CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48877
8.4 HIGH

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead …

Jun 2, 2025
CVE-2025-5447
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function …

Jun 2, 2025
CVE-2025-37094
5.5 MEDIUM

A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37093
9.8 CRITICAL

An authentication bypass vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37092
9.8 CRITICAL

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37091
7.2 HIGH

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37090
9.8 CRITICAL

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37089
9.8 CRITICAL

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2024-57783
8.1 HIGH

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with …

Jun 2, 2025
CVE-2025-5446
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS …

Jun 2, 2025
CVE-2025-5445
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function …

Jun 2, 2025
CVE-2025-48745

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-49113. Reason: This candidate is a reservation duplicate of CVE-2025-49113. Notes: All CVE users should reference …

Jun 2, 2025
CVE-2025-46806

A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4.

Jun 2, 2025
CVE-2025-26396
7.8 HIGH

The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a …

Jun 2, 2025
CVE-2024-12168
7.8 HIGH

Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.

Jun 2, 2025
CVE-2025-5444
6.3 MEDIUM

A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this vulnerability is the …

Jun 2, 2025
CVE-2025-5443
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function wirelessAdvancedHidden of …

Jun 2, 2025
CVE-2025-48990

NeKernal is a free and open-source operating system stack. Version 0.0.2 has a 1-byte heap overflow in `rt_copy_memory`, which unconditionally wrote a null terminator at …

Jun 2, 2025
CVE-2025-48958
5.5 MEDIUM

Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject …

Jun 2, 2025
CVE-2025-48957
7.5 HIGH

AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, …

Jun 2, 2025
CVE-2025-48955
6.2 MEDIUM

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret …

Jun 2, 2025
CVE-2025-48495
5.4 MEDIUM

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly name of an API key, an authenticated user …

Jun 2, 2025
CVE-2025-46807

A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny legitimate users …

Jun 2, 2025
CVE-2025-5442
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function …

Jun 2, 2025
CVE-2025-5441
6.3 MEDIUM

A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setDeviceURL of the …

Jun 2, 2025
CVE-2025-48494
5.4 MEDIUM

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encryption, a stored cross-site scripting vulnerability can be exploited …

Jun 2, 2025
CVE-2025-47289
6.3 MEDIUM

CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an …

Jun 2, 2025
CVE-2025-47272
5.5 MEDIUM

The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. …

Jun 2, 2025
CVE-2025-3454
5.0 MEDIUM

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with …

Jun 2, 2025
CVE-2025-29785
7.5 HIGH

quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release …

Jun 2, 2025
CVE-2025-1246
7.8 HIGH

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, …

Jun 2, 2025
CVE-2025-0819
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Jun 2, 2025
CVE-2025-0073
7.8 HIGH

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user …

Jun 2, 2025
CVE-2025-5440
6.3 MEDIUM

A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function NTP of the …

Jun 2, 2025
CVE-2025-5439
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rated as critical. Affected by this issue is …

Jun 2, 2025
CVE-2025-3260
8.3 HIGH

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). …

Jun 2, 2025
CVE-2025-1750
9.8 CRITICAL

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, …

Jun 2, 2025
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If …

Jun 2, 2025
CVE-2025-5438
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Affected by this vulnerability is …

Jun 2, 2025
CVE-2025-5437
5.3 MEDIUM

A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component …

Jun 2, 2025
CVE-2025-5436
5.3 MEDIUM

A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi. …

Jun 2, 2025
CVE-2025-5435
7.3 HIGH

A vulnerability was found in Marwal Infotech CMS 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /page.php. The …

Jun 2, 2025
CVE-2025-5113

The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used.

Jun 2, 2025
CVE-2025-0358
8.8 HIGH

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege …

Jun 2, 2025
CVE-2025-0325
4.3 MEDIUM

A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the …

Jun 2, 2025
CVE-2025-0324
9.4 CRITICAL

The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

Jun 2, 2025
CVE-2025-5434
7.3 HIGH

A vulnerability was found in Aem Solutions CMS up to 1.0. It has been classified as critical. This affects an unknown part of the file …

Jun 2, 2025
CVE-2025-5433
6.3 MEDIUM

A vulnerability was found in Fengoffice Feng Office 3.5.1.5 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php?c=account&a=set_timezone. …

Jun 2, 2025
CVE-2025-4010

The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoints of the web …

Jun 2, 2025
CVE-2025-1235
4.3 MEDIUM

A low privileged attacker can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This …

Jun 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.