CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29879
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29878
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29875
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29874
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-22483
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Aug 29, 2025
CVE-2024-12923
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the …

Aug 29, 2025
CVE-2025-9656
4.3 MEDIUM

A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the …

Aug 29, 2025
CVE-2025-55750
6.5 MEDIUM

Gitpod is a developer platform for cloud development environments. In versions before main-gha.33628 for both Gitpod Classic and Gitpod Classic Enterprise, OAuth integration with Bitbucket …

Aug 29, 2025
CVE-2025-55202
5.3 MEDIUM

Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections …

Aug 29, 2025
CVE-2025-55177
5.4 MEDIUM KEV

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could …

Aug 29, 2025
CVE-2025-54877
5.3 MEDIUM

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise …

Aug 29, 2025
CVE-2025-9654
6.3 MEDIUM

A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simple.mjs. Performing …

Aug 29, 2025
CVE-2025-55304
5.5 MEDIUM

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was …

Aug 29, 2025
CVE-2025-54080
5.5 MEDIUM

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read …

Aug 29, 2025
CVE-2025-9651
6.3 MEDIUM

A vulnerability was found in shafhasan chatbox up to 156a39cde62f78532c3265a70eda12c70907e56f. This impacts an unknown function of the file /chat.php. The manipulation of the argument user_id …

Aug 29, 2025
CVE-2025-9650
5.4 MEDIUM

A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This affects the function removeFileByPath of the file src/main/java/com/yeqifu/sys/utils/AppFileUtils.java. The manipulation of the argument …

Aug 29, 2025
CVE-2025-9647
4.3 MEDIUM

A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the …

Aug 29, 2025
CVE-2025-40709
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input …

Aug 29, 2025
CVE-2025-40708
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input …

Aug 29, 2025
CVE-2025-40707
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input …

Aug 29, 2025
CVE-2025-40706
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input …

Aug 29, 2025
CVE-2025-40705
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input …

Aug 29, 2025
CVE-2025-40704
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input …

Aug 29, 2025
CVE-2025-40703
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input …

Aug 29, 2025
CVE-2025-40702
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input …

Aug 29, 2025
CVE-2025-9217
6.5 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. …

Aug 29, 2025
CVE-2025-8150
6.4 MEDIUM

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter and Countdown widgets in all versions up …

Aug 29, 2025
CVE-2024-13987
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or …

Aug 29, 2025
CVE-2025-54777
4.3 MEDIUM

Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Email certificate, it may cause a …

Aug 29, 2025
CVE-2025-9441
6.5 MEDIUM

The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all versions up to, and including, 1.2 …

Aug 29, 2025
CVE-2025-9374
4.3 MEDIUM

The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due …

Aug 29, 2025
CVE-2025-8619
6.4 MEDIUM

The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map Block URL in all versions up …

Aug 29, 2025
CVE-2025-8290
6.4 MEDIUM

The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.0.6 due …

Aug 29, 2025
CVE-2025-8147
4.3 MEDIUM

The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscache_activatePlugin() function in all versions up to, …

Aug 29, 2025
CVE-2025-53507
6.5 MEDIUM

Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration information, such as admin password, may be disclosed. …

Aug 29, 2025
CVE-2025-9619
5.3 MEDIUM

A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of the file /basico/webservice/imprimir-danfe/id/. Performing manipulation …

Aug 29, 2025
CVE-2025-9609
6.3 MEDIUM

A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulation results in improper authorization. …

Aug 29, 2025
CVE-2025-9608
6.3 MEDIUM

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/view of the component Formula de …

Aug 29, 2025
CVE-2025-9607
6.3 MEDIUM

A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/TabelaArredondamento/view of the …

Aug 29, 2025
CVE-2025-9606
6.3 MEDIUM

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing manipulation of …

Aug 29, 2025
CVE-2025-39246
5.3 MEDIUM

There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via …

Aug 29, 2025
CVE-2025-39245
4.7 MEDIUM

There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.

Aug 29, 2025
CVE-2025-9603
6.3 MEDIUM

A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname …

Aug 29, 2025
CVE-2025-9602
6.3 MEDIUM

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. …

Aug 29, 2025
CVE-2025-54142
4.0 MEDIUM

Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within …

Aug 29, 2025
CVE-2025-43284
5.5 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app …

Aug 29, 2025
CVE-2024-54568
4.3 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may lead to an …

Aug 29, 2025
CVE-2024-54554
5.5 MEDIUM

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive …

Aug 29, 2025
CVE-2025-9595
4.3 MEDIUM

A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of …

Aug 29, 2025
CVE-2025-58061
5.5 MEDIUM

OpenEBS Local PV RawFile allows dynamic deployment of Stateful Persistent Node-Local Volumes & Filesystems for Kubernetes. Prior to version 0.10.0, persistent volume data is world …

Aug 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.