CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46780

Rejected reason: Not used

Apr 30, 2025
CVE-2025-46779

Rejected reason: Not used

Apr 30, 2025
CVE-2025-46778

Rejected reason: Not used

Apr 30, 2025
CVE-2025-46560
6.5 MEDIUM

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical …

Apr 30, 2025
CVE-2025-32444
10.0 CRITICAL

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, …

Apr 30, 2025
CVE-2025-30202
7.5 HIGH

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable to denial of …

Apr 30, 2025
CVE-2025-46552

KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a …

Apr 29, 2025
CVE-2025-3358

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 29, 2025
CVE-2025-29906
8.6 HIGH

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` …

Apr 29, 2025
CVE-2023-4377

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 29, 2025
CVE-2025-46550
4.3 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker …

Apr 29, 2025
CVE-2025-46549
4.3 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from …

Apr 29, 2025
CVE-2025-46348
10.0 CRITICAL

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without …

Apr 29, 2025
CVE-2025-46344

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke …

Apr 29, 2025
CVE-2025-3910
5.4 MEDIUM

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up …

Apr 29, 2025
CVE-2025-3501
8.2 HIGH

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

Apr 29, 2025
CVE-2025-4080
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 29, 2025
CVE-2025-4078
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. …

Apr 29, 2025
CVE-2025-0520

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue …

Apr 29, 2025
CVE-2024-57698
7.5 HIGH

An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration …

Apr 29, 2025
CVE-2025-4079
7.3 HIGH

A vulnerability, which was classified as critical, was found in PCMan FTP Server up to 2.0.7. Affected is an unknown function of the component RENAME …

Apr 29, 2025
CVE-2025-4095

Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile …

Apr 29, 2025
CVE-2025-4077
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects School Billing System 1.0. This vulnerability affects the function searchrec. The manipulation of the argument Name …

Apr 29, 2025
CVE-2025-4076
6.3 MEDIUM

A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of the file /cgi-bin/lighttpd.cgi of the …

Apr 29, 2025
CVE-2025-4075
4.3 MEDIUM

A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unknown functionality of the …

Apr 29, 2025
CVE-2025-4074
7.3 HIGH

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 29, 2025
CVE-2025-46350
3.5 LOW

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from …

Apr 29, 2025
CVE-2025-46349
7.6 HIGH

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability …

Apr 29, 2025
CVE-2025-46347
9.8 CRITICAL

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used …

Apr 29, 2025
CVE-2025-3911

Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, …

Apr 29, 2025
CVE-2025-4073
7.3 HIGH

A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. …

Apr 29, 2025
CVE-2025-4072
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-nurse.php. …

Apr 29, 2025
CVE-2025-45956
8.8 HIGH

A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" …

Apr 29, 2025
CVE-2025-23181
8.0 HIGH

CWE-250: Execution with Unnecessary Privileges

Apr 29, 2025
CVE-2025-23180
8.0 HIGH

CWE-250: Execution with Unnecessary Privileges

Apr 29, 2025
CVE-2025-0716
4.8 MEDIUM

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. …

Apr 29, 2025
CVE-2025-4071
7.3 HIGH

A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /test-details.php. …

Apr 29, 2025
CVE-2025-4070
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /admin/changeimage.php. …

Apr 29, 2025
CVE-2025-4069
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Product Management System 1.0. Affected by this issue is the function add_item. The …

Apr 29, 2025
CVE-2025-4068
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by this vulnerability is the function changeprize. The manipulation …

Apr 29, 2025
CVE-2025-46346
5.4 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, a stored cross-site scripting (XSS) vulnerability was discovered in the application’s comments feature. …

Apr 29, 2025
CVE-2025-40619
7.5 HIGH

Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach …

Apr 29, 2025
CVE-2025-40618
9.8 CRITICAL

SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the …

Apr 29, 2025
CVE-2025-40617
9.8 CRITICAL

SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the …

Apr 29, 2025
CVE-2025-40616
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL …

Apr 29, 2025
CVE-2025-40615
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL …

Apr 29, 2025
CVE-2025-32354
8.8 HIGH

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a …

Apr 29, 2025
CVE-2025-25962
9.8 CRITICAL

An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function

Apr 29, 2025
CVE-2025-25403
9.8 CRITICAL

Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.

Apr 29, 2025
CVE-2025-23179
5.5 MEDIUM

CWE-798: Use of Hard-coded Credentials

Apr 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.