CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46717
3.3 LOW

sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very limited) sudo privileges …

May 12, 2025
CVE-2025-46611
6.1 MEDIUM

Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.

May 12, 2025
CVE-2025-46610
8.8 HIGH

ARTEC EMA Mail 6.92 allows CSRF.

May 12, 2025
CVE-2025-26846
9.8 CRITICAL

An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.

May 12, 2025
CVE-2025-26841
6.1 MEDIUM

Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.

May 12, 2025
CVE-2024-56524
9.1 CRITICAL

Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by adding a special character to the request.

May 12, 2025
CVE-2024-56523
9.1 CRITICAL

Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when …

May 12, 2025
CVE-2025-45835
7.5 HIGH

A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function of the cgitest.cgi file. Attackers can trigger …

May 12, 2025
CVE-2025-40627
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim …

May 12, 2025
CVE-2025-40626
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim …

May 12, 2025
CVE-2025-47271

The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In versions …

May 12, 2025
CVE-2025-47270
7.5 HIGH

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. The `nimiq-network-libp2p` subcrate of nimiq/core-rs-albatross is vulnerable to a …

May 12, 2025
CVE-2025-46729

julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web their DVD collections maintained with Invelos's DVDProfiler software. …

May 12, 2025
CVE-2025-32390
8.5 HIGH

EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to complete page defacement …

May 12, 2025
CVE-2025-22247
6.1 MEDIUM

VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger …

May 12, 2025
CVE-2025-1533

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash …

May 12, 2025
CVE-2025-41393
6.1 MEDIUM

Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may …

May 12, 2025
CVE-2025-3496
7.5 HIGH

An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluetooth or RS-232 interface.

May 12, 2025
CVE-2025-4561
8.8 HIGH

The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell backdoors, thereby enabling …

May 12, 2025
CVE-2025-4560
6.5 MEDIUM

The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system functions. These functions include viewing the administrator list, …

May 12, 2025
CVE-2025-4559
9.8 CRITICAL

The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

May 12, 2025
CVE-2025-3649
6.8 MEDIUM

The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role …

May 12, 2025
CVE-2025-3597
5.9 MEDIUM

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is …

May 12, 2025
CVE-2025-4558
9.8 CRITICAL

The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password …

May 12, 2025
CVE-2025-4557
9.1 CRITICAL

The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate …

May 12, 2025
CVE-2025-4556
9.8 CRITICAL

The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and …

May 12, 2025
CVE-2025-4555
9.8 CRITICAL

The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system …

May 12, 2025
CVE-2025-4554
7.3 HIGH

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

May 12, 2025
CVE-2025-4553
7.3 HIGH

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

May 12, 2025
CVE-2025-4552
5.4 MEDIUM

A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

May 12, 2025
CVE-2025-4551
3.5 LOW

A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/common/file. The …

May 11, 2025
CVE-2025-4550
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Apartment Visitors Management System 1.0. This issue affects some unknown processing of the …

May 11, 2025
CVE-2025-4549
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/register-router.php. The manipulation …

May 11, 2025
CVE-2025-4548
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unknown part of the file /routers/router.php. The …

May 11, 2025
CVE-2025-4547
2.4 LOW

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown …

May 11, 2025
CVE-2025-4546
4.7 MEDIUM

A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 11, 2025
CVE-2025-4545
5.4 MEDIUM

A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\controllers\admin\Tpl.php …

May 11, 2025
CVE-2025-4544
6.6 MEDIUM

A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of …

May 11, 2025
CVE-2025-4543
7.3 HIGH

A vulnerability, which was classified as critical, was found in LyLme Spage 2.1. This affects an unknown part of the file lylme_spage/blob/master/admin/ajax_link.php. The manipulation of …

May 11, 2025
CVE-2025-4542
3.1 LOW

A vulnerability, which was classified as problematic, has been found in Freeebird Hotel 酒店管理系统 API up to 1.2. Affected by this issue is some unknown …

May 11, 2025
CVE-2025-4541
6.3 MEDIUM

A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\admin\ZtAction.class.php of the component POST Request …

May 11, 2025
CVE-2025-4540
7.0 HIGH

A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects some unknown processing of the component …

May 11, 2025
CVE-2025-4539
7.0 HIGH

A vulnerability was found in Hainan ToDesk 4.7.6.3. It has been declared as critical. This vulnerability affects unknown code in the library profapi.dll of the …

May 11, 2025
CVE-2025-4538
6.3 MEDIUM

A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of …

May 11, 2025
CVE-2025-4537
3.1 LOW

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some unknown functionality of the file …

May 11, 2025
CVE-2025-4536
5.3 MEDIUM

A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classified as critical. Affected by this vulnerability is an unknown …

May 11, 2025
CVE-2025-4535
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0. Affected is an unknown function of the …

May 11, 2025
CVE-2025-4534
3.7 LOW

A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak …

May 11, 2025
CVE-2025-4533
2.7 LOW

A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component …

May 11, 2025
CVE-2025-4532
7.0 HIGH

A vulnerability classified as critical has been found in Shanghai Bairui Information Technology SunloginClient 15.8.3.19819. This affects an unknown part in the library process.dll of …

May 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.