CVE Database

10779+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-45492
9.8 CRITICAL

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.

May 6, 2025
CVE-2025-45491
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

May 6, 2025
CVE-2025-45490
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.

May 6, 2025
CVE-2025-45489
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.

May 6, 2025
CVE-2025-45488
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

May 6, 2025
CVE-2025-45487
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

May 6, 2025
CVE-2025-40625
9.8 CRITICAL

Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to …

May 6, 2025
CVE-2025-40624
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-40623
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-40622
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-40621
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-40620
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-44074
9.8 CRITICAL

SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.

May 5, 2025
CVE-2025-44072
9.8 CRITICAL

SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.

May 5, 2025
CVE-2025-44071
9.8 CRITICAL

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via …

May 5, 2025
CVE-2025-46726
9.1 CRITICAL

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input …

May 5, 2025
CVE-2025-45616
9.8 CRITICAL

Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.

May 5, 2025
CVE-2025-45615
9.8 CRITICAL

Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.

May 5, 2025
CVE-2025-45612
9.8 CRITICAL

Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.

May 5, 2025
CVE-2025-45611
9.8 CRITICAL

Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.

May 5, 2025
CVE-2025-45607
9.8 CRITICAL

An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.

May 5, 2025
CVE-2025-1909
9.8 CRITICAL

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification …

May 5, 2025
CVE-2025-43852
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. …

May 5, 2025
CVE-2025-43851
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. …

May 5, 2025
CVE-2025-43850
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. …

May 5, 2025
CVE-2025-43849
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b variables take user …

May 5, 2025
CVE-2025-4052
9.8 CRITICAL

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

May 5, 2025
CVE-2025-45238
9.1 CRITICAL

foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.

May 5, 2025
CVE-2025-43848
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable takes user input (e.g. …

May 5, 2025
CVE-2025-43847
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path2 variable takes user input (e.g. …

May 5, 2025
CVE-2025-43846
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path1 variable takes user input (e.g. …

May 5, 2025
CVE-2025-43845
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. The ckpt_path2 variable takes user input (e.g. …

May 5, 2025
CVE-2025-43844
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, among others, take user …

May 5, 2025
CVE-2025-43843
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7 and f0method8 take …

May 5, 2025
CVE-2025-43842
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7, trainset_dir4 and sr2 …

May 5, 2025
CVE-2025-24977
9.1 CRITICAL

OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the …

May 5, 2025
CVE-2024-57235
9.8 CRITICAL

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.

May 5, 2025
CVE-2024-57234
9.8 CRITICAL

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

May 5, 2025
CVE-2024-57233
9.8 CRITICAL

NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

May 5, 2025
CVE-2024-57232
9.8 CRITICAL

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

May 5, 2025
CVE-2024-57231
9.8 CRITICAL

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

May 5, 2025
CVE-2024-57230
9.8 CRITICAL

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

May 5, 2025
CVE-2024-57229
9.8 CRITICAL

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.

May 5, 2025
CVE-2025-45042
9.8 CRITICAL

Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

May 5, 2025
CVE-2025-2905
9.1 CRITICAL

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 …

May 5, 2025
CVE-2025-3918
9.8 CRITICAL

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The …

May 3, 2025
CVE-2025-45800
9.8 CRITICAL

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the processing of the deviceMac parameter.

May 2, 2025
CVE-2025-44877
9.8 CRITICAL

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute …

May 2, 2025
CVE-2025-44872
9.8 CRITICAL

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute …

May 2, 2025
CVE-2025-44868
9.8 CRITICAL

Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows …

May 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.