CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4943
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and …

May 30, 2025
CVE-2025-48936
8.1 HIGH

Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vulnerability exists in the password reset mechanism. ZITADEL utilizes the …

May 30, 2025
CVE-2025-48880
6.6 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is …

May 30, 2025
CVE-2025-48875
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data …

May 30, 2025
CVE-2025-48865
9.1 CRITICAL

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except …

May 30, 2025
CVE-2025-48492
8.8 HIGH

GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject …

May 30, 2025
CVE-2025-48489
4.8 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to …

May 30, 2025
CVE-2025-48488
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML …

May 30, 2025
CVE-2025-48487
4.8 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a …

May 30, 2025
CVE-2025-48486
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerability is caused by the lack of …

May 30, 2025
CVE-2025-48485
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to …

May 30, 2025
CVE-2025-47697
7.5 HIGH

Client-side enforcement of server-side security issue exists in wivia 5 all versions. If exploited, an unauthenticated attacker may bypass authentication and operate the affected device …

May 30, 2025
CVE-2025-41406
6.1 MEDIUM

Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected device with a specific operation, an arbitrary …

May 30, 2025
CVE-2025-41385
7.2 HIGH

An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed by a …

May 30, 2025
CVE-2025-5259
6.4 MEDIUM

The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.7.3 …

May 30, 2025
CVE-2025-4659
5.3 MEDIUM

The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions …

May 30, 2025
CVE-2025-4429
6.1 MEDIUM

The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 30, 2025
CVE-2025-48889
5.3 MEDIUM

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. …

May 30, 2025
CVE-2025-48881
8.3 HIGH

Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEASE, all objects for which an object-management …

May 30, 2025
CVE-2025-48490

Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute …

May 30, 2025
CVE-2025-41235
8.6 HIGH

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.

May 30, 2025
CVE-2025-48484
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to …

May 30, 2025
CVE-2025-48483
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to …

May 30, 2025
CVE-2025-48482
4.3 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated …

May 30, 2025
CVE-2025-48481
9.8 CRITICAL

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invite_hash, can exploit …

May 30, 2025
CVE-2025-48480
2.7 LOW

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege …

May 30, 2025
CVE-2025-48479
2.7 LOW

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the …

May 30, 2025
CVE-2025-48478
4.9 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation during user creation has resulted in a mass …

May 30, 2025
CVE-2025-48477
8.1 HIGH

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires the user to perform a correct sequence …

May 30, 2025
CVE-2025-48476
8.8 HIGH

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user records using the fill() method, there …

May 30, 2025
CVE-2025-48491

Project AI is a platform designed to create AI agents. Prior to the pre-beta version, a hardcoded API key was present in the source code. …

May 30, 2025
CVE-2025-48381
4.3 MEDIUM

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an …

May 30, 2025
CVE-2025-48068
4.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may …

May 30, 2025
CVE-2025-47952
9.1 CRITICAL

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in Traefik managing …

May 30, 2025
CVE-2025-44906
7.8 HIGH

jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.

May 30, 2025
CVE-2025-44905
8.8 HIGH

hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.

May 30, 2025
CVE-2025-44904
8.8 HIGH

hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.

May 30, 2025
CVE-2025-48757
9.3 CRITICAL

An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. …

May 30, 2025
CVE-2025-44619
9.1 CRITICAL

Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without …

May 30, 2025
CVE-2025-44614
7.5 HIGH

Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext.

May 30, 2025
CVE-2025-44612
5.9 MEDIUM

Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept …

May 30, 2025
CVE-2024-12224
8.8 HIGH

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one part …

May 30, 2025
CVE-2020-36846
9.8 CRITICAL

A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli …

May 30, 2025
CVE-2025-46352
9.8 CRITICAL

The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the …

May 30, 2025
CVE-2025-41438
9.8 CRITICAL

The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to change this by …

May 30, 2025
CVE-2025-1907
9.8 CRITICAL

Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if connected.

May 30, 2025
CVE-2025-5332
7.3 HIGH

A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php. …

May 29, 2025
CVE-2025-5331
7.3 HIGH

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. …

May 29, 2025
CVE-2025-5330
7.3 HIGH

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component RETR Command Handler. …

May 29, 2025
CVE-2025-5307
7.8 HIGH

Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue to potentially disclose information and to execute arbitrary …

May 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.