CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5836
6.3 MEDIUM

A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of …

Jun 7, 2025
CVE-2025-49619
8.5 HIGH

Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization …

Jun 7, 2025
CVE-2025-5568
6.4 MEDIUM

The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient …

Jun 7, 2025
CVE-2025-5528
6.1 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up …

Jun 7, 2025
CVE-2024-9994
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2025
CVE-2024-9993
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2025
CVE-2025-5303
7.2 HIGH

The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress …

Jun 7, 2025
CVE-2025-5399
7.5 HIGH

Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless …

Jun 7, 2025
CVE-2025-5814
5.3 MEDIUM

The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 7, 2025
CVE-2025-47601
8.8 HIGH

Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <= 2.1.0.

Jun 7, 2025
CVE-2025-49128
4.0 MEDIUM

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a …

Jun 6, 2025
CVE-2025-49127

Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute …

Jun 6, 2025
CVE-2025-5799
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.09. It has been declared as critical. Affected by this vulnerability is the function fromSetWirelessRepeat of the file …

Jun 6, 2025
CVE-2025-5798
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.09. It has been classified as critical. Affected is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation …

Jun 6, 2025
CVE-2025-5797
3.5 LOW

A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unknown processing of the file /data/insert_type.php. The manipulation …

Jun 6, 2025
CVE-2025-5796
3.5 LOW

A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /data/edit_type.php. The manipulation …

Jun 6, 2025
CVE-2025-5795
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC5 1.0/15.03.06.47. This affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of …

Jun 6, 2025
CVE-2025-5794
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC5 15.03.06.47. Affected by this issue is the function formSetPPTPUserList of the file …

Jun 6, 2025
CVE-2025-5481
7.8 HIGH

Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Jun 6, 2025
CVE-2025-5480
7.8 HIGH

Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Action1. An attacker must …

Jun 6, 2025
CVE-2025-5474
7.3 HIGH

2BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of 2BrightSparks SyncBackFree. An attacker must …

Jun 6, 2025
CVE-2025-5473
8.8 HIGH

GIMP ICO File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User …

Jun 6, 2025
CVE-2025-3485
8.8 HIGH

Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required …

Jun 6, 2025
CVE-2025-2766
8.8 HIGH

70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510. Authentication is …

Jun 6, 2025
CVE-2025-5793
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formPortFw of the component …

Jun 6, 2025
CVE-2025-5792
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formWlanRedirect of …

Jun 6, 2025
CVE-2025-5790
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. This vulnerability affects unknown code of the file /boafrm/formIpQoS of the component HTTP POST …

Jun 6, 2025
CVE-2025-5789
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP …

Jun 6, 2025
CVE-2025-49011
3.7 LOW

SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the …

Jun 6, 2025
CVE-2025-47950
7.5 HIGH

CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) …

Jun 6, 2025
CVE-2025-5788
8.8 HIGH

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Jun 6, 2025
CVE-2025-5787
8.8 HIGH

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jun 6, 2025
CVE-2025-5786
8.8 HIGH

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formDMZ of the …

Jun 6, 2025
CVE-2025-49599
4.1 MEDIUM

Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V5R021C00S184 allow the Epuser account to disable ONT firewall functionality, e.g., to …

Jun 6, 2025
CVE-2025-5785
8.8 HIGH

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component …

Jun 6, 2025
CVE-2025-5784
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the file /myexp.php. …

Jun 6, 2025
CVE-2025-5783
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Employee Record Management System 1.3. This affects an unknown part of the file /editmyexp.php. …

Jun 6, 2025
CVE-2025-5751
6.8 MEDIUM

WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of …

Jun 6, 2025
CVE-2025-5750
8.8 HIGH

WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations …

Jun 6, 2025
CVE-2025-5749
8.8 HIGH

WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of …

Jun 6, 2025
CVE-2025-5748
8.0 HIGH

WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected …

Jun 6, 2025
CVE-2025-5747
8.0 HIGH

WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on …

Jun 6, 2025
CVE-2025-33035
6.5 MEDIUM

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the …

Jun 6, 2025
CVE-2025-33031
8.8 HIGH

An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Jun 6, 2025
CVE-2025-30279
8.8 HIGH

An improper certificate validation vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Jun 6, 2025
CVE-2025-29892
8.8 HIGH

An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to …

Jun 6, 2025
CVE-2025-29885
8.8 HIGH

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user …

Jun 6, 2025
CVE-2025-29884
8.8 HIGH

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user …

Jun 6, 2025
CVE-2025-29883
8.8 HIGH

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user …

Jun 6, 2025
CVE-2025-29877
7.5 HIGH

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Jun 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.