CVE Database

116976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5166
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file …

May 26, 2025
CVE-2025-5165
3.3 LOW

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. …

May 26, 2025
CVE-2025-5164
3.7 LOW

A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation …

May 26, 2025
CVE-2025-5163
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper …

May 26, 2025
CVE-2025-5162
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this issue is some unknown functionality …

May 26, 2025
CVE-2025-5161
4.3 MEDIUM

A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function operationDailyOut of the file …

May 26, 2025
CVE-2025-5160
4.3 MEDIUM

A vulnerability classified as problematic has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected is the function Download of the file /packetCaptureStrategy/download. The …

May 26, 2025
CVE-2025-5159
4.3 MEDIUM

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been rated as problematic. This issue affects the function Download of the …

May 26, 2025
CVE-2025-2146
9.8 CRITICAL

Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger …

May 26, 2025
CVE-2025-5158
4.3 MEDIUM

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been declared as problematic. This vulnerability affects the function downloadSoftware of the …

May 25, 2025
CVE-2025-5157
4.3 MEDIUM

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of the file …

May 25, 2025
CVE-2025-5156
8.8 HIGH

A vulnerability was found in H3C GR-5400AX up to 100R008 and classified as critical. Affected by this issue is the function EditWlanMacList of the file …

May 25, 2025
CVE-2025-5155
6.3 MEDIUM

A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the function batchCope of the file app/admin/controller/Article.php. …

May 25, 2025
CVE-2025-5154
2.3 LOW

A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of …

May 25, 2025
CVE-2025-5153
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown processing of the component Design …

May 25, 2025
CVE-2025-5152
6.3 MEDIUM

A vulnerability classified as critical was found in Chanjet CRM up to 20250510. This vulnerability affects unknown code of the file /activity/newActivityedit.php?DontCheckLogin=1&id=null&ret=mod1. The manipulation of …

May 25, 2025
CVE-2025-5151
5.3 MEDIUM

A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This affects the function execute_analysis_code_safely of the file introspect/backend/tools/analysis_tools.py. The manipulation …

May 25, 2025
CVE-2025-5150
6.3 MEDIUM

A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the …

May 25, 2025
CVE-2025-5149
5.6 MEDIUM

A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the …

May 25, 2025
CVE-2025-5148
5.3 MEDIUM

A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is the function load_state_dict of the file inspiremusic/cli/model.py …

May 25, 2025
CVE-2025-5147
6.3 MEDIUM

A vulnerability was found in Netcore NBR1005GPEV2, NBR200V2 and B6V2 up to 20250508 and classified as critical. This issue affects the function tools_ping of the …

May 25, 2025
CVE-2025-5146
6.3 MEDIUM

A vulnerability has been found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2 and NBR200V2 up to 20250508 and classified as critical. This vulnerability affects …

May 25, 2025
CVE-2025-5145
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, NBR200V2 and POWER13 up to 20250508. This affects …

May 25, 2025
CVE-2025-5140
6.3 MEDIUM

A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This affects the function this.oursNetService.getData of …

May 25, 2025
CVE-2025-5139
5.6 MEDIUM

A vulnerability was found in Qualitor 8.20/8.24. It has been rated as critical. Affected by this issue is some unknown functionality of the file /html/ad/adconexaooffice365/request/testaConexaoOffice365.php …

May 25, 2025
CVE-2025-5138
3.5 LOW

A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

May 25, 2025
CVE-2025-5137
4.7 MEDIUM

A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an unknown function of the file dede/sys_verifies.php?action=getfiles of the component …

May 25, 2025
CVE-2025-5136
3.7 LOW

A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of …

May 25, 2025
CVE-2025-5135
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionality of …

May 24, 2025
CVE-2025-5134
3.5 LOW

A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the component Buy …

May 24, 2025
CVE-2025-5133
4.3 MEDIUM

A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function of the component Search Box. The …

May 24, 2025
CVE-2025-5132
4.3 MEDIUM

A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file …

May 24, 2025
CVE-2025-5131
4.7 MEDIUM

A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the function uploadCategoryImage of the file …

May 24, 2025
CVE-2025-5130
4.7 MEDIUM

A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function uploadProductImage of the file tmall/admin/uploadProductImage. …

May 24, 2025
CVE-2025-5129
7.0 HIGH

A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulnerability is an unknown functionality in the library …

May 24, 2025
CVE-2025-5128
7.3 HIGH

A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component …

May 24, 2025
CVE-2025-5127
3.5 LOW

A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. Executing manipulation of the …

May 24, 2025
CVE-2025-5126
8.8 HIGH

A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the file \usr\www\application\models\settingsregional.php. Performing manipulation of the …

May 24, 2025
CVE-2025-5124
8.1 HIGH

A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown …

May 24, 2025
CVE-2025-4223
4.7 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘login_url’ parameter in all …

May 24, 2025
CVE-2025-5058
9.8 CRITICAL

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function …

May 24, 2025
CVE-2025-4603
9.1 CRITICAL

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function …

May 24, 2025
CVE-2025-4602
5.9 MEDIUM

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the …

May 24, 2025
CVE-2025-4336
8.1 HIGH

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function …

May 24, 2025
CVE-2025-5055
4.4 MEDIUM

The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings …

May 24, 2025
CVE-2025-48756
2.9 LOW

In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits …

May 24, 2025
CVE-2025-48755
2.9 LOW

In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).

May 24, 2025
CVE-2025-48754
2.9 LOW

In the memory_pages crate 0.1.0 for Rust, division by zero can occur.

May 24, 2025
CVE-2025-48753
2.9 LOW

In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.

May 24, 2025
CVE-2025-48752
2.9 LOW

In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.

May 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.