CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5530
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shortcode_btn' shortcode in all versions up to, …

Jul 11, 2025
CVE-2025-4593
6.5 MEDIUM

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the …

Jul 11, 2025
CVE-2025-6716
6.4 MEDIUM

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress …

Jul 11, 2025
CVE-2025-6200
5.9 MEDIUM

The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Jul 11, 2025
CVE-2025-30024
6.8 MEDIUM

The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

Jul 11, 2025
CVE-2025-2942
4.3 MEDIUM

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing …

Jul 11, 2025
CVE-2025-53864
5.8 MEDIUM

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply …

Jul 11, 2025
CVE-2025-5241
5.3 MEDIUM

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain …

Jul 11, 2025
CVE-2025-53519
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, …

Jul 11, 2025
CVE-2025-53509
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. …

Jul 11, 2025
CVE-2025-53471
5.1 MEDIUM

Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to …

Jul 11, 2025
CVE-2025-53397
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, …

Jul 11, 2025
CVE-2025-52459
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain …

Jul 11, 2025
CVE-2025-48496
5.1 MEDIUM

Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the …

Jul 11, 2025
CVE-2025-46704
4.3 MEDIUM

A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least …

Jul 11, 2025
CVE-2025-41442
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input …

Jul 11, 2025
CVE-2025-31267
4.6 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an …

Jul 10, 2025
CVE-2025-6392
4.4 MEDIUM

Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec …

Jul 10, 2025
CVE-2025-53637
4.1 MEDIUM

Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be …

Jul 10, 2025
CVE-2025-24798
4.3 MEDIUM

Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. …

Jul 10, 2025
CVE-2025-7415
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of …

Jul 10, 2025
CVE-2025-7414
6.3 MEDIUM

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. …

Jul 10, 2025
CVE-2025-6390
4.4 MEDIUM

Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit …

Jul 10, 2025
CVE-2025-4662
4.4 MEDIUM

Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the …

Jul 10, 2025
CVE-2025-2522
6.5 MEDIUM

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit …

Jul 10, 2025
CVE-2025-7413
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/profile.php. The manipulation of …

Jul 10, 2025
CVE-2025-7412
6.3 MEDIUM

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 10, 2025
CVE-2025-7021
6.5 MEDIUM

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker …

Jul 10, 2025
CVE-2025-45662
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's …

Jul 10, 2025
CVE-2025-53709
5.4 MEDIUM

Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The service only installed on a small number of environments. …

Jul 10, 2025
CVE-2025-53626
6.1 MEDIUM

pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading …

Jul 10, 2025
CVE-2025-52473
5.9 MEDIUM

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the …

Jul 10, 2025
CVE-2025-28245
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web script or HTML via the notification body.

Jul 10, 2025
CVE-2025-49464
6.5 MEDIUM

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

Jul 10, 2025
CVE-2025-49463
6.5 MEDIUM

Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via …

Jul 10, 2025
CVE-2025-47813
4.3 MEDIUM KEV

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Jul 10, 2025
CVE-2025-47811
4.1 MEDIUM

In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web …

Jul 10, 2025
CVE-2025-6395
6.5 MEDIUM

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

Jul 10, 2025
CVE-2025-53364
5.3 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and …

Jul 10, 2025
CVE-2025-46789
6.5 MEDIUM

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

Jul 10, 2025
CVE-2025-36090
4.3 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be used …

Jul 10, 2025
CVE-2024-39752
6.8 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to …

Jul 10, 2025
CVE-2024-38327
6.8 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which …

Jul 10, 2025
CVE-2024-37524
5.3 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is …

Jul 10, 2025
CVE-2025-7407
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Netgear D6400 1.0.0.114. This affects an unknown part of the file diag.cgi. The manipulation of …

Jul 10, 2025
CVE-2024-36697
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via …

Jul 10, 2025
CVE-2025-6211
6.5 MEDIUM

A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document …

Jul 10, 2025
CVE-2025-32990
6.5 MEDIUM

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from …

Jul 10, 2025
CVE-2025-5022
6.5 MEDIUM

Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi …

Jul 10, 2025
CVE-2025-3396
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have …

Jul 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.