CVE Database

116755+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6096
6.3 MEDIUM

A vulnerability has been found in codesiddhant Jasmin Ransomware up to 1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jun 16, 2025
CVE-2025-6095
7.3 HIGH

A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unknown function of the file /checklogin.php. The manipulation …

Jun 15, 2025
CVE-2025-6094
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file …

Jun 15, 2025
CVE-2025-6093
5.5 MEDIUM

A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a275d1007e295. This vulnerability affects the function heartrate1_i2c_hal_write of the file 7.Example/hal/i2c/max30100/Manual/demo2/2/heartrate1_hal.c. The manipulation …

Jun 15, 2025
CVE-2025-5964
6.5 MEDIUM

A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.

Jun 15, 2025
CVE-2025-6092
4.3 MEDIUM

A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jun 15, 2025
CVE-2025-5990
7.6 HIGH

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored …

Jun 15, 2025
CVE-2025-6091
8.8 HIGH

A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation …

Jun 15, 2025
CVE-2024-25573

Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.

Jun 15, 2025
CVE-2025-6090
8.8 HIGH

A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function UpdateWanparamsMulti/UpdateIpv6params of the file /routing/goform/aspForm. The manipulation of …

Jun 15, 2025
CVE-2025-22854

Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.

Jun 15, 2025
CVE-2025-21085

PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.

Jun 15, 2025
CVE-2025-6089
4.3 MEDIUM

A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the file atCheckJS.aspx. The …

Jun 15, 2025
CVE-2025-36041
4.7 MEDIUM

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator …

Jun 15, 2025
CVE-2025-1411
7.8 HIGH

IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges.

Jun 15, 2025
CVE-2025-5337
6.4 MEDIUM

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, …

Jun 14, 2025
CVE-2025-5238
6.4 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.5.0 …

Jun 14, 2025
CVE-2025-4667
6.4 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and …

Jun 14, 2025
CVE-2025-6070
6.5 MEDIUM

The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This …

Jun 14, 2025
CVE-2025-6065
9.1 CRITICAL

The Image Resizer On The Fly plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' task …

Jun 14, 2025
CVE-2025-6064
6.1 MEDIUM

The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to …

Jun 14, 2025
CVE-2025-6063
6.1 MEDIUM

The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing …

Jun 14, 2025
CVE-2025-6062
4.3 MEDIUM

The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due …

Jun 14, 2025
CVE-2025-6061
6.4 MEDIUM

The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcode in all versions up to, and including, …

Jun 14, 2025
CVE-2025-6055
6.1 MEDIUM

The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to …

Jun 14, 2025
CVE-2025-6040
6.1 MEDIUM

The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing …

Jun 14, 2025
CVE-2025-5589
6.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 …

Jun 14, 2025
CVE-2025-5336
6.4 MEDIUM

The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 …

Jun 14, 2025
CVE-2025-4592
4.3 MEDIUM

The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 14, 2025
CVE-2025-4216
6.4 MEDIUM

The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and …

Jun 14, 2025
CVE-2025-4200
8.1 HIGH

The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Jun 14, 2025
CVE-2025-4187
5.9 MEDIUM

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 …

Jun 14, 2025
CVE-2025-5487
7.2 HIGH

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the …

Jun 14, 2025
CVE-2025-3234
7.2 HIGH

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up …

Jun 14, 2025
CVE-2025-6059
4.3 MEDIUM

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing …

Jun 14, 2025
CVE-2025-50150

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50149

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50148

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50147

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50146

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50145

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50144

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50143

Rejected reason: Not used

Jun 14, 2025
CVE-2025-50142

Rejected reason: Not used

Jun 14, 2025
CVE-2025-33108
8.5 HIGH

IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to …

Jun 14, 2025
CVE-2025-25215
8.8 HIGH

An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted …

Jun 13, 2025
CVE-2025-24919
8.1 HIGH

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially …

Jun 13, 2025
CVE-2025-6083
4.3 MEDIUM

In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search …

Jun 13, 2025
CVE-2025-49598

conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feedstock setup script is vulnerable due to the unsafe …

Jun 13, 2025
CVE-2025-25050
8.8 HIGH

An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially …

Jun 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.