CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-25999
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme BodyCenter - Gym, Fitness WooCommerce WordPress Theme allows …

Jun 9, 2025
CVE-2025-5885
4.3 MEDIUM

A vulnerability has been found in Konica Minolta bizhub up to 20250202 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to …

Jun 9, 2025
CVE-2025-5884
3.5 LOW

A vulnerability, which was classified as problematic, was found in Konica Minolta bizhub up to 20250202. This affects an unknown part of the component Display …

Jun 9, 2025
CVE-2025-5881
6.3 MEDIUM

A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. …

Jun 9, 2025
CVE-2025-5880
4.3 MEDIUM

A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the …

Jun 9, 2025
CVE-2025-5879
3.5 LOW

A vulnerability, which was classified as problematic, was found in WuKongOpenSource WukongCRM 9.0. This affects an unknown part of the file AdminSysConfigController.java of the component …

Jun 9, 2025
CVE-2025-5877
6.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the …

Jun 9, 2025
CVE-2025-49131
6.3 MEDIUM

FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-sandbox) is a …

Jun 9, 2025
CVE-2025-49130

Laravel Translation Manager is a package to manage Laravel translation files. Prior to version 0.6.8, the application is vulnerable to Cross-Site Scripting (XSS) attacks due …

Jun 9, 2025
CVE-2025-49013
9.9 CRITICAL

WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage …

Jun 9, 2025
CVE-2025-49006

Wasp (Web Application Specification) is a Rails-like framework for React, Node.js, and Prisma. Prior to version 0.16.6, Wasp authentication has a vulnerability in the OAuth …

Jun 9, 2025
CVE-2025-48877
9.8 CRITICAL

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the …

Jun 9, 2025
CVE-2025-48062
7.1 HIGH

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the …

Jun 9, 2025
CVE-2025-48053
7.5 HIGH

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the …

Jun 9, 2025
CVE-2025-40670
8.8 HIGH

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a …

Jun 9, 2025
CVE-2025-40669
6.5 MEDIUM

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including …

Jun 9, 2025
CVE-2025-40668
6.5 MEDIUM

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a …

Jun 9, 2025
CVE-2025-5876
5.3 MEDIUM

A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability is an unknown functionality. The …

Jun 9, 2025
CVE-2025-5875
8.8 HIGH

A vulnerability classified as critical has been found in TP-LINK Technologies TL-IPC544EP-W4 1.0.9 Build 240428 Rel 69493n. Affected is the function sub_69064 of the file …

Jun 9, 2025
CVE-2025-41444
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.

Jun 9, 2025
CVE-2025-5874
4.6 MEDIUM

A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as problematic. This issue affects the function run_query of the file /query_runner/python.py …

Jun 9, 2025
CVE-2025-5873
6.3 MEDIUM

A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmware.php …

Jun 9, 2025
CVE-2025-41437
4.3 MEDIUM

Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.

Jun 9, 2025
CVE-2025-3835
9.6 CRITICAL

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

Jun 9, 2025
CVE-2025-36528
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.

Jun 9, 2025
CVE-2025-27709
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.

Jun 9, 2025
CVE-2025-5872
5.3 MEDIUM

A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting …

Jun 9, 2025
CVE-2025-5871
5.3 MEDIUM

A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality of the component …

Jun 9, 2025
CVE-2025-40675
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser …

Jun 9, 2025
CVE-2025-5870
7.3 HIGH

A vulnerability has been found in TRENDnet TV-IP121W 1.1.1 Build 36 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 9, 2025
CVE-2025-5869
8.0 HIGH

A vulnerability, which was classified as critical, was found in RT-Thread 5.1.0. Affected is the function sys_recvfrom of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the …

Jun 9, 2025
CVE-2025-5894
8.8 HIGH

Smart Parking Management System from Honding Technology has a Missing Authorization vulnerability, allowing remote attackers with regular privileges to access a specific functionality to create …

Jun 9, 2025
CVE-2025-5868
8.0 HIGH

A vulnerability, which was classified as critical, has been found in RT-Thread 5.1.0. This issue affects the function sys_thread_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation …

Jun 9, 2025
CVE-2025-5867
8.0 HIGH

A vulnerability classified as critical was found in RT-Thread 5.1.0. This vulnerability affects the function csys_sendto of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument …

Jun 9, 2025
CVE-2025-5893
9.8 CRITICAL

Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access a specific page and obtain …

Jun 9, 2025
CVE-2025-5866
8.0 HIGH

A vulnerability classified as critical has been found in RT-Thread 5.1.0. This affects the function sys_sigprocmask of the file rt-thread/components/lwp/lwp_syscall.c. The manipulation of the argument …

Jun 9, 2025
CVE-2025-5865
8.0 HIGH

A vulnerability was found in RT-Thread 5.1.0. It has been rated as critical. Affected by this issue is the function sys_select of the file rt-thread/components/lwp/lwp_syscall.c …

Jun 9, 2025
CVE-2025-5864
3.7 LOW

A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Jun 9, 2025
CVE-2025-5863
8.8 HIGH

A vulnerability was found in Tenda AC5 15.03.06.47. It has been classified as critical. Affected is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation …

Jun 9, 2025
CVE-2025-4652
6.1 MEDIUM

The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jun 9, 2025
CVE-2025-47712
6.5 MEDIUM

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status …

Jun 9, 2025
CVE-2025-47711
6.5 MEDIUM

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific …

Jun 9, 2025
CVE-2025-3582
4.8 MEDIUM

The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin …

Jun 9, 2025
CVE-2025-3581
4.8 MEDIUM

The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the …

Jun 9, 2025
CVE-2025-25209
5.7 MEDIUM

The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead …

Jun 9, 2025
CVE-2025-25208
5.7 MEDIUM

A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster

Jun 9, 2025
CVE-2025-25207
5.7 MEDIUM

The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona …

Jun 9, 2025
CVE-2025-5862
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of …

Jun 9, 2025
CVE-2025-5861
8.8 HIGH

A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation …

Jun 9, 2025
CVE-2025-5860
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Maid Hiring Management System 1.0. This affects an unknown part of the file /admin/search-booking-request.php. …

Jun 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.