CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53893
6.5 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In …

Jul 15, 2025
CVE-2025-52082
6.5 MEDIUM

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests containing …

Jul 15, 2025
CVE-2025-52081
6.5 MEDIUM

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests …

Jul 15, 2025
CVE-2025-52080
6.5 MEDIUM

In Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi endpoint. The vulnerability occurs when processing POST requests …

Jul 15, 2025
CVE-2025-53622
5.2 MEDIUM

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.4, 8.2, and 9.1, a path traversal …

Jul 15, 2025
CVE-2025-53621
6.9 MEDIUM

DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all …

Jul 15, 2025
CVE-2025-52379
5.4 MEDIUM

Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerability in the firmware update feature. The /web/um_fileName_set.cgi and /web/um_web_upgrade.cgi endpoints …

Jul 15, 2025
CVE-2025-52378
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below allowing attackers to inject JavaScript code that is executed in the …

Jul 15, 2025
CVE-2025-52377
5.4 MEDIUM

Command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below, allowing authenticated attackers to execute arbitrary commands on the device. The vulnerability …

Jul 15, 2025
CVE-2025-48795
5.6 MEDIUM

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary file …

Jul 15, 2025
CVE-2025-33097
6.4 MEDIUM

IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in …

Jul 15, 2025
CVE-2025-30483
5.5 MEDIUM

Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local …

Jul 15, 2025
CVE-2025-4369
5.5 MEDIUM

The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ parameter in all versions up to, and including, 3.9.2 …

Jul 15, 2025
CVE-2025-24477
4.2 MEDIUM

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its …

Jul 15, 2025
CVE-2025-7672
4.3 MEDIUM

The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XSS. This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23.

Jul 15, 2025
CVE-2025-7367
6.4 MEDIUM

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 …

Jul 15, 2025
CVE-2025-53891
4.3 MEDIUM

The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found in the TIME LINE website where uploaded files (instruction/message …

Jul 15, 2025
CVE-2025-53889
6.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with …

Jul 15, 2025
CVE-2025-53887
5.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus …

Jul 15, 2025
CVE-2025-53886
4.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus …

Jul 15, 2025
CVE-2025-53885
4.2 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus …

Jul 15, 2025
CVE-2025-53839
4.0 MEDIUM

DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON …

Jul 15, 2025
CVE-2025-53834
6.3 MEDIUM

Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s toast UI component in versions prior to 0.49.0. …

Jul 14, 2025
CVE-2025-53824
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jul 14, 2025
CVE-2025-53822
6.5 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jul 14, 2025
CVE-2025-53821
4.7 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the web …

Jul 14, 2025
CVE-2025-53820
6.5 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jul 14, 2025
CVE-2025-53640
6.5 MEDIUM

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an …

Jul 14, 2025
CVE-2025-7628
5.4 MEDIUM

A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects the function deleteFile of the file /deleteFile. …

Jul 14, 2025
CVE-2025-7627
6.3 MEDIUM

A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this issue is the function fileUpload of the file …

Jul 14, 2025
CVE-2025-52363
6.8 MEDIUM

Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image …

Jul 14, 2025
CVE-2025-7626
4.3 MEDIUM

A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the …

Jul 14, 2025
CVE-2025-7625
4.3 MEDIUM

A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function Download of the file /download. The …

Jul 14, 2025
CVE-2025-51660
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.

Jul 14, 2025
CVE-2025-51659
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.

Jul 14, 2025
CVE-2025-51658
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.

Jul 14, 2025
CVE-2025-51657
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.

Jul 14, 2025
CVE-2025-51656
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.

Jul 14, 2025
CVE-2025-51655
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.

Jul 14, 2025
CVE-2025-51654
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.

Jul 14, 2025
CVE-2025-51653
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.

Jul 14, 2025
CVE-2025-51652
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.

Jul 14, 2025
CVE-2025-51651
5.5 MEDIUM

An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.

Jul 14, 2025
CVE-2025-51650
5.6 MEDIUM

An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.

Jul 14, 2025
CVE-2024-42649
6.5 MEDIUM

NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

Jul 14, 2025
CVE-2024-42648
6.5 MEDIUM

NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

Jul 14, 2025
CVE-2025-7616
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of …

Jul 14, 2025
CVE-2025-7615
6.3 MEDIUM

A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file /cgi-bin/cstecgi.cgi of the …

Jul 14, 2025
CVE-2025-7614
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi of the component HTTP …

Jul 14, 2025
CVE-2025-7613
6.3 MEDIUM

A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file /cgi-bin/cstecgi.cgi of …

Jul 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.