CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7489
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. This issue affects some unknown processing of the file /admin/search-vehicle.php. …

Jul 12, 2025
CVE-2025-7488
4.3 MEDIUM

A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and classified as critical. This vulnerability affects the function Download of the file /file/download. …

Jul 12, 2025
CVE-2025-7487
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This affects the function SysFileController of the file /file/upload. The …

Jul 12, 2025
CVE-2025-7484
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Vehicle Parking Management System 1.13. Affected is an unknown function of the file /admin/view-outgoingvehicle-detail.php. The …

Jul 12, 2025
CVE-2025-7482
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 12, 2025
CVE-2025-7481
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This affects an unknown part of the file …

Jul 12, 2025
CVE-2025-7479
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 12, 2025
CVE-2025-7477
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the …

Jul 12, 2025
CVE-2025-36104
6.5 MEDIUM

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the …

Jul 12, 2025
CVE-2021-4458
5.9 MEDIUM

The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions …

Jul 12, 2025
CVE-2025-7518
4.9 MEDIUM

The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via the get_local_filename() function. This makes it …

Jul 12, 2025
CVE-2025-7462
4.3 MEDIUM

A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. This affects the function pdf_ferror of the file devices/vector/gdevpdf.c …

Jul 12, 2025
CVE-2024-38648
5.7 MEDIUM

A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.

Jul 12, 2025
CVE-2023-39339
4.9 MEDIUM

A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can perform an arbitrary file read via a maliciously …

Jul 12, 2025
CVE-2023-39338
6.8 MEDIUM

Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry policy to …

Jul 12, 2025
CVE-2025-53636
5.4 MEDIUM

Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs …

Jul 11, 2025
CVE-2025-3631
6.5 MEDIUM

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

Jul 11, 2025
CVE-2025-7452
6.3 MEDIUM

A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as critical. This vulnerability affects the function GetFile of the file …

Jul 11, 2025
CVE-2025-53642
4.8 MEDIUM

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the …

Jul 11, 2025
CVE-2025-7450
5.4 MEDIUM

A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the function ResetUserAvatar of the file controller/api/v1/user.go …

Jul 11, 2025
CVE-2025-47964
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jul 11, 2025
CVE-2025-47963
6.3 MEDIUM

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 11, 2025
CVE-2025-47182
5.6 MEDIUM

Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

Jul 11, 2025
CVE-2025-45582
4.1 MEDIUM

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an …

Jul 11, 2025
CVE-2024-47065
6.5 MEDIUM

Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are …

Jul 11, 2025
CVE-2025-6549
6.5 MEDIUM

An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the Juniper …

Jul 11, 2025
CVE-2025-52989
5.1 MEDIUM

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high …

Jul 11, 2025
CVE-2025-52988
6.7 MEDIUM

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos …

Jul 11, 2025
CVE-2025-52986
5.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jul 11, 2025
CVE-2025-52985
5.3 MEDIUM

A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security …

Jul 11, 2025
CVE-2025-52984
5.9 MEDIUM

A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker …

Jul 11, 2025
CVE-2025-52982
5.9 MEDIUM

An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based …

Jul 11, 2025
CVE-2025-52994
4.9 MEDIUM

gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.

Jul 11, 2025
CVE-2025-52964
6.5 MEDIUM

A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to …

Jul 11, 2025
CVE-2025-52963
5.5 MEDIUM

An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, …

Jul 11, 2025
CVE-2025-52958
5.3 MEDIUM

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to …

Jul 11, 2025
CVE-2025-52955
6.5 MEDIUM

An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent …

Jul 11, 2025
CVE-2025-52953
6.5 MEDIUM

An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker …

Jul 11, 2025
CVE-2025-52952
6.5 MEDIUM

An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line …

Jul 11, 2025
CVE-2025-52951
5.8 MEDIUM

A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to …

Jul 11, 2025
CVE-2025-52949
6.5 MEDIUM

An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a …

Jul 11, 2025
CVE-2025-52948
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker, in rare cases, sending …

Jul 11, 2025
CVE-2025-52947
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker …

Jul 11, 2025
CVE-2025-48924
5.3 MEDIUM

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. …

Jul 11, 2025
CVE-2023-38329
6.1 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web …

Jul 11, 2025
CVE-2023-38327
5.3 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web …

Jul 11, 2025
CVE-2025-3933
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability …

Jul 11, 2025
CVE-2025-6838
4.1 MEDIUM

The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are …

Jul 11, 2025
CVE-2025-6745
5.3 MEDIUM

The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_query() function due to insufficient …

Jul 11, 2025
CVE-2025-6068
6.4 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & …

Jul 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.