CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5499
7.3 HIGH

A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the file image_resized.php. The manipulation …

Jun 3, 2025
CVE-2025-5498
5.5 MEDIUM

A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/is_file of the file …

Jun 3, 2025
CVE-2025-46154
8.4 HIGH

Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

Jun 3, 2025
CVE-2025-45855
5.4 MEDIUM

An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.

Jun 3, 2025
CVE-2025-5497
6.3 MEDIUM

A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_feedimport/inc/processing.inc.php of the component Feedimport …

Jun 3, 2025
CVE-2025-5495
7.3 HIGH

A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknown part of the component URL Handler. The …

Jun 3, 2025
CVE-2025-4517
9.4 CRITICAL

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract …

Jun 3, 2025
CVE-2025-4435
7.5 HIGH

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. …

Jun 3, 2025
CVE-2025-4330
7.5 HIGH

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are …

Jun 3, 2025
CVE-2025-4138
7.5 HIGH

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are …

Jun 3, 2025
CVE-2024-12718
5.3 MEDIUM

Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected …

Jun 3, 2025
CVE-2025-5340
6.4 MEDIUM

The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’ parameter in all versions up to, and including, …

Jun 3, 2025
CVE-2025-4671
6.4 MEDIUM

The Profile Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's user_meta and compare shortcodes in all versions up to, and …

Jun 3, 2025
CVE-2025-4205
6.4 MEDIUM

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all versions up to, and including, 1.20.4 due …

Jun 3, 2025
CVE-2025-5493
6.3 MEDIUM

A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 3, 2025
CVE-2025-5492
6.3 MEDIUM

A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnerability is the function sub_456DE8 of the …

Jun 3, 2025
CVE-2025-4392
7.2 HIGH

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads …

Jun 3, 2025
CVE-2025-31359
8.8 HIGH

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vulnerability can be exploited by …

Jun 3, 2025
CVE-2024-54189
7.8 HIGH

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine …

Jun 3, 2025
CVE-2024-52561
7.8 HIGH

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine …

Jun 3, 2025
CVE-2024-36486
7.8 HIGH

A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual machine …

Jun 3, 2025
CVE-2025-5116
6.4 MEDIUM

The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerid’ parameter in all versions up to, and including, …

Jun 3, 2025
CVE-2025-5103
4.9 MEDIUM

The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'default_price' and 'product_id' parameters in all versions up …

Jun 3, 2025
CVE-2025-4420
6.4 MEDIUM

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all …

Jun 3, 2025
CVE-2025-1725
6.4 MEDIUM

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site …

Jun 3, 2025
CVE-2025-46355
7.3 HIGH

Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where …

Jun 3, 2025
CVE-2025-41428
5.3 MEDIUM

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the …

Jun 3, 2025
CVE-2025-21479
8.6 HIGH KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Jun 3, 2025
CVE-2025-4567
4.8 MEDIUM

The Post Slider and Post Carousel with Post Vertical Scrolling Widget WordPress plugin before 3.2.10 does not validate and escape some of its Widget options …

Jun 3, 2025
CVE-2025-3662
6.1 MEDIUM

The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was …

Jun 3, 2025
CVE-2025-3584
4.8 MEDIUM

The Newsletter WordPress plugin before 8.8.2 does not sanitise and escape some of its Subscription settings, which could allow high privilege users such as admin …

Jun 3, 2025
CVE-2025-31712
5.1 MEDIUM

In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jun 3, 2025
CVE-2025-31711
5.1 MEDIUM

In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional …

Jun 3, 2025
CVE-2025-31710
5.9 MEDIUM

In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional …

Jun 3, 2025
CVE-2025-27038
7.5 HIGH KEV

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

Jun 3, 2025
CVE-2025-27031
7.8 HIGH

memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.

Jun 3, 2025
CVE-2025-27029
7.5 HIGH

Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.

Jun 3, 2025
CVE-2025-21486
7.8 HIGH

Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.

Jun 3, 2025
CVE-2025-21485
7.8 HIGH

Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.

Jun 3, 2025
CVE-2025-21480
8.6 HIGH KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Jun 3, 2025
CVE-2025-21463
7.5 HIGH

Transient DOS while processing the EHT operation IE in the received beacon frame.

Jun 3, 2025
CVE-2024-53026
8.2 HIGH

Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.

Jun 3, 2025
CVE-2024-53021
8.2 HIGH

Information disclosure may occur while processing goodbye RTCP packet from network.

Jun 3, 2025
CVE-2024-53020
8.2 HIGH

Information disclosure may occur while decoding the RTP packet with invalid header extension from network.

Jun 3, 2025
CVE-2024-53019
8.2 HIGH

Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing sources.

Jun 3, 2025
CVE-2024-53018
6.6 MEDIUM

Memory corruption may occur while processing the OIS packet parser.

Jun 3, 2025
CVE-2024-53017
6.6 MEDIUM

Memory corruption while handling test pattern generator IOCTL command.

Jun 3, 2025
CVE-2024-53016
6.6 MEDIUM

Memory corruption while processing I2C settings in Camera driver.

Jun 3, 2025
CVE-2024-53015
6.6 MEDIUM

Memory corruption while processing IOCTL command to handle buffers associated with a session.

Jun 3, 2025
CVE-2024-53013
6.6 MEDIUM

Memory corruption may occur while processing voice call registration with user.

Jun 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.