

Jun 19, 2025
CVE-2025-23169
6.1 MEDIUM

The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations …

Jun 19, 2025
CVE-2025-23168
6.3 MEDIUM

The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input …

Jun 19, 2025
CVE-2025-23121
8.8 HIGH

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

Jun 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.