CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42922
6.5 MEDIUM

AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.

May 21, 2025
CVE-2025-48417
6.5 MEDIUM

The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware …

May 21, 2025
CVE-2025-48416
8.1 HIGH

An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image for the "root" user. …

May 21, 2025
CVE-2025-48415
6.2 MEDIUM

A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The .ini file can contain several "commands" …

May 21, 2025
CVE-2025-40775
7.5 HIGH

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm …

May 21, 2025
CVE-2025-1421

Data provided in a request performed to the server while activating a new device are put in a database. Other high privileged users might download …

May 21, 2025
CVE-2025-1420

Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. …

May 21, 2025
CVE-2025-1419

Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue …

May 21, 2025
CVE-2025-1418

A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not …

May 21, 2025
CVE-2025-1417

In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by the MDM (Mobile Device Management). This …

May 21, 2025
CVE-2025-1416

In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities restricted by the MDM (Mobile Device Management). For it …

May 21, 2025
CVE-2025-4803
7.2 HIGH

The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …

May 21, 2025
CVE-2025-4611
6.4 MEDIUM

The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in …

May 21, 2025
CVE-2025-4221
6.4 MEDIUM

The Animated Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-downloader' shortcode in all versions up to, and including, 1.0.0 …

May 21, 2025
CVE-2025-4219
6.4 MEDIUM

The DPEPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dpe' shortcode in all versions up to, and including, 0.3 due …

May 21, 2025
CVE-2025-4217
6.4 MEDIUM

The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_youtube' shortcode in all versions up to, and …

May 21, 2025
CVE-2025-4105
5.4 MEDIUM

The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions in the 'splitIt-flexfields-payment-gateway.php' file in …

May 21, 2025
CVE-2025-48414
6.5 MEDIUM

There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are …

May 21, 2025
CVE-2025-48413
7.7 HIGH

The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is …

May 21, 2025
CVE-2025-41232
9.1 CRITICAL

Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass. Your application may be affected by …

May 21, 2025
CVE-2025-3781
6.4 MEDIUM

The Raisely Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's raisely_donation_form shortcode in all versions up to, and including, …

May 21, 2025
CVE-2025-3750
6.4 MEDIUM

The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ parameter in all versions up to, and including, 7.7.1 …

May 21, 2025
CVE-2025-27804
6.5 MEDIUM

Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted message to a certain MQTT topic …

May 21, 2025
CVE-2025-27803
6.5 MEDIUM

The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately …

May 21, 2025
CVE-2025-1415

A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Device Management), as well as details of …

May 21, 2025
CVE-2024-12561
6.1 MEDIUM

The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.0. …

May 21, 2025
CVE-2025-1712
8.8 HIGH

Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files

May 21, 2025
CVE-2019-16536
8.8 HIGH

Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.

May 21, 2025
CVE-2025-4949
5.3 MEDIUM

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 …

May 21, 2025
CVE-2025-4524
9.8 CRITICAL

The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, …

May 21, 2025
CVE-2021-25262
5.4 MEDIUM

Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.

May 21, 2025
CVE-2021-25255
7.5 HIGH

Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.

May 21, 2025
CVE-2021-25254
5.3 MEDIUM

Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.

May 21, 2025
CVE-2025-5013
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the …

May 21, 2025
CVE-2025-4969
6.5 MEDIUM

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can …

May 21, 2025
CVE-2025-4094
9.8 CRITICAL

The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to …

May 21, 2025
CVE-2025-48427

Rejected reason: Not used

May 21, 2025
CVE-2025-48426

Rejected reason: Not used

May 21, 2025
CVE-2025-48425

Rejected reason: Not used

May 21, 2025
CVE-2025-48424

Rejected reason: Not used

May 21, 2025
CVE-2025-48423

Rejected reason: Not used

May 21, 2025
CVE-2025-48422

Rejected reason: Not used

May 21, 2025
CVE-2025-48421

Rejected reason: Not used

May 21, 2025
CVE-2025-48420

Rejected reason: Not used

May 21, 2025
CVE-2025-48419

Rejected reason: Not used

May 21, 2025
CVE-2025-5011
2.4 LOW

A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List …

May 21, 2025
CVE-2025-5010
2.4 LOW

A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog …

May 21, 2025
CVE-2025-5008
7.3 HIGH

A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

May 20, 2025
CVE-2025-5007
3.5 LOW

A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the …

May 20, 2025
CVE-2025-5006
7.3 HIGH

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/category.php. …

May 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.