CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5385
6.3 MEDIUM

A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. …

May 31, 2025
CVE-2025-5384
6.3 MEDIUM

A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAutoListController of the file /cgAutoListController.do?datagrid. The …

May 31, 2025
CVE-2025-5383
2.4 LOW

A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component …

May 31, 2025
CVE-2025-5381
2.7 LOW

A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/File/downloadFile of …

May 31, 2025
CVE-2025-5380
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f5615e5a3d8bcbfbb. This issue affects some unknown processing of …

May 31, 2025
CVE-2025-5379
4.3 MEDIUM

A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation …

May 31, 2025
CVE-2025-5378
4.3 MEDIUM

A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown part of the file mycouncil2.aspx. The manipulation …

May 31, 2025
CVE-2025-5377
4.3 MEDIUM

A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

May 31, 2025
CVE-2025-5376
7.3 HIGH

A vulnerability was found in SourceCodester Health Center Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an …

May 31, 2025
CVE-2025-4857
7.2 HIGH

The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9 via the 'file' parameter. This makes …

May 31, 2025
CVE-2025-4691
5.3 MEDIUM

The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

May 31, 2025
CVE-2025-5375
6.3 MEDIUM

A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critical. Affected is an unknown function of the …

May 31, 2025
CVE-2025-5374
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affects some unknown processing of the file /admin/all-applications.php. …

May 31, 2025
CVE-2025-5373
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/users-applications.php. …

May 31, 2025
CVE-2025-5371
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Health Center Patient Record Management System 1.0. Affected by this issue is some …

May 31, 2025
CVE-2025-5290
6.4 MEDIUM

The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, …

May 31, 2025
CVE-2025-3813
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and …

May 31, 2025
CVE-2025-5292
6.4 MEDIUM

The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder plugin for WordPress is vulnerable to Stored …

May 31, 2025
CVE-2025-5285
6.4 MEDIUM

The Product Subtitle for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmlTag’ parameter in all versions up to, and including, …

May 31, 2025
CVE-2025-4672
8.8 HIGH

The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback() function in versions 2.2.1 to …

May 31, 2025
CVE-2025-4631
9.8 CRITICAL

The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. …

May 31, 2025
CVE-2025-4607
9.8 CRITICAL

The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() …

May 31, 2025
CVE-2025-4595
6.4 MEDIUM

The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fastspring/block-fastspringblocks-complete-product-catalog' block in all versions up to, and including, 3.0.1 due …

May 31, 2025
CVE-2025-4590
6.4 MEDIUM

The Daisycon prijsvergelijkers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'daisycon_uitvaart' shortcode in all versions up to, and including, 4.9.0 …

May 31, 2025
CVE-2025-4103
8.8 HIGH

The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_ajax_wpgm_start_geojson_import() function in versions 0.3.4 to 0.3.5. …

May 31, 2025
CVE-2025-5370
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The …

May 31, 2025
CVE-2025-5369
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester PHP Display Username After Login 1.0. Affected is an unknown function of the file /login.php. …

May 31, 2025
CVE-2025-5368
6.3 MEDIUM

A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affects some unknown processing of the …

May 31, 2025
CVE-2025-5016
4.7 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and …

May 31, 2025
CVE-2025-5367
7.3 HIGH

A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

May 31, 2025
CVE-2025-5365
7.3 HIGH

A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

May 31, 2025
CVE-2018-25111
5.1 MEDIUM

django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.

May 31, 2025
CVE-2025-5364
7.3 HIGH

A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

May 30, 2025
CVE-2025-5363
7.3 HIGH

A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

May 30, 2025
CVE-2025-5362
7.3 HIGH

A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/doctor-specilization.php. …

May 30, 2025
CVE-2025-5361
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. This issue affects some unknown processing of the …

May 30, 2025
CVE-2025-5360
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /book-appointment.php. The manipulation …

May 30, 2025
CVE-2025-48949
9.8 CRITICAL

Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the …

May 30, 2025
CVE-2025-48948
6.5 MEDIUM

Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any authenticated regular user …

May 30, 2025
CVE-2025-48946
3.7 LOW

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an algorithm with …

May 30, 2025
CVE-2025-48882

PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using …

May 30, 2025
CVE-2025-2503
7.1 HIGH

An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated …

May 30, 2025
CVE-2025-2502
7.8 HIGH

An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

May 30, 2025
CVE-2025-2501
7.8 HIGH

An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.

May 30, 2025
CVE-2025-1479
5.3 MEDIUM

An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary …

May 30, 2025
CVE-2025-5359
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /appointment-history.php. The …

May 30, 2025
CVE-2025-48944
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with …

May 30, 2025
CVE-2025-48943
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) …

May 30, 2025
CVE-2025-48942
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with …

May 30, 2025
CVE-2025-48938
9.8 CRITICAL

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 …

May 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.