CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-38354
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm/gpu: Fix crash when throttling GPU immediately during boot There is a small chance that …

Jul 25, 2025
CVE-2025-38353
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix taking invalid lock on wedge If device wedges on e.g. GuC upload, the …

Jul 25, 2025
CVE-2025-5254
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS.This issue affects Kron PAM: …

Jul 25, 2025
CVE-2025-5253
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS.This issue affects Kron PAM: before 3.7.

Jul 25, 2025
CVE-2025-8135
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Insurance Management System 1.0. This issue affects some unknown processing of the file …

Jul 25, 2025
CVE-2025-8134
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul BP Monitoring Management System 1.0. This vulnerability affects unknown code of the file /bwdates-report-result.php. The manipulation …

Jul 25, 2025
CVE-2025-8133
6.3 MEDIUM

A vulnerability classified as critical has been found in yanyutao0402 ChanCMS up to 3.1.2. This affects the function getArticle of the file app/modules/api/service/gather.js. The manipulation …

Jul 25, 2025
CVE-2025-7022
6.1 MEDIUM

The My Reservation System WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jul 25, 2025
CVE-2025-8132
5.4 MEDIUM

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is the function delfile of …

Jul 25, 2025
CVE-2025-8128
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de48f7fbe98. This issue affects some unknown processing of the file …

Jul 25, 2025
CVE-2025-8127
6.3 MEDIUM

A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. This vulnerability affects unknown code of the file /system/user/list. The manipulation of …

Jul 25, 2025
CVE-2025-8126
6.3 MEDIUM

A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipulation …

Jul 25, 2025
CVE-2025-54567
4.2 MEDIUM

hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.

Jul 25, 2025
CVE-2025-54566
4.2 MEDIUM

hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

Jul 25, 2025
CVE-2025-8125
6.3 MEDIUM

A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 25, 2025
CVE-2025-54558
4.1 MEDIUM

OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.

Jul 25, 2025
CVE-2025-8124
6.3 MEDIUM

A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 25, 2025
CVE-2025-3614
6.4 MEDIUM

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all …

Jul 24, 2025
CVE-2025-8123
6.3 MEDIUM

A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. …

Jul 24, 2025
CVE-2025-45702
6.5 MEDIUM

SoftPerfect Pty Ltd Connection Quality Monitor v1.1 was discovered to store all credentials in plaintext.

Jul 24, 2025
CVE-2025-47061
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Jul 24, 2025
CVE-2025-46996
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Jul 24, 2025
CVE-2025-46993
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Jul 24, 2025
CVE-2025-8114
4.7 MEDIUM

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an …

Jul 24, 2025
CVE-2025-51089
6.5 MEDIUM

Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of the argument `mac` leads to heap-based buffer overflow.

Jul 24, 2025
CVE-2025-51088
5.3 MEDIUM

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argument `shareSpeed` leads to stack-based buffer overflow.

Jul 24, 2025
CVE-2025-51085
5.3 MEDIUM

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the argument `timeZone` and `timeType` leads to stack-based buffer overflow.

Jul 24, 2025
CVE-2025-51082
5.3 MEDIUM

Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of the argument `timeZone` leads to stack-based buffer overflow.

Jul 24, 2025
CVE-2025-36005
5.9 MEDIUM

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 …

Jul 24, 2025
CVE-2025-33013
6.2 MEDIUM

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 …

Jul 24, 2025
CVE-2025-45731
6.5 MEDIUM

A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other operations are pending.

Jul 24, 2025
CVE-2025-8071
6.4 MEDIUM

Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all versions up to, and including, 2.1.10 due to …

Jul 24, 2025
CVE-2025-7966
6.4 MEDIUM

The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and 'subs_count’ parameters in all versions up to, …

Jul 24, 2025
CVE-2025-7959
6.4 MEDIUM

The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter in all versions up to, and including, …

Jul 24, 2025
CVE-2025-7835
4.3 MEDIUM

The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due …

Jul 24, 2025
CVE-2025-7822
4.3 MEDIUM

The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all …

Jul 24, 2025
CVE-2025-7780
6.5 MEDIUM

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to …

Jul 24, 2025
CVE-2025-7690
6.1 MEDIUM

The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing …

Jul 24, 2025
CVE-2025-6588
6.1 MEDIUM

The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to, and including, 1.4.3 due to …

Jul 24, 2025
CVE-2025-6539
6.4 MEDIUM

The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.5 …

Jul 24, 2025
CVE-2025-6387
6.4 MEDIUM

The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, …

Jul 24, 2025
CVE-2025-6385
6.4 MEDIUM

The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 0.4.1 due …

Jul 24, 2025
CVE-2025-6382
6.4 MEDIUM

The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortcode in all versions up to, and including, 0.1.10. …

Jul 24, 2025
CVE-2025-6262
6.4 MEDIUM

The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai shortcode in all versions up to, and including, …

Jul 24, 2025
CVE-2025-5084
6.1 MEDIUM

The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and including, 3.4.13 …

Jul 24, 2025
CVE-2025-4608
6.4 MEDIUM

The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and including, 1.6.4 …

Jul 24, 2025
CVE-2025-3669
6.4 MEDIUM

The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's auto_qrcodesabb shortcode in all versions up to, …

Jul 24, 2025
CVE-2025-8107
6.3 MEDIUM

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability …

Jul 24, 2025
CVE-2025-8009
4.9 MEDIUM

The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, …

Jul 24, 2025
CVE-2025-7745
5.8 MEDIUM

Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.

Jul 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.