CVE Database

10779+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3927
9.8 CRITICAL

Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the …

May 2, 2025
CVE-2025-2605
9.9 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from …

May 2, 2025
CVE-2025-2421
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.This issue affects SambaBox: before 5.1.

May 2, 2025
CVE-2025-2812
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection.This issue affects …

May 2, 2025
CVE-2025-3709
9.8 CRITICAL

Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack.

May 2, 2025
CVE-2025-3708
9.8 CRITICAL

Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and …

May 2, 2025
CVE-2025-3746
9.8 CRITICAL

The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.14 to 2.0.59. This is due …

May 2, 2025
CVE-2024-48905
9.1 CRITICAL

Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

May 1, 2025
CVE-2025-35996
9.0 CRITICAL

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That …

May 1, 2025
CVE-2025-32011
9.8 CRITICAL

KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path …

May 1, 2025
CVE-2025-24522
10.0 CRITICAL

KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote …

May 1, 2025
CVE-2025-46566
9.8 CRITICAL

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue …

May 1, 2025
CVE-2025-46337
10.0 CRITICAL

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query …

May 1, 2025
CVE-2025-27007
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.

May 1, 2025
CVE-2025-47154
9.0 CRITICAL

LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary …

May 1, 2025
CVE-2025-4144
9.8 CRITICAL

PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could …

May 1, 2025
CVE-2025-46558
9.0 CRITICAL

XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, …

Apr 30, 2025
CVE-2025-46557
9.8 CRITICAL

XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, …

Apr 30, 2025
CVE-2025-46331
9.8 CRITICAL

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker …

Apr 30, 2025
CVE-2025-44192
9.8 CRITICAL

SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance.

Apr 30, 2025
CVE-2025-30392
9.8 CRITICAL

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Apr 30, 2025
CVE-2025-30390
9.9 CRITICAL

Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

Apr 30, 2025
CVE-2025-32974
9.0 CRITICAL

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't …

Apr 30, 2025
CVE-2025-32973
9.0 CRITICAL

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, …

Apr 30, 2025
CVE-2025-45018
9.8 CRITICAL

A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary …

Apr 30, 2025
CVE-2025-45017
9.8 CRITICAL

A SQL injection vulnerability was discovered in edit-ticket.php of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via …

Apr 30, 2025
CVE-2025-32444
10.0 CRITICAL

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, …

Apr 30, 2025
CVE-2025-46348
10.0 CRITICAL

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without …

Apr 29, 2025
CVE-2025-46347
9.8 CRITICAL

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used …

Apr 29, 2025
CVE-2025-40618
9.8 CRITICAL

SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the …

Apr 29, 2025
CVE-2025-40617
9.8 CRITICAL

SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the …

Apr 29, 2025
CVE-2025-25962
9.8 CRITICAL

An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function

Apr 29, 2025
CVE-2025-25403
9.8 CRITICAL

Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.

Apr 29, 2025
CVE-2025-4083
9.1 CRITICAL

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead …

Apr 29, 2025
CVE-2025-45953
9.1 CRITICAL

A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of …

Apr 28, 2025
CVE-2025-45949
9.8 CRITICAL

A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - …

Apr 28, 2025
CVE-2025-45947
9.8 CRITICAL

An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - …

Apr 28, 2025
CVE-2025-31651
9.8 CRITICAL

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a …

Apr 28, 2025
CVE-2015-2079
9.9 CRITICAL

Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.

Apr 28, 2025
CVE-2025-46661
10.0 CRITICAL

IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection. All instances have …

Apr 28, 2025
CVE-2025-3200
9.1 CRITICAL

An unauthenticated remote attacker could exploit the used, insecure TLS 1.0 and TLS 1.1 protocols to intercept and manipulate encrypted communications between the Com-Server and …

Apr 28, 2025
CVE-2025-2907
9.8 CRITICAL

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to …

Apr 26, 2025
CVE-2025-32985
9.8 CRITICAL

NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

Apr 25, 2025
CVE-2025-32980
9.8 CRITICAL

NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration.

Apr 25, 2025
CVE-2025-25775
9.8 CRITICAL

Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

Apr 25, 2025
CVE-2024-56156
9.0 CRITICAL

Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This …

Apr 25, 2025
CVE-2025-32432
10.0 CRITICAL KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to …

Apr 25, 2025
CVE-2025-2470
9.8 CRITICAL

The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in …

Apr 25, 2025
CVE-2025-46616
9.9 CRITICAL

Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, …

Apr 25, 2025
CVE-2025-46275
9.8 CRITICAL

WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator account without knowing any existing credentials.

Apr 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.