CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36572
6.5 MEDIUM

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the …

May 28, 2025
CVE-2025-32802
6.1 MEDIUM

Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, …

May 28, 2025
CVE-2025-32801
7.8 HIGH

Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry …

May 28, 2025
CVE-2024-47056
5.1 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be directly accessible via a web browser. This exposure could lead …

May 28, 2025
CVE-2022-26424

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-26304

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-26072

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-26056

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-26037

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-25909

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-25870

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-25868

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2022-24067

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 28, 2025
CVE-2025-45343
9.8 CRITICAL

An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules …

May 28, 2025
CVE-2024-51453
4.3 MEDIUM

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted …

May 28, 2025
CVE-2024-38341
5.9 MEDIUM

IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker …

May 28, 2025
CVE-2025-3357
9.8 CRITICAL

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index …

May 28, 2025
CVE-2025-5277
9.6 CRITICAL

aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands …

May 28, 2025
CVE-2025-4134
7.3 HIGH

Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update …

May 28, 2025
CVE-2025-48734
8.8 HIGH

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using …

May 28, 2025
CVE-2025-45997
8.6 HIGH

Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying …

May 28, 2025
CVE-2025-40651

Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the …

May 28, 2025
CVE-2025-4493
6.5 MEDIUM

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting …

May 28, 2025
CVE-2025-5299
7.3 HIGH

A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

May 28, 2025
CVE-2025-5298
7.3 HIGH

A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/betweendates-detailsreports.php. …

May 28, 2025
CVE-2025-5297
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file …

May 28, 2025
CVE-2025-3864

Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote attackers can exploit this to exhaust connection pools, …

May 28, 2025
CVE-2025-5295
7.3 HIGH

A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code of the component PORT Command Handler. The manipulation …

May 28, 2025
CVE-2025-40673

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because …

May 28, 2025
CVE-2025-4963
6.4 MEDIUM

The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.15 due …

May 28, 2025
CVE-2025-1753
7.8 HIGH

LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files` argument, which is directly passed …

May 28, 2025
CVE-2025-5287
7.5 HIGH

The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.0.0 …

May 28, 2025
CVE-2025-5082
6.1 MEDIUM

The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ parameter in all versions up to, and including, 5.0.12 due …

May 28, 2025
CVE-2025-47295
3.7 LOW

A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker …

May 28, 2025
CVE-2025-47294
5.3 MEDIUM

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the …

May 28, 2025
CVE-2025-46777
2.3 LOW

A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an …

May 28, 2025
CVE-2025-27528
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security …

May 28, 2025
CVE-2025-27526
6.5 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability …

May 28, 2025
CVE-2025-27522
6.5 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for …

May 28, 2025
CVE-2025-25251
7.8 HIGH

An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a local attacker to escalate privileges …

May 28, 2025
CVE-2025-24473
3.7 LOW

A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an …

May 28, 2025
CVE-2025-22252
9.8 CRITICAL

A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 …

May 28, 2025
CVE-2024-54020
2.3 LOW

A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds …

May 28, 2025
CVE-2025-5025
4.8 MEDIUM

libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC …

May 28, 2025
CVE-2025-4947
6.5 MEDIUM

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does …

May 28, 2025
CVE-2025-4009

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This …

May 28, 2025
CVE-2025-4800
8.8 HIGH

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attachment function in …

May 28, 2025
CVE-2025-48848

Rejected reason: Not used

May 28, 2025
CVE-2025-48847

Rejected reason: Not used

May 28, 2025
CVE-2025-48846

Rejected reason: Not used

May 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.