CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48951

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie …

Jun 3, 2025
CVE-2025-5525
5.6 MEDIUM

A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file …

Jun 3, 2025
CVE-2025-5523
3.5 LOW

A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File …

Jun 3, 2025
CVE-2025-35036
7.3 HIGH

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression …

Jun 3, 2025
CVE-2025-23100
7.5 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of …

Jun 3, 2025
CVE-2025-23098
7.8 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege …

Jun 3, 2025
CVE-2025-23097
9.1 CRITICAL

An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.

Jun 3, 2025
CVE-2025-5522
7.3 HIGH

A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown …

Jun 3, 2025
CVE-2025-5521
4.3 MEDIUM

A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Jun 3, 2025
CVE-2025-48998
8.8 HIGH

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users …

Jun 3, 2025
CVE-2025-48997

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1.4.4-lts.1 and prior to version 2.0.1 allows an attacker …

Jun 3, 2025
CVE-2025-48953
5.5 MEDIUM

Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a file …

Jun 3, 2025
CVE-2025-48950
8.8 HIGH

MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such …

Jun 3, 2025
CVE-2025-23102
8.8 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Double Free in the mobile …

Jun 3, 2025
CVE-2025-5520
5.3 MEDIUM

A vulnerability was found in Open5GS up to 2.7.3. It has been classified as problematic. Affected is the function gmm_state_authentication/emm_state_authentication of the component AMF/MME. The …

Jun 3, 2025
CVE-2025-5516
2.4 LOW

A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an unknown part of the file /boafrm/formFilter of the component …

Jun 3, 2025
CVE-2025-5515
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK X2000R 1.0.0-B20230726.1108. Affected by this issue is some unknown functionality of the file …

Jun 3, 2025
CVE-2025-5513
3.5 LOW

A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jun 3, 2025
CVE-2025-30360
6.5 MEDIUM

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen …

Jun 3, 2025
CVE-2025-30359
5.3 MEDIUM

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen …

Jun 3, 2025
CVE-2025-5512
7.3 HIGH

A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/sys/user/verifyPassword/ of …

Jun 3, 2025
CVE-2025-5511
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file …

Jun 3, 2025
CVE-2025-5510
6.3 MEDIUM

A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknown code of the file /app/sys/article/optimize. The manipulation of …

Jun 3, 2025
CVE-2025-32106
9.8 CRITICAL

In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.

Jun 3, 2025
CVE-2025-32105
9.8 CRITICAL

A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.

Jun 3, 2025
CVE-2025-30167
7.3 HIGH

Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared …

Jun 3, 2025
CVE-2025-23107
8.6 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

Jun 3, 2025
CVE-2025-5509
6.3 MEDIUM

A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload. The manipulation …

Jun 3, 2025
CVE-2025-5508
2.4 LOW

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component …

Jun 3, 2025
CVE-2025-5507
2.4 LOW

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component …

Jun 3, 2025
CVE-2025-45854
10.0 CRITICAL

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

Jun 3, 2025
CVE-2025-44148
9.8 CRITICAL

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

Jun 3, 2025
CVE-2025-25022
9.6 CRITICAL

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to …

Jun 3, 2025
CVE-2025-25021
7.2 HIGH

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management …

Jun 3, 2025
CVE-2025-25020
6.5 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial …

Jun 3, 2025
CVE-2025-25019
4.8 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could …

Jun 3, 2025
CVE-2025-23103
8.6 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

Jun 3, 2025
CVE-2025-1334
4.0 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can …

Jun 3, 2025
CVE-2025-5506
2.4 LOW

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as problematic. Affected is an unknown function of the component NAT Mapping Page. …

Jun 3, 2025
CVE-2025-5505
2.4 LOW

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component …

Jun 3, 2025
CVE-2025-5504
6.3 MEDIUM

A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWsc. The manipulation of …

Jun 3, 2025
CVE-2025-5503
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of …

Jun 3, 2025
CVE-2025-46548
6.5 MEDIUM

If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead …

Jun 3, 2025
CVE-2025-43925
4.6 MEDIUM

An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the cleartext data.

Jun 3, 2025
CVE-2025-43924
6.1 MEDIUM

Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in FriendsController (for …

Jun 3, 2025
CVE-2025-43923
6.5 MEDIUM

An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via …

Jun 3, 2025
CVE-2025-36564
7.8 HIGH

Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, leading to …

Jun 3, 2025
CVE-2024-45655
5.5 MEDIUM

IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment.

Jun 3, 2025
CVE-2025-5502
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this issue is the function formMapReboot of the file …

Jun 3, 2025
CVE-2025-5501
5.3 MEDIUM

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_request_transfer of the file src/smf/ngap-handler.c of …

Jun 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.