CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5657
6.3 MEDIUM

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 5, 2025
CVE-2025-5656
6.3 MEDIUM

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-category.php. …

Jun 5, 2025
CVE-2025-5341
6.4 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id' and …

Jun 5, 2025
CVE-2011-10007
8.8 HIGH

File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opened with the 2 …

Jun 5, 2025
CVE-2025-5655
6.3 MEDIUM

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. …

Jun 5, 2025
CVE-2025-5654
6.3 MEDIUM

A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 5, 2025
CVE-2025-5653
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 5, 2025
CVE-2025-5652
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/between-date-complaintreport.php. The …

Jun 5, 2025
CVE-2025-5651
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Traffic Offense Reporting System 1.0. This issue affects some unknown processing of the …

Jun 5, 2025
CVE-2025-5650
7.3 HIGH

A vulnerability classified as critical was found in 1000projects Online Notice Board 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of …

Jun 5, 2025
CVE-2025-4568

Improper neutralization of input provided by an unauthorized user into changes__reference_id parameter in URL allows for boolean-based Blind SQL Injection attacks.

Jun 5, 2025
CVE-2025-5649
5.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of …

Jun 5, 2025
CVE-2025-5648
2.5 LOW

A vulnerability was found in Radare2 5.9.9. It has been classified as problematic. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component …

Jun 5, 2025
CVE-2025-5647
2.5 LOW

A vulnerability was found in Radare2 5.9.9 and classified as problematic. This issue affects the function r_cons_context_break_pop in the library /libr/cons/cons.c of the component radiff2. …

Jun 5, 2025
CVE-2025-5646
2.5 LOW

A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r_cons_rainbow_free in the library /libr/cons/pal.c of the component …

Jun 5, 2025
CVE-2025-5645
2.5 LOW

A vulnerability, which was classified as problematic, was found in Radare2 5.9.9. This affects the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. …

Jun 5, 2025
CVE-2025-5644
2.5 LOW

A vulnerability, which was classified as problematic, has been found in Radare2 5.9.9. Affected by this issue is the function r_cons_flush in the library /libr/cons/cons.c …

Jun 5, 2025
CVE-2025-5643
2.5 LOW

A vulnerability classified as problematic was found in Radare2 5.9.9. Affected by this vulnerability is the function cons_stack_load in the library /libr/cons/cons.c of the component …

Jun 5, 2025
CVE-2025-5642
2.5 LOW

A vulnerability classified as problematic has been found in Radare2 5.9.9. Affected is the function r_cons_pal_init in the library /libr/cons/pal.c of the component radiff2. The …

Jun 5, 2025
CVE-2025-5641
2.5 LOW

A vulnerability was found in Radare2 5.9.9. It has been rated as problematic. This issue affects the function r_cons_is_breaked in the library /libr/cons/cons.c of the …

Jun 5, 2025
CVE-2025-5683
5.5 MEDIUM

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt from versions 6.3.0 through …

Jun 5, 2025
CVE-2025-5640
3.3 LOW

A vulnerability was found in PX4-Autopilot 1.12.3. It has been classified as problematic. This affects the function MavlinkReceiver::handle_message_trajectory_representation_waypoints of the file mavlink_receiver.cpp of the component …

Jun 5, 2025
CVE-2025-5639
7.3 HIGH

A vulnerability was found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 5, 2025
CVE-2025-3055
8.1 HIGH

The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in …

Jun 5, 2025
CVE-2025-3054
8.8 HIGH

The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in …

Jun 5, 2025
CVE-2025-5638
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 5, 2025
CVE-2025-5637
7.3 HIGH

A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component SYSTEM Command Handler. …

Jun 5, 2025
CVE-2025-5636
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SET …

Jun 5, 2025
CVE-2025-1793
9.8 CRITICAL

Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially …

Jun 5, 2025
CVE-2025-5635
7.3 HIGH

A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation …

Jun 5, 2025
CVE-2025-5634
7.3 HIGH

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component NOOP Command Handler. The …

Jun 5, 2025
CVE-2025-5633
6.3 MEDIUM

A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is some unknown …

Jun 5, 2025
CVE-2025-5632
6.3 MEDIUM

A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Jun 5, 2025
CVE-2025-5631
7.3 HIGH

A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been classified as critical. Affected is an unknown function of the …

Jun 5, 2025
CVE-2025-5630
9.8 CRITICAL

A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of …

Jun 5, 2025
CVE-2025-5629
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC10 up to 15.03.06.47. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg of …

Jun 5, 2025
CVE-2025-49466
5.8 MEDIUM

aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,

Jun 5, 2025
CVE-2025-48432
4.0 MEDIUM

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which …

Jun 5, 2025
CVE-2025-5628
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Food Menu Manager 1.0. Affected by this issue is some unknown functionality of …

Jun 5, 2025
CVE-2025-5627
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 5, 2025
CVE-2025-5626
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected is an unknown function of the file /admin/edit-subjects-detail.php. …

Jun 5, 2025
CVE-2025-5625
7.3 HIGH

A vulnerability was found in Campcodes Online Teacher Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

Jun 5, 2025
CVE-2025-5624
9.8 CRITICAL

A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The …

Jun 5, 2025
CVE-2025-49008

Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows argument injection, leading to arbitrary …

Jun 5, 2025
CVE-2025-5623
9.8 CRITICAL

A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation …

Jun 5, 2025
CVE-2025-5622
9.8 CRITICAL

A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The …

Jun 5, 2025
CVE-2025-5621
7.3 HIGH

A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. …

Jun 5, 2025
CVE-2025-5620
7.3 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of …

Jun 5, 2025
CVE-2025-5619
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. This issue affects the function formaddUserName of the file /goform/addUserName. The …

Jun 4, 2025
CVE-2025-5618
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. This vulnerability affects unknown code of the file /admin/edit-team.php. The manipulation …

Jun 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.