CVE Database

116976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5033
4.3 MEDIUM

A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/controller/admin/UserManageController/addUser. The manipulation …

May 21, 2025
CVE-2025-5020
4.3 MEDIUM

Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes …

May 21, 2025
CVE-2025-48069
6.6 MEDIUM

ejson2env allows users to decrypt EJSON secrets and export them as environment variables. Prior to version 2.0.8, the `ejson2env` tool has a vulnerability related to …

May 21, 2025
CVE-2025-48064
3.3 LOW

GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file …

May 21, 2025
CVE-2025-48063
8.8 HIGH

XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part …

May 21, 2025
CVE-2025-48060
7.5 HIGH

jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from …

May 21, 2025
CVE-2025-47291
7.5 HIGH

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version …

May 21, 2025
CVE-2025-46822

OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path …

May 21, 2025
CVE-2025-2102

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.

May 21, 2025
CVE-2025-5032
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /admin/edit-category.php. The manipulation …

May 21, 2025
CVE-2025-5031
3.1 LOW

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the component …

May 21, 2025
CVE-2025-5030
5.0 MEDIUM

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of the file …

May 21, 2025
CVE-2025-4416
7.5 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events Log Track: from 0.0.0 before 3.1.11, …

May 21, 2025
CVE-2025-4415
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO allows Cross-Site Scripting (XSS).This issue affects Piwik PRO: from 0.0.0 …

May 21, 2025
CVE-2025-48012
4.8 MEDIUM

Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0.

May 21, 2025
CVE-2025-48011
4.8 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before …

May 21, 2025
CVE-2025-48010
4.8 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before …

May 21, 2025
CVE-2025-48009
3.1 LOW

Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse.This issue affects Single Content Sync: from 0.0.0 before 1.4.12.

May 21, 2025
CVE-2025-45754
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious JavaScript payloads by creating a document with …

May 21, 2025
CVE-2025-25539
6.5 MEDIUM

Local File Inclusion vulnerability in Vasco v3.14and before allows a remote attacker to obtain sensitive information via help menu.

May 21, 2025
CVE-2025-20267
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks …

May 21, 2025
CVE-2025-20258
5.4 MEDIUM

A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails that are sent by …

May 21, 2025
CVE-2025-20257
6.5 MEDIUM

A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker …

May 21, 2025
CVE-2025-20256
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote …

May 21, 2025
CVE-2025-20255
4.3 MEDIUM

A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join …

May 21, 2025
CVE-2025-20250
6.1 MEDIUM

A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering …

May 21, 2025
CVE-2025-20247
6.1 MEDIUM

A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering …

May 21, 2025
CVE-2025-20246
6.1 MEDIUM

A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering …

May 21, 2025
CVE-2025-20242
6.5 MEDIUM

A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data …

May 21, 2025
CVE-2025-20152
8.6 HIGH

A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of …

May 21, 2025
CVE-2025-20114
4.3 MEDIUM

A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an …

May 21, 2025
CVE-2025-20113
7.1 HIGH

A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on …

May 21, 2025
CVE-2025-20112
5.1 MEDIUM

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an …

May 21, 2025
CVE-2025-0372

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.

May 21, 2025
CVE-2024-56428
5.5 MEDIUM

The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the …

May 21, 2025
CVE-2025-4008
8.8 HIGH KEV

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI …

May 21, 2025
CVE-2025-48207
8.6 HIGH

The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.

May 21, 2025
CVE-2025-48206
6.1 MEDIUM

The ns_backup extension through 13.0.0 for TYPO3 allows XSS.

May 21, 2025
CVE-2025-48205
8.6 HIGH

The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.

May 21, 2025
CVE-2025-48204
6.8 MEDIUM

The ns_backup extension through 13.0.0 for TYPO3 allows command injection.

May 21, 2025
CVE-2025-48203
6.4 MEDIUM

The cs_seo extension through 9.2.0 for TYPO3 allows XSS.

May 21, 2025
CVE-2025-48202
5.3 MEDIUM

The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.

May 21, 2025
CVE-2025-48201
8.6 HIGH

The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.

May 21, 2025
CVE-2025-48200
10.0 CRITICAL

The sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.

May 21, 2025
CVE-2025-27998
8.4 HIGH

An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.

May 21, 2025
CVE-2025-27997
8.4 HIGH

An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.

May 21, 2025
CVE-2025-5029
5.4 MEDIUM

A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by …

May 21, 2025
CVE-2024-23337
4.3 MEDIUM

jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, …

May 21, 2025
CVE-2025-44895
6.5 MEDIUM

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.

May 21, 2025
CVE-2025-44892
6.5 MEDIUM

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.

May 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.