CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7001
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have …

Jul 24, 2025
CVE-2025-4976
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain …

Jul 24, 2025
CVE-2025-4968
6.4 MEDIUM

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box, Separator …

Jul 24, 2025
CVE-2025-4395
6.8 MEDIUM

Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no …

Jul 24, 2025
CVE-2025-4394
6.8 MEDIUM

Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue …

Jul 24, 2025
CVE-2025-4393
6.5 MEDIUM

Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary …

Jul 24, 2025
CVE-2025-1299
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions …

Jul 24, 2025
CVE-2025-0765
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have …

Jul 24, 2025
CVE-2025-32019
4.1 MEDIUM

Harbor is an open source trusted cloud native registry project that stores, signs, and scans content. Versions 2.11.2 and below, as well as versions 2.12.0-rc1 …

Jul 23, 2025
CVE-2025-44109
5.4 MEDIUM

A URL redirection in Pinokio v3.6.23 allows attackers to redirect victim users to attacker-controlled pages.

Jul 23, 2025
CVE-2025-50477
5.4 MEDIUM

A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.

Jul 23, 2025
CVE-2025-50481
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a …

Jul 23, 2025
CVE-2025-46171
5.4 MEDIUM

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list …

Jul 23, 2025
CVE-2025-40598
6.1 MEDIUM

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potentially execute arbitrary JavaScript code.

Jul 23, 2025
CVE-2025-36117
6.3 MEDIUM

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate …

Jul 23, 2025
CVE-2025-36116
6.3 MEDIUM

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated …

Jul 23, 2025
CVE-2025-33020
5.9 MEDIUM

IBM Engineering Systems Design Rhapsody 9.0.2, 10.0, and 10.0.1 transmits sensitive information without encryption that could allow an attacker to obtain highly sensitive information.

Jul 23, 2025
CVE-2025-54090
6.3 MEDIUM

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, …

Jul 23, 2025
CVE-2025-4411
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dataprom Informatics PACS-ACSS allows Cross-Site Scripting (XSS).This issue affects PACS-ACSS: before …

Jul 23, 2025
CVE-2025-4296
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing.This issue affects B2B: before 04.06.2025.

Jul 23, 2025
CVE-2024-41751
5.5 MEDIUM

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security …

Jul 23, 2025
CVE-2024-41750
5.5 MEDIUM

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security …

Jul 23, 2025
CVE-2024-40686
5.4 MEDIUM

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input …

Jul 23, 2025
CVE-2024-40682
6.2 MEDIUM

IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due …

Jul 23, 2025
CVE-2025-27930
6.4 MEDIUM

Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

Jul 23, 2025
CVE-2025-53882
4.4 MEDIUM

A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP …

Jul 23, 2025
CVE-2025-6174
6.1 MEDIUM

The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_stylesheet" parameter before outputting it back in the …

Jul 23, 2025
CVE-2025-43881
4.3 MEDIUM

Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. If exploited, a denial of service (DoS) …

Jul 23, 2025
CVE-2024-53288
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated …

Jul 23, 2025
CVE-2024-53287
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated …

Jul 23, 2025
CVE-2025-42947
5.5 MEDIUM

SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An …

Jul 23, 2025
CVE-2025-6261
6.4 MEDIUM

The Fleetwire Fleet Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fleetwire_list shortcode in all versions up to, and including, …

Jul 23, 2025
CVE-2025-6215
5.3 MEDIUM

The Omnishop plugin for WordPress is vulnerable to Unauthenticated Registration Bypass in all versions up to, and including, 1.0.9. Its /users/register endpoint is exposed to …

Jul 23, 2025
CVE-2025-6214
6.5 MEDIUM

The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all versions up to, and including, 1.0.9. The …

Jul 23, 2025
CVE-2025-6054
6.1 MEDIUM

The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or …

Jul 23, 2025
CVE-2025-5818
5.5 MEDIUM

The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, …

Jul 23, 2025
CVE-2025-5753
6.4 MEDIUM

The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.3.2 due …

Jul 23, 2025
CVE-2025-54139
4.3 MEDIUM

HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions …

Jul 23, 2025
CVE-2025-43489
5.2 MEDIUM

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize untrusted data without validation. …

Jul 23, 2025
CVE-2025-43488
4.8 MEDIUM

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the …

Jul 23, 2025
CVE-2025-43487
6.8 MEDIUM

A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not …

Jul 23, 2025
CVE-2025-43486
4.8 MEDIUM

A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to …

Jul 23, 2025
CVE-2025-43485
4.5 MEDIUM

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user …

Jul 23, 2025
CVE-2025-43484
6.1 MEDIUM

A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or …

Jul 23, 2025
CVE-2025-43483
5.7 MEDIUM

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded …

Jul 23, 2025
CVE-2025-43021
5.7 MEDIUM

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval …

Jul 22, 2025
CVE-2025-43020
6.8 MEDIUM

A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user …

Jul 22, 2025
CVE-2025-8033
6.5 MEDIUM

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed …

Jul 22, 2025
CVE-2025-8027
6.5 MEDIUM

On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This …

Jul 22, 2025
CVE-2025-51462
6.1 MEDIUM

Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, …

Jul 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.