CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8772
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Vinades NukeViet up to 4.5.06. This issue affects some unknown processing of the file …

Aug 9, 2025
CVE-2025-8764
6.3 MEDIUM

A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upload. The manipulation …

Aug 9, 2025
CVE-2025-8756
6.3 MEDIUM

A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preHandle of the …

Aug 9, 2025
CVE-2024-58238
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Resolve TX timeout error in power save stress test This fixes the tx …

Aug 9, 2025
CVE-2022-50233
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix using strlen with hdev->{dev_name,short_name} Both dev_name and short_name are not guaranteed to …

Aug 9, 2025
CVE-2025-8755
5.3 MEDIUM

A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of …

Aug 9, 2025
CVE-2025-8753
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete of …

Aug 9, 2025
CVE-2025-7726
6.4 MEDIUM

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via its lightbox rendering code in all versions up to, and including, 12.6.0 due …

Aug 9, 2025
CVE-2025-8745
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Weee RICEPO App 6.17.77 on Android. This issue affects some unknown processing of the …

Aug 9, 2025
CVE-2025-4655
5.0 MEDIUM

SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through …

Aug 9, 2025
CVE-2025-55013
4.2 MEDIUM

The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below …

Aug 9, 2025
CVE-2025-55006
4.3 MEDIUM

Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize …

Aug 9, 2025
CVE-2025-55003
5.7 MEDIUM

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's …

Aug 9, 2025
CVE-2025-55001
6.5 MEDIUM

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao …

Aug 9, 2025
CVE-2025-55000
6.5 MEDIUM

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's …

Aug 9, 2025
CVE-2025-54998
5.3 MEDIUM

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers …

Aug 9, 2025
CVE-2025-55152
5.3 MEDIUM

oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, …

Aug 9, 2025
CVE-2025-8739
4.3 MEDIUM

A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /admin/tags/save. The …

Aug 8, 2025
CVE-2025-8738
5.3 MEDIUM

A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of …

Aug 8, 2025
CVE-2025-8736
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the function yylex of …

Aug 8, 2025
CVE-2025-50928
4.8 MEDIUM

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function.

Aug 8, 2025
CVE-2025-50927
6.3 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting …

Aug 8, 2025
CVE-2025-50468
6.5 MEDIUM

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters …

Aug 8, 2025
CVE-2025-50467
6.5 MEDIUM

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDataTypeParam parameter …

Aug 8, 2025
CVE-2025-47872
5.8 MEDIUM

The public-facing product registration endpoint server responds differently depending on whether the S/N is valid and unregistered, valid but already registered, or does not exist …

Aug 8, 2025
CVE-2025-52586
6.9 MEDIUM

The MOD3 command traffic between the monitoring application and the inverter is transmitted in plaintext without encryption or obfuscation. This vulnerability may allow an attacker …

Aug 8, 2025
CVE-2025-4576
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.133, and Liferay DXP 2025.Q1.0 through 2025.Q1.4 ,2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, …

Aug 8, 2025
CVE-2025-36023
6.5 MEDIUM

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive user and …

Aug 8, 2025
CVE-2025-8729
6.3 MEDIUM

A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is the function process_cert_files of the file backend/service/upload_service.py. …

Aug 8, 2025
CVE-2025-8749
6.5 MEDIUM

Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR Robots allows authenticated users to extract files …

Aug 8, 2025
CVE-2025-6572
5.9 MEDIUM

The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does not validate and escape some of its block options …

Aug 8, 2025
CVE-2025-54959
4.3 MEDIUM

Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is exploited, an arbitrary file in the affected product may …

Aug 8, 2025
CVE-2025-54958
6.3 MEDIUM

Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is exploited, arbitrary OS commands may be executed on …

Aug 8, 2025
CVE-2024-58257
5.7 MEDIUM

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

Aug 8, 2025
CVE-2024-58256
4.5 MEDIUM

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

Aug 8, 2025
CVE-2024-58255
5.0 MEDIUM

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

Aug 8, 2025
CVE-2025-8708
5.0 MEDIUM

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of …

Aug 8, 2025
CVE-2025-8707
5.3 MEDIUM

A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unknown part of the file …

Aug 8, 2025
CVE-2025-8706
6.3 MEDIUM

A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as critical. Affected by this vulnerability is an unknown …

Aug 8, 2025
CVE-2025-8705
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Affected is an unknown function of the …

Aug 8, 2025
CVE-2025-8704
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This issue affects some unknown processing …

Aug 8, 2025
CVE-2025-8703
6.3 MEDIUM

A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This vulnerability affects unknown code of the file /WEAS_HomePage/GetAreaTrendChartData …

Aug 8, 2025
CVE-2025-54793
6.1 MEDIUM

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic …

Aug 8, 2025
CVE-2025-8702
6.3 MEDIUM

A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This affects an unknown part of the file …

Aug 8, 2025
CVE-2025-8701
6.3 MEDIUM

A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is some …

Aug 7, 2025
CVE-2025-53774
6.5 MEDIUM

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

Aug 7, 2025
CVE-2025-47808
5.6 MEDIUM

In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.

Aug 7, 2025
CVE-2025-47807
5.5 MEDIUM

In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.

Aug 7, 2025
CVE-2025-47806
5.6 MEDIUM

In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.

Aug 7, 2025
CVE-2025-47183
6.6 MEDIUM

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to …

Aug 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.