CVE Database

10779+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-32754
9.1 CRITICAL

In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on …

Apr 10, 2025
CVE-2025-32206
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Server.This issue affects Processing …

Apr 10, 2025
CVE-2025-32202
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress insert-or-embed-articulate-content-into-wordpress allows Upload a Web …

Apr 10, 2025
CVE-2025-32140
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This …

Apr 10, 2025
CVE-2025-27690
9.8 CRITICAL

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, …

Apr 10, 2025
CVE-2024-58136
9.0 CRITICAL KEV

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild …

Apr 10, 2025
CVE-2024-55210
9.8 CRITICAL

An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via a crafted websocket message.

Apr 9, 2025
CVE-2025-3115
9.8 CRITICAL

Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can …

Apr 9, 2025
CVE-2025-32695
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through <= 8.7.5.

Apr 9, 2025
CVE-2025-32642
10.0 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This issue affects Vite Coupon: from n/a through <= 1.0.9.

Apr 9, 2025
CVE-2025-32641
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forgery.This issue affects Anant Addons for Elementor: from n/a …

Apr 9, 2025
CVE-2025-32576
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web Shell to a Web Server.This issue affects …

Apr 9, 2025
CVE-2025-32496
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web Shell to a Web Server.This issue affects Ultra Demo Importer: …

Apr 9, 2025
CVE-2025-31033
9.8 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in Adam Nowak Buddypress Humanity buddypress-humanity allows Cross Site Request Forgery.This issue affects Buddypress Humanity: from n/a through <= 1.2.

Apr 9, 2025
CVE-2025-31002
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Malicious Files.This issue affects Squeeze: from n/a through <= 1.6.

Apr 9, 2025
CVE-2025-32375
9.8 CRITICAL

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.8, there was an insecure deserialization …

Apr 9, 2025
CVE-2025-27797
9.8 CRITICAL

OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by …

Apr 9, 2025
CVE-2025-32461
9.9 CRITICAL

wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.

Apr 9, 2025
CVE-2025-30282
9.1 CRITICAL

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-30281
9.1 CRITICAL

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker …

Apr 8, 2025
CVE-2025-24447
9.1 CRITICAL

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the …

Apr 8, 2025
CVE-2025-24446
9.1 CRITICAL

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution. Exploitation of this …

Apr 8, 2025
CVE-2025-22871
9.1 CRITICAL

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http …

Apr 8, 2025
CVE-2025-25226
9.8 CRITICAL

Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a …

Apr 8, 2025
CVE-2024-48887
9.8 CRITICAL

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Apr 8, 2025
CVE-2025-32028
9.9 CRITICAL

HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a …

Apr 8, 2025
CVE-2024-54092
9.8 CRITICAL

A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial …

Apr 8, 2025
CVE-2024-41794
10.0 CRITICAL

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for remote access to the device operating …

Apr 8, 2025
CVE-2024-41790
9.1 CRITICAL

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the region parameter …

Apr 8, 2025
CVE-2024-41789
9.1 CRITICAL

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language parameter …

Apr 8, 2025
CVE-2024-41788
9.1 CRITICAL

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the input parameters …

Apr 8, 2025
CVE-2025-31330
9.9 CRITICAL

SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the …

Apr 8, 2025
CVE-2025-30016
9.8 CRITICAL

SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to …

Apr 8, 2025
CVE-2025-27429
9.9 CRITICAL

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of …

Apr 8, 2025
CVE-2025-2004
9.1 CRITICAL

The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpe_delete_file AJAX action in …

Apr 8, 2025
CVE-2025-3363
9.8 CRITICAL

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them …

Apr 8, 2025
CVE-2025-3362
9.8 CRITICAL

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them …

Apr 8, 2025
CVE-2025-3361
9.8 CRITICAL

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them …

Apr 8, 2025
CVE-2025-28413
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

Apr 7, 2025
CVE-2025-28412
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

Apr 7, 2025
CVE-2025-28411
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

Apr 7, 2025
CVE-2025-28410
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has …

Apr 7, 2025
CVE-2025-28408
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the …

Apr 7, 2025
CVE-2025-28406
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

Apr 7, 2025
CVE-2025-28405
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

Apr 7, 2025
CVE-2025-28402
9.8 CRITICAL

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

Apr 7, 2025
CVE-2025-3248
9.8 CRITICAL KEV

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to …

Apr 7, 2025
CVE-2025-20654
9.8 CRITICAL

In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with …

Apr 7, 2025
CVE-2025-2941
9.8 CRITICAL

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via …

Apr 5, 2025
CVE-2021-47667
10.0 CRITICAL

An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters …

Apr 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.