CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3794
5.4 MEDIUM

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 9, 2025
CVE-2025-4494
7.3 HIGH

A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component …

May 9, 2025
CVE-2025-4492
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Campcodes Online Food Ordering System 1.0. This issue affects some unknown processing of the …

May 9, 2025
CVE-2025-4491
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/ticket-status.php. The manipulation …

May 9, 2025
CVE-2025-4490
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unknown part of the file /view-ticket-admin.php. The …

May 9, 2025
CVE-2025-4489
7.3 HIGH

A vulnerability was found in Campcodes Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

May 9, 2025
CVE-2025-4447
7.8 HIGH

In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file …

May 9, 2025
CVE-2025-47269
8.3 HIGH

code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result …

May 9, 2025
CVE-2025-4488
7.3 HIGH

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 9, 2025
CVE-2025-4487
7.3 HIGH

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=delete_member. …

May 9, 2025
CVE-2025-4486
7.3 HIGH

A vulnerability was found in itsourcecode Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_plan. The …

May 9, 2025
CVE-2025-4485
7.3 HIGH

A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=delete_trainer. The …

May 9, 2025
CVE-2025-4484
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Gym Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_user. The …

May 9, 2025
CVE-2025-4483
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. Affected by this issue is some unknown functionality of …

May 9, 2025
CVE-2025-4482
7.3 HIGH

A vulnerability classified as critical was found in Project Worlds Student Project Allocation System 1.0. Affected by this vulnerability is an unknown functionality of the …

May 9, 2025
CVE-2025-1993
5.1 MEDIUM

IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, …

May 9, 2025
CVE-2025-4481
7.3 HIGH

A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

May 9, 2025
CVE-2025-4480
5.3 MEDIUM

A vulnerability was found in code-projects Simple College Management System 1.0. It has been declared as critical. This vulnerability affects the function input of the …

May 9, 2025
CVE-2025-46192
9.8 CRITICAL

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.

May 9, 2025
CVE-2025-46191
9.8 CRITICAL

Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to …

May 9, 2025
CVE-2025-46190
9.8 CRITICAL

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.

May 9, 2025
CVE-2025-29509
8.8 HIGH

Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening …

May 9, 2025
CVE-2025-1278
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions …

May 9, 2025
CVE-2025-0549
6.8 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 …

May 9, 2025
CVE-2024-8973
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 …

May 9, 2025
CVE-2025-4432
5.3 MEDIUM

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows …

May 9, 2025
CVE-2025-46193
9.8 CRITICAL

SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.

May 9, 2025
CVE-2025-46189
9.8 CRITICAL

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.

May 9, 2025
CVE-2025-46188
9.8 CRITICAL

SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.

May 9, 2025
CVE-2025-45513
9.8 CRITICAL

Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.

May 9, 2025
CVE-2025-28203
8.8 HIGH

Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.

May 9, 2025
CVE-2025-28202
8.8 HIGH

Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.

May 9, 2025
CVE-2025-28201
6.8 MEDIUM

An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.

May 9, 2025
CVE-2025-28200
9.8 CRITICAL

Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.

May 9, 2025
CVE-2024-9524
7.8 HIGH

Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime Version 1.1.96.2 on Windows 10 x64 allows local attackers …

May 9, 2025
CVE-2024-13962
7.8 HIGH

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers …

May 9, 2025
CVE-2024-13961
7.8 HIGH

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges …

May 9, 2025
CVE-2024-13960
7.8 HIGH

Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges …

May 9, 2025
CVE-2024-13959
7.8 HIGH

Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitrary code in …

May 9, 2025
CVE-2024-13944
7.8 HIGH

Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges …

May 9, 2025
CVE-2024-13759
7.8 HIGH

Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64 allows local attackers to gain system-level privileges via arbitrary file deletion

May 9, 2025
CVE-2025-45887
9.1 CRITICAL

Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.

May 9, 2025
CVE-2025-45885
9.8 CRITICAL

PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and …

May 9, 2025
CVE-2024-12442
9.8 CRITICAL

EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.

May 9, 2025
CVE-2024-11861
9.8 CRITICAL

EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.

May 9, 2025
CVE-2025-4382
5.9 MEDIUM

A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys …

May 9, 2025
CVE-2025-4206
7.2 HIGH

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deletion due to …

May 9, 2025
CVE-2025-3897
5.9 MEDIUM

The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' function. This makes …

May 9, 2025
CVE-2025-3528
8.2 HIGH

A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the …

May 9, 2025
CVE-2025-1087

Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation …

May 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.