CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8265
4.7 MEDIUM

A vulnerability classified as critical has been found in 299Ko CMS 2.0.0. This affects an unknown part of the file /admin/filemanager/view of the component File …

Jul 28, 2025
CVE-2025-27802
4.8 MEDIUM

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious …

Jul 28, 2025
CVE-2025-27801
4.8 MEDIUM

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious …

Jul 28, 2025
CVE-2025-27800
4.8 MEDIUM

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious …

Jul 28, 2025
CVE-2025-8262
4.3 MEDIUM

A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. …

Jul 28, 2025
CVE-2025-8258
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Cool Mo Maigcal Number App up to 1.0.3 on Android. Affected by this issue …

Jul 28, 2025
CVE-2025-8257
5.3 MEDIUM

A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality …

Jul 28, 2025
CVE-2025-8256
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin/product.php. The manipulation …

Jul 28, 2025
CVE-2025-8254
6.3 MEDIUM

A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view_parcel.php. …

Jul 28, 2025
CVE-2023-53159
4.5 MEDIUM

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

Jul 28, 2025
CVE-2022-50237
5.9 MEDIUM

The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for …

Jul 28, 2025
CVE-2023-53158
4.1 MEDIUM

The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability …

Jul 28, 2025
CVE-2025-8247
6.3 MEDIUM

A vulnerability classified as critical has been found in Projectworlds Online Admission System 1.0. This affects an unknown part of the file /admin.php. The manipulation …

Jul 28, 2025
CVE-2023-53157
5.3 MEDIUM

The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UDP packet.

Jul 28, 2025
CVE-2023-53156
4.5 MEDIUM

The transpose crate before 0.2.3 for Rust allows an integer overflow via input_width and input_height arguments.

Jul 27, 2025
CVE-2025-8231
6.8 MEDIUM

A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects some unknown processing of the file …

Jul 27, 2025
CVE-2025-8230
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Courier Management System 1.0. This vulnerability affects unknown code of the file /manage_user.php. The manipulation of …

Jul 27, 2025
CVE-2025-8229
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Courier Management System 1.0. This affects an unknown part of the file /parcel_list.php. The manipulation …

Jul 27, 2025
CVE-2025-8228
6.3 MEDIUM

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function getPages of …

Jul 27, 2025
CVE-2025-8227
6.3 MEDIUM

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 27, 2025
CVE-2025-8226
4.3 MEDIUM

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sysApp/find. …

Jul 27, 2025
CVE-2025-8223
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. This affects an unknown part of the file AdminTypeCustController.java. …

Jul 27, 2025
CVE-2025-8221
4.3 MEDIUM

A vulnerability classified as problematic was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. Affected by this vulnerability is the function goodsSearch of the file …

Jul 27, 2025
CVE-2025-8104
4.3 MEDIUM

The Memory Usage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.98. This is due to missing …

Jul 27, 2025
CVE-2025-8219
6.3 MEDIUM

A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. It has been rated as critical. This issue affects some unknown …

Jul 27, 2025
CVE-2025-6241
4.4 MEDIUM

LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable …

Jul 27, 2025
CVE-2025-8210
5.3 MEDIUM

A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affected is an unknown function of …

Jul 26, 2025
CVE-2025-8207
5.3 MEDIUM

A vulnerability was found in Canara ai1 Mobile Banking App 3.6.23 on Android and classified as problematic. This issue affects some unknown processing of the …

Jul 26, 2025
CVE-2025-8203
6.3 MEDIUM

A vulnerability classified as critical has been found in Jingmen Zeyou Large File Upload Control up to 6.3. Affected is an unknown function of the …

Jul 26, 2025
CVE-2025-8190
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Courier Management System 1.0. This issue affects some unknown processing of the file …

Jul 26, 2025
CVE-2025-8189
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Courier Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The manipulation of …

Jul 26, 2025
CVE-2025-8188
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Courier Management System 1.0. This affects an unknown part of the file /edit_staff.php. The manipulation …

Jul 26, 2025
CVE-2025-8187
6.3 MEDIUM

A vulnerability was found in Campcodes Courier Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 26, 2025
CVE-2025-8186
6.3 MEDIUM

A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 26, 2025
CVE-2025-8182
5.6 MEDIUM

A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component …

Jul 26, 2025
CVE-2025-5529
6.4 MEDIUM

The Educenter theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Circle Counter Block in all versions up to, and including, 1.6.2 due …

Jul 26, 2025
CVE-2025-8097
5.3 MEDIUM

The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient validation …

Jul 26, 2025
CVE-2025-7501
6.4 MEDIUM

The Wonder Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image title and description DOM in all versions up to, and …

Jul 26, 2025
CVE-2025-6987
6.4 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 …

Jul 26, 2025
CVE-2025-8177
5.3 MEDIUM

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. …

Jul 26, 2025
CVE-2025-8176
5.3 MEDIUM

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. …

Jul 26, 2025
CVE-2025-8103
4.3 MEDIUM

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due …

Jul 26, 2025
CVE-2025-54380
6.5 MEDIUM

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would incorrectly send the …

Jul 26, 2025
CVE-2025-8175
6.5 MEDIUM

A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the …

Jul 26, 2025
CVE-2025-8174
6.3 MEDIUM

A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/candidates_add.php. …

Jul 26, 2025
CVE-2025-8172
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Employee Management System 1.0. Affected is an unknown function of the file /admin/index.php. The …

Jul 25, 2025
CVE-2025-8171
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This issue affects some unknown processing of the file …

Jul 25, 2025
CVE-2025-8165
6.3 MEDIUM

A vulnerability was found in code-projects Food Review System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/approve_reservation.php. The …

Jul 25, 2025
CVE-2025-52455
5.3 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (EPS Server modules) allows Resource Location Spoofing. This issue affects Tableau Server: before …

Jul 25, 2025
CVE-2025-8164
6.3 MEDIUM

A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affects unknown code of the file send_message.php. The …

Jul 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.