CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8697
6.3 MEDIUM

A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the component MCPSessionManager/MCPTool/MCPToolkit. The manipulation …

Aug 7, 2025
CVE-2025-7195
6.4 MEDIUM

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided …

Aug 7, 2025
CVE-2025-51533
5.3 MEDIUM

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.

Aug 7, 2025
CVE-2023-41529
6.1 MEDIUM

Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.

Aug 7, 2025
CVE-2023-41519
6.1 MEDIUM

Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.

Aug 7, 2025
CVE-2023-40992
6.5 MEDIUM

Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.

Aug 7, 2025
CVE-2025-54397
4.3 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.

Aug 7, 2025
CVE-2025-54396
5.4 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.

Aug 7, 2025
CVE-2025-54395
6.1 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.

Aug 7, 2025
CVE-2025-54394
5.3 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.

Aug 7, 2025
CVE-2025-54393
5.4 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.

Aug 7, 2025
CVE-2025-54392
6.1 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.

Aug 7, 2025
CVE-2024-42048
6.5 MEDIUM

OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In …

Aug 7, 2025
CVE-2025-7054
6.5 MEDIUM

Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers …

Aug 7, 2025
CVE-2025-55136
5.7 MEDIUM

ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used.

Aug 7, 2025
CVE-2025-55135
6.4 MEDIUM

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted …

Aug 7, 2025
CVE-2025-55134
6.4 MEDIUM

In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.

Aug 7, 2025
CVE-2025-55133
6.4 MEDIUM

In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManager.js.

Aug 7, 2025
CVE-2025-44779
6.6 MEDIUM

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

Aug 7, 2025
CVE-2025-50952
6.5 MEDIUM

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

Aug 7, 2025
CVE-2025-47188
6.5 MEDIUM

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 …

Aug 7, 2025
CVE-2024-55401
6.5 MEDIUM

An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.

Aug 7, 2025
CVE-2024-52680
6.1 MEDIUM

EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.

Aug 7, 2025
CVE-2025-32094
4.0 MEDIUM

An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS …

Aug 7, 2025
CVE-2025-8583
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Aug 7, 2025
CVE-2025-8582
4.3 MEDIUM

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL …

Aug 7, 2025
CVE-2025-8581
4.3 MEDIUM

Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Aug 7, 2025
CVE-2025-8580
4.3 MEDIUM

Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Aug 7, 2025
CVE-2025-8579
4.3 MEDIUM

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI …

Aug 7, 2025
CVE-2025-8577
4.3 MEDIUM

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI …

Aug 7, 2025
CVE-2025-54784
6.1 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions …

Aug 7, 2025
CVE-2025-54783
6.1 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability allows …

Aug 7, 2025
CVE-2025-54786
5.3 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows …

Aug 7, 2025
CVE-2025-6632
5.3 MEDIUM

A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this …

Aug 6, 2025
CVE-2025-51058
6.5 MEDIUM

Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers to trigger HTTP requests …

Aug 6, 2025
CVE-2025-51057
6.5 MEDIUM

A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' …

Aug 6, 2025
CVE-2025-51054
6.5 MEDIUM

Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via …

Aug 6, 2025
CVE-2025-51053
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject arbitrary Javascript or HTML code and potentially trigger …

Aug 6, 2025
CVE-2025-51052
6.5 MEDIUM

A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in …

Aug 6, 2025
CVE-2025-50740
6.1 MEDIUM

AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web interface /_ac/config allows HTML/JS code to be executed …

Aug 6, 2025
CVE-2025-46660
5.3 MEDIUM

An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.

Aug 6, 2025
CVE-2024-55402
5.3 MEDIUM

4C Strategies Exonaut before v22.4 was discovered to contain an access control issue.

Aug 6, 2025
CVE-2024-55399
6.5 MEDIUM

4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).

Aug 6, 2025
CVE-2024-55398
6.5 MEDIUM

4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.

Aug 6, 2025
CVE-2025-8667
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2. Affected is the function from_code/from_dict/from_mcp of the file src/tools/tools.py. The …

Aug 6, 2025
CVE-2025-8665
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the function MCPTools/MultiMCPTools in the library …

Aug 6, 2025
CVE-2025-8419
5.3 MEDIUM

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is …

Aug 6, 2025
CVE-2025-20332
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected …

Aug 6, 2025
CVE-2025-20331
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a stored XSS attack …

Aug 6, 2025
CVE-2025-20215
5.4 MEDIUM

A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of …

Aug 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.