CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53249
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online build-app-online allows Cross Site Request Forgery.This issue affects Build App Online: from n/a through <= …

Aug 14, 2025
CVE-2025-53241
5.5 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in kodeshpa Simplified simplified allows Server Side Request Forgery.This issue affects Simplified: from n/a through <= 1.0.11.

Aug 14, 2025
CVE-2025-53221
4.3 MEDIUM

Missing Authorization vulnerability in codeablepress CodeablePress codeablepress-simple-frontend-profile-picture-upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CodeablePress: from n/a through <= 1.0.2.

Aug 14, 2025
CVE-2025-53219
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows Cross Site Request Forgery.This issue affects WP-Database-Optimizer-Tools: from n/a through <= 0.2.

Aug 14, 2025
CVE-2025-52771
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bcupham Video Expander video-expander allows Stored XSS.This issue affects Video Expander: from n/a …

Aug 14, 2025
CVE-2025-52769
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in flexostudio flexo-social-gallery flexo-social-gallery allows Cross Site Request Forgery.This issue affects flexo-social-gallery: from n/a through <= 1.0006.

Aug 14, 2025
CVE-2025-52767
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin allows Cross Site Request Forgery.This issue affects NetInsight Analytics Implementation Plugin: from n/a …

Aug 14, 2025
CVE-2025-52335
6.1 MEDIUM

EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information.

Aug 14, 2025
CVE-2025-21110
6.7 MEDIUM

Dell Data Lakehouse, versions prior to 1.5.0.0, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this …

Aug 14, 2025
CVE-2024-37945
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor allows Stored XSS.This issue affects …

Aug 14, 2025
CVE-2023-43687
6.5 MEDIUM

An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). There is a Race condition that leads to code …

Aug 14, 2025
CVE-2025-9039
4.3 MEDIUM

We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accessed off-host by another instance if the …

Aug 14, 2025
CVE-2025-50817
5.4 MEDIUM

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is …

Aug 14, 2025
CVE-2025-50515
6.5 MEDIUM

An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the config file was loaded.

Aug 14, 2025
CVE-2025-20306
4.9 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker with Administrator-level privileges to …

Aug 14, 2025
CVE-2025-20302
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to retrieve a generated report from …

Aug 14, 2025
CVE-2025-20301
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-privileged, remote attacker to access troubleshoot files for a …

Aug 14, 2025
CVE-2025-20268
5.8 MEDIUM

A vulnerability in the Geolocation-Based Remote Access (RA) VPN feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to …

Aug 14, 2025
CVE-2025-20254
5.8 MEDIUM

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense …

Aug 14, 2025
CVE-2025-20252
5.8 MEDIUM

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense …

Aug 14, 2025
CVE-2025-20238
6.0 MEDIUM

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker …

Aug 14, 2025
CVE-2025-20237
6.0 MEDIUM

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker …

Aug 14, 2025
CVE-2025-20235
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site …

Aug 14, 2025
CVE-2025-20225
5.8 MEDIUM

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, …

Aug 14, 2025
CVE-2025-20224
5.8 MEDIUM

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense …

Aug 14, 2025
CVE-2025-20220
6.0 MEDIUM

A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, …

Aug 14, 2025
CVE-2025-20219
5.3 MEDIUM

A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall …

Aug 14, 2025
CVE-2025-20218
4.9 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to retrieve sensitive information …

Aug 14, 2025
CVE-2025-20135
4.3 MEDIUM

A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could …

Aug 14, 2025
CVE-2023-43683
6.5 MEDIUM

An issue was discovered in Malwarebytes 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). A Stack buffer out-of-bounds access exists because of an integer …

Aug 14, 2025
CVE-2025-8965
6.3 MEDIUM

A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. …

Aug 14, 2025
CVE-2025-54409
6.2 MEDIUM

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash …

Aug 14, 2025
CVE-2025-54389
6.2 MEDIUM

AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. An attacker can craft a …

Aug 14, 2025
CVE-2025-53631
5.4 MEDIUM

flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to …

Aug 14, 2025
CVE-2025-36047
5.3 MEDIUM

IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could …

Aug 14, 2025
CVE-2025-33142
5.3 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.

Aug 14, 2025
CVE-2023-43694
5.2 MEDIUM

An issue was discovered in Malwarebytes 4.6.14.326 and before and 5.1.5.116 and before (and Nebula 2020-10-21 and later). An Out of bounds read in several …

Aug 14, 2025
CVE-2025-8964
5.3 MEDIUM

A vulnerability was identified in code-projects Hostel Management System 1.0. This affects an unknown part of the file hostel_manage.exe of the component Login. The manipulation …

Aug 14, 2025
CVE-2025-8962
5.3 MEDIUM

A vulnerability was found in code-projects Hostel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file hostel_manage.exe of the component …

Aug 14, 2025
CVE-2025-38745
4.8 MEDIUM

Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backup and Restore. A …

Aug 14, 2025
CVE-2025-38738
6.7 MEDIUM

SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installer. A low privileged attacker with local …

Aug 14, 2025
CVE-2025-36612
6.7 MEDIUM

SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this …

Aug 14, 2025
CVE-2025-27847
4.3 MEDIUM

In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout.

Aug 14, 2025
CVE-2025-27846
4.3 MEDIUM

In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected.

Aug 14, 2025
CVE-2025-26484
5.5 MEDIUM

Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could potentially …

Aug 14, 2025
CVE-2025-55675
6.5 MEDIUM

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources …

Aug 14, 2025
CVE-2025-55674
6.5 MEDIUM

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline …

Aug 14, 2025
CVE-2025-55673
4.3 MEDIUM

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This …

Aug 14, 2025
CVE-2025-55672
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload …

Aug 14, 2025
CVE-2025-8963
6.3 MEDIUM

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component …

Aug 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.