CVE Database

10779+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29709
9.8 CRITICAL

SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.

Apr 16, 2025
CVE-2025-29708
9.8 CRITICAL

SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.

Apr 16, 2025
CVE-2024-55372
9.8 CRITICAL

Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The …

Apr 16, 2025
CVE-2024-55371
9.8 CRITICAL

Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. …

Apr 16, 2025
CVE-2025-31201
9.8 CRITICAL KEV

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS …

Apr 16, 2025
CVE-2025-31200
9.8 CRITICAL KEV

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, …

Apr 16, 2025
CVE-2025-27540
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-27539
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2025-27495
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used …

Apr 16, 2025
CVE-2024-40073
9.8 CRITICAL

Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.

Apr 16, 2025
CVE-2024-40072
9.8 CRITICAL

Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.

Apr 16, 2025
CVE-2024-40071
9.8 CRITICAL

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code …

Apr 16, 2025
CVE-2025-39601
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & PHP: from …

Apr 16, 2025
CVE-2025-39557
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Upload a Web Shell to a Web Server.This issue …

Apr 16, 2025
CVE-2024-22036
9.1 CRITICAL

A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail and gain root access …

Apr 16, 2025
CVE-2025-3495
9.8 CRITICAL

Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and …

Apr 16, 2025
CVE-2025-30215
9.6 CRITICAL

NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.27 and 2.11.1, …

Apr 16, 2025
CVE-2025-30967
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.

Apr 15, 2025
CVE-2025-30510
9.8 CRITICAL

An attacker can upload an arbitrary file instead of a plant image.

Apr 15, 2025
CVE-2025-26927
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to a Web Server.This issue affects AI …

Apr 15, 2025
CVE-2025-24297
9.8 CRITICAL

Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.

Apr 15, 2025
CVE-2025-30727
9.8 CRITICAL

Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated …

Apr 15, 2025
CVE-2025-32445
9.9 CRITICAL

Argo Events is an event-driven workflow automation framework for Kubernetes. A user with permission to create/modify EventSource and Sensor custom resources can gain privileged access …

Apr 15, 2025
CVE-2025-30206
9.8 CRITICAL

Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, …

Apr 15, 2025
CVE-2025-2567
9.8 CRITICAL

An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling of ATG monitoring. This would result in potential …

Apr 15, 2025
CVE-2025-28399
9.8 CRITICAL

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

Apr 15, 2025
CVE-2025-25456
9.8 CRITICAL

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.

Apr 15, 2025
CVE-2025-22900
9.8 CRITICAL

Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.

Apr 15, 2025
CVE-2025-28100
9.8 CRITICAL

A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.

Apr 15, 2025
CVE-2021-27289
9.1 CRITICAL

A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion …

Apr 15, 2025
CVE-2025-32911
9.0 CRITICAL

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the …

Apr 15, 2025
CVE-2025-28137
9.8 CRITICAL

The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

Apr 15, 2025
CVE-2025-30985
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4.

Apr 15, 2025
CVE-2025-24797
9.4 CRITICAL

Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protobuf data can result in an attacker-controlled …

Apr 15, 2025
CVE-2025-3277
9.8 CRITICAL

An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes …

Apr 14, 2025
CVE-2025-32931
9.1 CRITICAL

DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan …

Apr 14, 2025
CVE-2025-3439
9.8 CRITICAL

The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in …

Apr 11, 2025
CVE-2025-23391
9.1 CRITICAL

A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue …

Apr 11, 2025
CVE-2025-32607
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Injection.This issue affects WpBookingly: from n/a through <= 1.3.0.

Apr 11, 2025
CVE-2025-32603
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK WP Online Users Stats wp-online-users-stats allows Blind SQL Injection.This issue …

Apr 11, 2025
CVE-2025-32579
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects …

Apr 11, 2025
CVE-2025-32577
9.8 CRITICAL

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online build-app-online allows PHP Local File …

Apr 11, 2025
CVE-2025-32569
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in RealMag777 TableOn posts-table-filterable allows Object Injection.This issue affects TableOn: from n/a through <= 1.0.4.3.

Apr 11, 2025
CVE-2025-32568
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce empik-for-woocommerce allows Object Injection.This issue affects EmpikPlace for Woocommerce: from n/a through <= 1.4.3.

Apr 11, 2025
CVE-2025-32565
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-woocommerce allows SQL Injection.This issue affects Neon …

Apr 11, 2025
CVE-2025-32491
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO – On-site SEO rankology-seo-all-in-one-seo-analytics allows Privilege Escalation.This issue affects Rankology SEO – On-site SEO: from n/a through …

Apr 11, 2025
CVE-2025-31599
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync sync-wc-google allows SQL Injection.This issue affects Bulk …

Apr 11, 2025
CVE-2025-31565
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisandro Martinez WPSmartContracts wp-smart-contracts allows Blind SQL Injection.This issue affects WPSmartContracts: …

Apr 11, 2025
CVE-2025-32743
9.0 CRITICAL

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set …

Apr 10, 2025
CVE-2025-32755
9.1 CRITICAL

In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, causing all containers based on …

Apr 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.