CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8527
6.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file …

Aug 4, 2025
CVE-2025-54554
5.3 MEDIUM

tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.

Aug 4, 2025
CVE-2025-4604
6.1 MEDIUM

The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through …

Aug 4, 2025
CVE-2025-4599
6.1 MEDIUM

The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 …

Aug 4, 2025
CVE-2025-8526
6.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file …

Aug 4, 2025
CVE-2025-8525
5.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring …

Aug 4, 2025
CVE-2025-8524
5.3 MEDIUM

A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the …

Aug 4, 2025
CVE-2025-8523
5.3 MEDIUM

A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality …

Aug 4, 2025
CVE-2025-55014
4.7 MEDIUM

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers …

Aug 4, 2025
CVE-2025-50340
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other …

Aug 4, 2025
CVE-2025-8522
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of …

Aug 4, 2025
CVE-2025-8520
4.7 MEDIUM

A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/?module=editor/editor of the component …

Aug 4, 2025
CVE-2025-46206
6.5 MEDIUM

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` …

Aug 4, 2025
CVE-2024-45183
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads …

Aug 4, 2025
CVE-2025-8518
4.7 MEDIUM

A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file …

Aug 4, 2025
CVE-2025-50420
6.5 MEDIUM

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can …

Aug 4, 2025
CVE-2025-44962
5.0 MEDIUM

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.

Aug 4, 2025
CVE-2025-44958
5.3 MEDIUM

RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.

Aug 4, 2025
CVE-2025-8517
6.3 MEDIUM

A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. …

Aug 4, 2025
CVE-2025-8516
5.3 MEDIUM

A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file K3Cloud\BBCMallSite\WEB-INF\lib\Kingdee.K3.O2O.Base.WebApp.jar!\kingdee\k3\o2o\base\webapp\action\FileUploadAction.class of …

Aug 4, 2025
CVE-2025-5988
5.3 MEDIUM

A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, …

Aug 4, 2025
CVE-2025-30098
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-30097
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-30096
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-36605
6.1 MEDIUM

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the CWE-79: Improper Neutralization of …

Aug 4, 2025
CVE-2025-0932
4.3 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace …

Aug 4, 2025
CVE-2025-8341
5.0 MEDIUM

Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, …

Aug 4, 2025
CVE-2025-41658
5.5 MEDIUM

CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

Aug 4, 2025
CVE-2025-48499
5.3 MEDIUM

Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (Line Printer Daemon) packet may cause a …

Aug 4, 2025
CVE-2025-54962
6.4 MEDIUM

/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then …

Aug 4, 2025
CVE-2025-20698
6.7 MEDIUM

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Aug 4, 2025
CVE-2025-20697
6.7 MEDIUM

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Aug 4, 2025
CVE-2025-20696
6.8 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Aug 4, 2025
CVE-2025-8513
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Caixin News App 8.0.1 on Android. Affected is an unknown function of the file AndroidManifest.xml …

Aug 3, 2025
CVE-2025-8512
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in TVB Big Big Shop App 2.9.0 on Android. This issue affects some unknown processing …

Aug 3, 2025
CVE-2024-51775
5.3 MEDIUM

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal …

Aug 3, 2025
CVE-2024-52279
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects …

Aug 3, 2025
CVE-2024-41177
6.1 MEDIUM

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which …

Aug 3, 2025
CVE-2025-8505
4.3 MEDIUM

A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site …

Aug 3, 2025
CVE-2025-8504
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation …

Aug 3, 2025
CVE-2025-8500
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Aug 3, 2025
CVE-2025-52133
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.

Aug 3, 2025
CVE-2025-52132
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.

Aug 3, 2025
CVE-2025-52131
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

Aug 3, 2025
CVE-2025-54349
6.5 MEDIUM

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

Aug 3, 2025
CVE-2025-23285
5.5 MEDIUM

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful exploit of this …

Aug 2, 2025
CVE-2023-32255
5.3 MEDIUM

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an …

Aug 2, 2025
CVE-2023-32253
5.9 MEDIUM

A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a …

Aug 2, 2025
CVE-2025-23286
4.4 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit of this vulnerability might …

Aug 2, 2025
CVE-2025-7500
6.4 MEDIUM

The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 …

Aug 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.