CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5912
8.8 HIGH

A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the function do_file of the component HTTP POST …

Jun 10, 2025
CVE-2025-4601
8.8 HIGH

The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is …

Jun 10, 2025
CVE-2025-4387
8.8 HIGH

The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add_to_cart_popup_upload_files function in …

Jun 10, 2025
CVE-2025-5911
8.8 HIGH

A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 10, 2025
CVE-2025-5910
8.8 HIGH

A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 10, 2025
CVE-2024-55595

Rejected reason: Not used

Jun 10, 2025
CVE-2025-5909
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formReflashClientTbl of …

Jun 10, 2025
CVE-2025-5908
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file …

Jun 10, 2025
CVE-2025-5907
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formFilter of the component …

Jun 10, 2025
CVE-2025-5906
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manipulation leads …

Jun 10, 2025
CVE-2025-42998
5.3 MEDIUM

The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted …

Jun 10, 2025
CVE-2025-42996
5.6 MEDIUM

SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to …

Jun 10, 2025
CVE-2025-42995
7.5 HIGH

SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process …

Jun 10, 2025
CVE-2025-42994
7.5 HIGH

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process …

Jun 10, 2025
CVE-2025-42993
6.7 MEDIUM

Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an …

Jun 10, 2025
CVE-2025-42991
4.3 MEDIUM

SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'approver' user to delete attachment from bank account application of …

Jun 10, 2025
CVE-2025-42990
3.0 LOW

Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the …

Jun 10, 2025
CVE-2025-42989
9.6 CRITICAL

RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact …

Jun 10, 2025
CVE-2025-42988
3.7 LOW

Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP …

Jun 10, 2025
CVE-2025-42987
4.3 MEDIUM

SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. …

Jun 10, 2025
CVE-2025-42984
5.4 MEDIUM

SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function …

Jun 10, 2025
CVE-2025-42983
8.5 HIGH

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or …

Jun 10, 2025
CVE-2025-42982
8.8 HIGH

SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes …

Jun 10, 2025
CVE-2025-42977
7.6 HIGH

SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker …

Jun 10, 2025
CVE-2025-31325
5.8 MEDIUM

Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an …

Jun 10, 2025
CVE-2025-23192
8.2 HIGH

SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, …

Jun 10, 2025
CVE-2025-5905
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file …

Jun 10, 2025
CVE-2025-5904
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file …

Jun 10, 2025
CVE-2025-5903
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the …

Jun 10, 2025
CVE-2025-0037
6.6 MEDIUM

In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated …

Jun 10, 2025
CVE-2025-0036
3.2 LOW

In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to …

Jun 10, 2025
CVE-2025-5902
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component …

Jun 9, 2025
CVE-2025-5901
8.8 HIGH

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the …

Jun 9, 2025
CVE-2025-30515
9.8 CRITICAL

CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.

Jun 9, 2025
CVE-2025-30507
5.3 MEDIUM

CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.

Jun 9, 2025
CVE-2025-30183
7.5 HIGH

CyberData 011209 Intercom does not properly store or protect web server admin credentials.

Jun 9, 2025
CVE-2025-26468
7.5 HIGH

CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.

Jun 9, 2025
CVE-2025-5900
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. …

Jun 9, 2025
CVE-2025-5899
5.3 MEDIUM

A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation …

Jun 9, 2025
CVE-2025-5898
5.3 MEDIUM

A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to …

Jun 9, 2025
CVE-2025-49140
7.5 HIGH

Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a bug in a RTP packet factory that can be …

Jun 9, 2025
CVE-2025-30184
9.8 CRITICAL

CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.

Jun 9, 2025
CVE-2025-5897
4.3 MEDIUM

A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file …

Jun 9, 2025
CVE-2025-5896
4.3 MEDIUM

A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. …

Jun 9, 2025
CVE-2025-49141
8.5 HIGH

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string …

Jun 9, 2025
CVE-2025-49139
5.3 MEDIUM

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can …

Jun 9, 2025
CVE-2025-49138
6.5 MEDIUM

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability …

Jun 9, 2025
CVE-2025-49137
8.5 HIGH

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user …

Jun 9, 2025
CVE-2025-49004
7.5 HIGH

Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caido can be loaded on …

Jun 9, 2025
CVE-2025-5918
3.9 LOW

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading …

Jun 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.