CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-45250
5.5 MEDIUM

MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.

May 6, 2025
CVE-2025-32022
4.6 MEDIUM

Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot which leads to it overwriting other parts …

May 6, 2025
CVE-2025-30165
8.0 HIGH

vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some …

May 6, 2025
CVE-2025-26262
6.5 MEDIUM

An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a …

May 6, 2025
CVE-2025-22476
5.5 MEDIUM

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

May 6, 2025
CVE-2023-33770
5.1 MEDIUM

Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php.

May 6, 2025
CVE-2025-4384

The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows …

May 6, 2025
CVE-2025-4368
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC8 16.03.34.06. Affected is the function formGetRouterStatus of the file /goform/MtuSetMacWan. The manipulation of …

May 6, 2025
CVE-2025-4363
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. This issue affects some unknown processing of the file …

May 6, 2025
CVE-2025-45492
9.8 CRITICAL

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.

May 6, 2025
CVE-2025-45491
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

May 6, 2025
CVE-2025-45490
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.

May 6, 2025
CVE-2025-45489
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.

May 6, 2025
CVE-2025-45488
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

May 6, 2025
CVE-2025-45487
9.8 CRITICAL

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

May 6, 2025
CVE-2025-23379
3.5 LOW

Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker …

May 6, 2025
CVE-2025-22479
3.5 LOW

Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated …

May 6, 2025
CVE-2025-22478
8.1 HIGH

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network …

May 6, 2025
CVE-2025-22477
8.3 HIGH

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this …

May 6, 2025
CVE-2025-4374
6.5 MEDIUM

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been …

May 6, 2025
CVE-2025-4373
4.8 MEDIUM

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the …

May 6, 2025
CVE-2025-4362
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_membership. The manipulation of …

May 6, 2025
CVE-2025-4361
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. This affects an unknown part of the file /department.php. The …

May 6, 2025
CVE-2025-4360
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0. Affected by this issue is some unknown functionality of …

May 6, 2025
CVE-2025-46814
3.4 LOW

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. An HTTP header injection vulnerability …

May 6, 2025
CVE-2025-2898
7.5 HIGH

IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulnerability in …

May 6, 2025
CVE-2025-4359
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_member. …

May 6, 2025
CVE-2025-4358
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /admin-profile.php. The …

May 6, 2025
CVE-2025-4357
4.7 MEDIUM

A vulnerability was found in Tenda RX3 16.03.13.11_multi. It has been rated as critical. This issue affects some unknown processing of the file /goform/telnet. The …

May 6, 2025
CVE-2025-4356
8.8 HIGH

A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been declared as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of …

May 6, 2025
CVE-2025-4355
8.8 HIGH

A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02. It has been classified as critical. This affects the function set_ws_action of the file /dws/api/. The manipulation …

May 6, 2025
CVE-2025-4354
8.8 HIGH

A vulnerability was found in Tenda DAP-1520 1.10B04_BETA02 and classified as critical. Affected by this issue is the function check_dws_cookie of the file /storage. The …

May 6, 2025
CVE-2018-1359

Rejected reason: Not used

May 6, 2025
CVE-2025-4353
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Brilliance Golden Link Secondary System up to 20250424. Affected is an unknown function of the …

May 6, 2025
CVE-2025-4352
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250424. This issue affects some unknown processing …

May 6, 2025
CVE-2025-4350
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the function wake_on_lan. The manipulation of the argument host …

May 6, 2025
CVE-2025-4349
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects the function formSysCmd. The manipulation of the argument host …

May 6, 2025
CVE-2025-0984
8.2 HIGH

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netoloji Software E-Flow allows …

May 6, 2025
CVE-2025-4348
8.8 HIGH

A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been rated as critical. Affected by this issue is the function formSetWanL2TP. The …

May 6, 2025
CVE-2025-4347
8.8 HIGH

A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been declared as critical. Affected by this vulnerability is the function formWlSiteSurvey. The …

May 6, 2025
CVE-2025-40625
9.8 CRITICAL

Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to …

May 6, 2025
CVE-2025-40624
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-40623
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-40622
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-40621
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-40620
9.8 CRITICAL

SQL injection in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to inject an SQL statement to obtain, update and delete all information in …

May 6, 2025
CVE-2025-4346
8.8 HIGH

A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been classified as critical. Affected is the function formSetWAN_Wizard534. The manipulation of the …

May 6, 2025
CVE-2025-4345
8.8 HIGH

A vulnerability was found in D-Link DIR-600L up to 2.07B01 and classified as critical. This issue affects the function formSetLog. The manipulation of the argument …

May 6, 2025
CVE-2025-4344
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-600L up to 2.07B01. This affects the function formLogin. The manipulation of the argument …

May 6, 2025
CVE-2025-46762
8.1 HIGH

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 introduced a fix …

May 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.