CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-45751
6.1 MEDIUM

SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.

May 5, 2025
CVE-2025-28168
6.4 MEDIUM

The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced …

May 5, 2025
CVE-2025-2545

Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with …

May 5, 2025
CVE-2025-4272
7.0 HIGH

A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the …

May 5, 2025
CVE-2025-2905
9.1 CRITICAL

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 …

May 5, 2025
CVE-2025-4271
5.3 MEDIUM

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

May 5, 2025
CVE-2025-4270
5.3 MEDIUM

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the …

May 5, 2025
CVE-2025-4269
6.5 MEDIUM

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component …

May 5, 2025
CVE-2025-4268
5.3 MEDIUM

A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation of …

May 5, 2025
CVE-2025-4267
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchase_order/view_po of …

May 5, 2025
CVE-2025-4266
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. Affected by this issue is some unknown functionality of …

May 5, 2025
CVE-2025-3583
4.8 MEDIUM

The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 5, 2025
CVE-2025-39363
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Stored XSS.This issue affects Custom Login and …

May 5, 2025
CVE-2025-4265
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file …

May 5, 2025
CVE-2025-4264
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/edit-ambulance.php. The …

May 5, 2025
CVE-2025-4263
7.3 HIGH

A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

May 5, 2025
CVE-2025-4262
7.3 HIGH

A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

May 5, 2025
CVE-2025-4261
5.3 MEDIUM

A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as critical. This affects the function run_single of the file factool/factool/math/tool.py. …

May 5, 2025
CVE-2025-4260
4.3 MEDIUM

A vulnerability was found in zhangyanbo2007 youkefu up to 4.2.0 and classified as problematic. Affected by this issue is the function impsave of the file …

May 5, 2025
CVE-2025-4259
6.3 MEDIUM

A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The …

May 5, 2025
CVE-2025-20671
7.0 HIGH

In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a …

May 5, 2025
CVE-2025-20670
5.7 MEDIUM

In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has connected …

May 5, 2025
CVE-2025-20668
7.8 HIGH

In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

May 5, 2025
CVE-2025-20667
7.5 HIGH

In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote information disclosure, if a UE has connected …

May 5, 2025
CVE-2025-20666
7.5 HIGH

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has …

May 5, 2025
CVE-2025-20665
5.5 MEDIUM

In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with …

May 5, 2025
CVE-2025-4273

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 5, 2025
CVE-2025-4258
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master\src\main\java\com\ukefu\webim\web\handler\resource\MediaController.java. The …

May 5, 2025
CVE-2025-4257
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pay.php. The manipulation …

May 5, 2025
CVE-2025-4256
3.5 LOW

A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus …

May 5, 2025
CVE-2025-4255
7.3 HIGH

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RMD Command Handler. The …

May 5, 2025
CVE-2025-4254
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the …

May 5, 2025
CVE-2025-4253
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

May 4, 2025
CVE-2025-4252
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function of the component APPEND Command …

May 4, 2025
CVE-2025-4251
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. This issue affects some unknown processing of the component RMDIR Command Handler. …

May 4, 2025
CVE-2025-4250
7.3 HIGH

A vulnerability was found in code-projects Nero Social Networking Site 1.0. It has been classified as critical. This affects an unknown part of the file …

May 4, 2025
CVE-2025-4249
7.3 HIGH

A vulnerability was found in PHPGurukul e-Diary Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

May 4, 2025
CVE-2025-4248
6.3 MEDIUM

A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

May 4, 2025
CVE-2025-4247
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is an unknown function of the file /delete_task.php. …

May 4, 2025
CVE-2025-47245
8.1 HIGH

In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.

May 4, 2025
CVE-2025-47244
7.3 HIGH

Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when …

May 3, 2025
CVE-2025-47241
4.0 MEDIUM

In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.

May 3, 2025
CVE-2025-4244
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This affects an unknown part of the file /seatlocation.php. …

May 3, 2025
CVE-2025-4243
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Affected by this issue is some unknown functionality …

May 3, 2025
CVE-2025-4242
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vulnerability is an unknown functionality of the file …

May 3, 2025
CVE-2025-1838
6.5 MEDIUM

IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user to bypass client-side data validation in an authoring …

May 3, 2025
CVE-2025-4241
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/search.php. …

May 3, 2025
CVE-2025-4240
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component LCD …

May 3, 2025
CVE-2025-4239
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component TYPE Command …

May 3, 2025
CVE-2025-4238
7.3 HIGH

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component MGET Command …

May 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.