CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4531
6.3 MEDIUM

A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected by this issue is the …

May 11, 2025
CVE-2025-4530
4.3 MEDIUM

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. It has been declared as problematic. Affected by this vulnerability is the function handleFileDownload of …

May 11, 2025
CVE-2025-4529
4.3 MEDIUM

A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been classified as problematic. Affected is the function Download of …

May 11, 2025
CVE-2025-4528
4.3 MEDIUM

A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic. This issue affects some unknown processing. The manipulation leads to …

May 11, 2025
CVE-2025-4527
3.7 LOW

A vulnerability has been found in Dígitro NGC Explorer 3.44.15 and classified as problematic. This vulnerability affects unknown code of the component Password Transmission Handler. …

May 11, 2025
CVE-2025-47828
6.4 MEDIUM

Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.

May 11, 2025
CVE-2025-4526
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Dígitro NGC Explorer 3.44.15. This affects an unknown part of the component Configuration Page. The …

May 11, 2025
CVE-2025-4525
7.0 HIGH

A vulnerability, which was classified as critical, has been found in Discord 1.0.9188 on Windows. Affected by this issue is some unknown functionality in the …

May 10, 2025
CVE-2025-47817
8.8 HIGH

In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.

May 10, 2025
CVE-2025-47816
2.9 LOW

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.

May 10, 2025
CVE-2025-47815
4.5 MEDIUM

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.

May 10, 2025
CVE-2025-47814
4.5 MEDIUM

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.

May 10, 2025
CVE-2025-4515
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The …

May 10, 2025
CVE-2025-4514
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Zhengzhou Jiuhua Electronic Technology mayicms up to 5.8E. Affected by this issue is some …

May 10, 2025
CVE-2025-4513
4.3 MEDIUM

A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of …

May 10, 2025
CVE-2025-4512
4.3 MEDIUM

A vulnerability classified as problematic has been found in Inetum IODAS 7.2-LTS.4.1-JDK7/7.2-RC3.2-JDK7. Affected is an unknown function of the file /astre/iodasweb/app.jsp. The manipulation of the …

May 10, 2025
CVE-2025-4511
6.3 MEDIUM

A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file …

May 10, 2025
CVE-2025-4510
6.3 MEDIUM

A vulnerability was found in Changjietong UFIDA CRM 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /optnty/optntyday.php. The …

May 10, 2025
CVE-2025-4509
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul e-Diary Management System 1.0. This issue affects some unknown processing of the file …

May 10, 2025
CVE-2025-4508
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. This vulnerability affects unknown code of the file /my-profile.php. The manipulation of …

May 10, 2025
CVE-2025-4507
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unknown part of the file /routers/add-item.php. The …

May 10, 2025
CVE-2025-4506
7.3 HIGH

A vulnerability was found in Campcodes Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

May 10, 2025
CVE-2025-4505
7.3 HIGH

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 10, 2025
CVE-2025-4504
7.3 HIGH

A vulnerability was found in SourceCodester Online College Library System 1.0. It has been classified as critical. Affected is an unknown function of the file …

May 10, 2025
CVE-2023-53145
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition In btsdio_probe, …

May 10, 2025
CVE-2025-4503
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/customer_update.php. …

May 10, 2025
CVE-2025-4502
7.3 HIGH

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/creditor_add.php. …

May 10, 2025
CVE-2025-1752
7.5 HIGH

A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due …

May 10, 2025
CVE-2025-4501
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects the function searchalbum of the component Search Albums. …

May 10, 2025
CVE-2025-4500
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected by this issue is the function Edit of …

May 10, 2025
CVE-2025-4499
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component …

May 10, 2025
CVE-2025-3878
6.4 MEDIUM

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up …

May 10, 2025
CVE-2025-3876
8.8 HIGH

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function …

May 10, 2025
CVE-2025-4498
5.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. …

May 10, 2025
CVE-2025-2158
8.8 HIGH

The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all versions up …

May 10, 2025
CVE-2025-4497
5.3 MEDIUM

A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of …

May 10, 2025
CVE-2025-2944
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button and Countdown Widgets in all versions up …

May 10, 2025
CVE-2025-4496
8.8 HIGH

A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the …

May 10, 2025
CVE-2025-47770

Rejected reason: Not used

May 10, 2025
CVE-2025-47769

Rejected reason: Not used

May 10, 2025
CVE-2025-47768

Rejected reason: Not used

May 10, 2025
CVE-2025-47767

Rejected reason: Not used

May 10, 2025
CVE-2025-47766

Rejected reason: Not used

May 10, 2025
CVE-2025-47765

Rejected reason: Not used

May 10, 2025
CVE-2025-47764

Rejected reason: Not used

May 10, 2025
CVE-2025-47763

Rejected reason: Not used

May 10, 2025
CVE-2025-47762

Rejected reason: Not used

May 10, 2025
CVE-2025-1137
7.5 HIGH

IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization.

May 10, 2025
CVE-2025-4495
3.5 LOW

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. …

May 10, 2025
CVE-2025-47424
7.1 HIGH

Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host header can be manipulated.

May 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.