CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23376
2.3 LOW

Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged …

Apr 28, 2025
CVE-2025-23375
7.8 HIGH

Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit …

Apr 28, 2025
CVE-2015-2079
9.9 CRITICAL

Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.

Apr 28, 2025
CVE-2025-4023
7.3 HIGH

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Apr 28, 2025
CVE-2025-4022
6.3 MEDIUM

A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file …

Apr 28, 2025
CVE-2025-4021
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 28, 2025
CVE-2025-4020
7.3 HIGH

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

Apr 28, 2025
CVE-2025-46661
10.0 CRITICAL

IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection. All instances have …

Apr 28, 2025
CVE-2025-32472
5.3 MEDIUM

The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowloris-type attack, causing the …

Apr 28, 2025
CVE-2025-4019
7.3 HIGH

A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file novel-admin/src/main/java/com/java2nb/common/controller/GeneratorController.java. The …

Apr 28, 2025
CVE-2025-4018
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file …

Apr 28, 2025
CVE-2025-4017
4.3 MEDIUM

A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This vulnerability affects the function list of the file nnovel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation …

Apr 28, 2025
CVE-2025-4016
5.4 MEDIUM

A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIndex of the file novel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation …

Apr 28, 2025
CVE-2025-4015
5.3 MEDIUM

A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of …

Apr 28, 2025
CVE-2025-4014
7.3 HIGH

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 28, 2025
CVE-2025-3200
9.1 CRITICAL

An unauthenticated remote attacker could exploit the used, insecure TLS 1.0 and TLS 1.1 protocols to intercept and manipulate encrypted communications between the Com-Server and …

Apr 28, 2025
CVE-2025-4013
7.3 HIGH

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Apr 28, 2025
CVE-2025-4012
2.7 LOW

A vulnerability was found in playeduxyz PlayEdu 开源培训系统 up to 1.8 and classified as problematic. This issue affects some unknown processing of the file /api/backend/v1/user/create …

Apr 28, 2025
CVE-2025-4011
3.5 LOW

A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation …

Apr 28, 2025
CVE-2025-42598
7.8 HIGH

Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than …

Apr 28, 2025
CVE-2025-39367
5.3 MEDIUM

Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4.

Apr 28, 2025
CVE-2025-32471
3.7 LOW

The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.

Apr 28, 2025
CVE-2025-32470
7.5 HIGH

A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.

Apr 28, 2025
CVE-2025-4007
8.8 HIGH

A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vulnerability is the function cgidhcpsCfgSet of the file /goform/modules …

Apr 28, 2025
CVE-2025-22235
7.3 HIGH

EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may …

Apr 28, 2025
CVE-2025-4006
4.7 MEDIUM

A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the file /admin/theme/Upload.html of the component Document …

Apr 28, 2025
CVE-2025-4005
7.3 HIGH

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 28, 2025
CVE-2025-4004
7.3 HIGH

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 28, 2025
CVE-2025-4003
5.5 MEDIUM

A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects the function InternalApfsTranslateBlock of the file Library/RP_ApfsLib/RP_ApfsIo.c. The manipulation …

Apr 28, 2025
CVE-2025-0627
3.5 LOW

The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high …

Apr 28, 2025
CVE-2024-9771
3.5 LOW

The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Apr 28, 2025
CVE-2024-13688
5.3 MEDIUM

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection …

Apr 28, 2025
CVE-2025-4002
5.5 MEDIUM

A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB and classified as problematic. Affected by this issue is the function GetDebugLogFile of the file Library/MemLogLib/BootLog.c. The …

Apr 28, 2025
CVE-2025-4001
3.3 LOW

A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability is the function main of the …

Apr 28, 2025
CVE-2025-4000
3.5 LOW

A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function of the …

Apr 28, 2025
CVE-2025-3999
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unknown processing …

Apr 28, 2025
CVE-2025-3998
7.3 HIGH

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of …

Apr 28, 2025
CVE-2025-3997
4.3 MEDIUM

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-profile-ajax-1 of the component Personal …

Apr 28, 2025
CVE-2025-3996
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Apr 28, 2025
CVE-2025-3706
6.1 MEDIUM

The eHRMS from 104 Corporation has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Apr 28, 2025
CVE-2025-3995
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Apr 28, 2025
CVE-2025-3994
2.4 LOW

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unknown function of the file /home.htm of the …

Apr 28, 2025
CVE-2025-3993
8.8 HIGH

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of …

Apr 28, 2025
CVE-2025-3992
8.8 HIGH

A vulnerability has been found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWlwds. The manipulation of …

Apr 28, 2025
CVE-2025-3991
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boafrm/formWdsEncrypt. The manipulation of …

Apr 28, 2025
CVE-2025-31144
5.8 MEDIUM

Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker …

Apr 28, 2025
CVE-2025-27937
6.5 MEDIUM

Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an …

Apr 28, 2025
CVE-2025-26692
8.1 HIGH

Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary …

Apr 28, 2025
CVE-2025-3990
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this issue is some unknown functionality of the file …

Apr 27, 2025
CVE-2025-3989
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is an unknown functionality of the file /boafrm/formStaticDHCP. The manipulation …

Apr 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.