CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-32711
9.3 CRITICAL

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Jun 11, 2025
CVE-2025-5144
6.4 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 …

Jun 11, 2025
CVE-2025-5986
6.5 MEDIUM

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even …

Jun 11, 2025
CVE-2025-5687
7.8 HIGH

A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other …

Jun 11, 2025
CVE-2025-49710
9.8 CRITICAL

An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.

Jun 11, 2025
CVE-2025-49709
9.8 CRITICAL

Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.

Jun 11, 2025
CVE-2025-3302
7.2 HIGH

The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, …

Jun 11, 2025
CVE-2025-4573
4.1 MEDIUM

Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated …

Jun 11, 2025
CVE-2025-4128
3.1 LOW

Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view …

Jun 11, 2025
CVE-2025-4315
8.8 HIGH

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is …

Jun 11, 2025
CVE-2025-41663
9.8 CRITICAL

For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers, which are then …

Jun 11, 2025
CVE-2025-41662

Rejected reason: CVE-2025-41662 is considered redundant or unnecessary and thus should be withdrawn. Instead, a new CVE CVE-2025-41687 has been reserved to better reflect the …

Jun 11, 2025
CVE-2025-41661
8.8 HIGH

An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection.

Jun 11, 2025
CVE-2025-26412
6.8 MEDIUM

The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker …

Jun 11, 2025
CVE-2025-5991

There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by …

Jun 11, 2025
CVE-2025-29756

SunGrow's back end users system iSolarCloud https://isolarcloud.com uses an MQTT service to transport data from the user's connected devices to the user's web browser. The …

Jun 11, 2025
CVE-2025-5395
8.8 HIGH

The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php' file in all …

Jun 11, 2025
CVE-2024-35295
6.1 MEDIUM

A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 to April 2025). …

Jun 11, 2025
CVE-2025-4799
7.2 HIGH

The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from …

Jun 11, 2025
CVE-2025-4798
4.9 MEDIUM

The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack …

Jun 11, 2025
CVE-2025-4666
6.4 MEDIUM

The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versions up to, and including, 7.3.15 due to …

Jun 11, 2025
CVE-2025-49793

Rejected reason: Not used

Jun 11, 2025
CVE-2025-49792

Rejected reason: Not used

Jun 11, 2025
CVE-2025-49791

Rejected reason: Not used

Jun 11, 2025
CVE-2025-49790

Rejected reason: Not used

Jun 11, 2025
CVE-2025-49789

Rejected reason: Not used

Jun 11, 2025
CVE-2025-49788

Rejected reason: Not used

Jun 11, 2025
CVE-2025-49787

Rejected reason: Not used

Jun 11, 2025
CVE-2025-49786

Rejected reason: Not used

Jun 11, 2025
CVE-2025-49785

Rejected reason: Not used

Jun 11, 2025
CVE-2024-1244

Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control over the OSSEC server or …

Jun 11, 2025
CVE-2024-1243
7.2 HIGH

Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key …

Jun 11, 2025
CVE-2025-5959
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Jun 11, 2025
CVE-2025-5958
8.8 HIGH

Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2025
CVE-2025-4275
7.8 HIGH

A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a …

Jun 11, 2025
CVE-2025-49091
8.2 HIGH

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or …

Jun 11, 2025
CVE-2025-32717
8.4 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jun 11, 2025
CVE-2025-30675
4.7 MEDIUM

In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue …

Jun 11, 2025
CVE-2025-1055
5.6 MEDIUM

A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate …

Jun 11, 2025
CVE-2024-9062
7.8 HIGH

The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is exposed via XPC. …

Jun 11, 2025
CVE-2024-8270
5.5 MEDIUM

The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling the exploitation or abuse of permissions …

Jun 11, 2025
CVE-2024-7457
7.8 HIGH

The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the client's authorization reference, the helper invokes …

Jun 11, 2025
CVE-2025-5985
7.3 HIGH

A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation …

Jun 10, 2025
CVE-2025-5984
3.5 LOW

A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jun 10, 2025
CVE-2025-47849
8.8 HIGH

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the …

Jun 10, 2025
CVE-2025-47713
8.8 HIGH

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the …

Jun 10, 2025
CVE-2025-47117
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Jun 10, 2025
CVE-2025-47116
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Jun 10, 2025
CVE-2025-47115
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Jun 10, 2025
CVE-2025-47114
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Jun 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.