CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6150
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the …

Jun 17, 2025
CVE-2025-6149
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK A3002R 4.0.0-B20230531.1404. Affected is an unknown function of the file /boafrm/formSysLog of the component HTTP …

Jun 17, 2025
CVE-2025-6148
8.8 HIGH

A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formSysLog of …

Jun 17, 2025
CVE-2025-6147
8.8 HIGH

A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formSysLog of the …

Jun 17, 2025
CVE-2025-48993
6.1 MEDIUM

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the …

Jun 17, 2025
CVE-2025-6146
8.8 HIGH

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. This affects an unknown part of the file /boafrm/formSysLog of the …

Jun 17, 2025
CVE-2025-6145
8.8 HIGH

A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formSysLog of …

Jun 16, 2025
CVE-2025-6144
8.8 HIGH

A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formSysCmd …

Jun 16, 2025
CVE-2025-6143
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formNtp of the component …

Jun 16, 2025
CVE-2025-48992
4.8 MEDIUM

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a stored and blind cross-site scripting (XSS) vulnerability exists …

Jun 16, 2025
CVE-2025-6142
6.3 MEDIUM

A vulnerability was found in Intera InHire up to 20250530. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The …

Jun 16, 2025
CVE-2025-6141
3.3 LOW

A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. …

Jun 16, 2025
CVE-2025-6140
3.3 LOW

A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped_padder in the library include/spdlog/pattern_formatter-inl.h. The manipulation …

Jun 16, 2025
CVE-2025-43200
4.2 MEDIUM KEV

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and …

Jun 16, 2025
CVE-2025-27587
5.3 MEDIUM

OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using …

Jun 16, 2025
CVE-2025-6139
3.9 LOW

A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file …

Jun 16, 2025
CVE-2025-6138
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the …

Jun 16, 2025
CVE-2025-49134
5.3 MEDIUM

Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This …

Jun 16, 2025
CVE-2025-47951
4.9 MEDIUM

Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence …

Jun 16, 2025
CVE-2025-32800
9.8 CRITICAL

Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not …

Jun 16, 2025
CVE-2025-32799
9.8 CRITICAL

Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due …

Jun 16, 2025
CVE-2025-6137
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP …

Jun 16, 2025
CVE-2025-6136
6.3 MEDIUM

A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 16, 2025
CVE-2025-32798
9.8 CRITICAL

Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe processing logic has been found to be vulnerable to …

Jun 16, 2025
CVE-2025-6135
6.3 MEDIUM

A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 16, 2025
CVE-2025-6134
6.3 MEDIUM

A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jun 16, 2025
CVE-2025-6087
9.1 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open …

Jun 16, 2025
CVE-2025-32797
7.0 HIGH

Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_build.sh with …

Jun 16, 2025
CVE-2025-6133
6.3 MEDIUM

A vulnerability was found in Projectworlds Life Insurance Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jun 16, 2025
CVE-2025-6132
7.3 HIGH

A vulnerability has been found in Chanjet CRM 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /sysconfig/departmentsetting.php. …

Jun 16, 2025
CVE-2025-6179
9.8 CRITICAL

Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including …

Jun 16, 2025
CVE-2025-6177
7.4 HIGH

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting …

Jun 16, 2025
CVE-2025-6131
2.4 LOW

A vulnerability, which was classified as problematic, was found in CodeAstro Food Ordering System 1.0. Affected is an unknown function of the file /admin/store/edit/ of …

Jun 16, 2025
CVE-2025-6130
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formStats of …

Jun 16, 2025
CVE-2025-5309
9.8 CRITICAL

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote …

Jun 16, 2025
CVE-2025-2327

A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.

Jun 16, 2025
CVE-2025-6170
2.5 LOW

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long …

Jun 16, 2025
CVE-2025-6129
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formSaveConfig of the component HTTP POST …

Jun 16, 2025
CVE-2025-6128
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWirelessTbl of the component HTTP …

Jun 16, 2025
CVE-2025-49796
9.1 CRITICAL

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an …

Jun 16, 2025
CVE-2025-49795
7.5 HIGH

A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input …

Jun 16, 2025
CVE-2025-49794
9.1 CRITICAL

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> …

Jun 16, 2025
CVE-2025-6127
3.5 LOW

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown …

Jun 16, 2025
CVE-2025-6126
4.3 MEDIUM

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Jun 16, 2025
CVE-2025-4565
5.3 MEDIUM

Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series …

Jun 16, 2025
CVE-2025-49125
7.5 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the …

Jun 16, 2025
CVE-2025-49124
8.4 HIGH

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This …

Jun 16, 2025
CVE-2025-48988
7.5 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from …

Jun 16, 2025
CVE-2025-48976
7.5 HIGH

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 …

Jun 16, 2025
CVE-2025-3594
9.8 CRITICAL

Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update …

Jun 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.