CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13451
5.3 MEDIUM

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Jul 2, 2025
CVE-2025-52462
6.1 MEDIUM

Cross-site scripting vulnerability exists in Active! mail 6 BuildInfo: 6.30.01004145 to 6.60.06008562. If this vulnerability is exploited, an arbitrary script may be executed on the …

Jul 2, 2025
CVE-2025-6687
6.4 MEDIUM

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and …

Jul 2, 2025
CVE-2025-6686
6.4 MEDIUM

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and …

Jul 2, 2025
CVE-2025-52925
5.0 MEDIUM

In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.

Jul 2, 2025
CVE-2024-11405
6.1 MEDIUM

The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email and wpmp_reset_password_token parameters in all versions up …

Jul 2, 2025
CVE-2025-5692
6.3 MEDIUM

The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in …

Jul 2, 2025
CVE-2025-6600
4.3 MEDIUM

An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within …

Jul 1, 2025
CVE-2025-46259
5.4 MEDIUM

Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons …

Jul 1, 2025
CVE-2025-27153
6.5 MEDIUM

Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This can lead …

Jul 1, 2025
CVE-2025-53103
5.8 MEDIUM

JUnit is a testing framework for Java and the JVM. From version 5.12.0 to 5.13.1, JUnit's support for writing Open Test Reporting XML files can …

Jul 1, 2025
CVE-2025-52294
5.7 MEDIUM

Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view the wallet balance.

Jul 1, 2025
CVE-2025-45083
6.1 MEDIUM

Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspecified vectors.

Jul 1, 2025
CVE-2025-34080
6.1 MEDIUM

The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in …

Jul 1, 2025
CVE-2025-50641
6.5 MEDIUM

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the addWifiMacFilter function via the parameter deviceId.

Jul 1, 2025
CVE-2025-50405
6.5 MEDIUM

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation function.

Jul 1, 2025
CVE-2025-50404
5.3 MEDIUM

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of …

Jul 1, 2025
CVE-2025-6920
5.3 MEDIUM

A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key …

Jul 1, 2025
CVE-2025-36582
4.8 MEDIUM

Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially …

Jul 1, 2025
CVE-2025-6951
4.3 MEDIUM

A vulnerability classified as problematic was found in SAFECAM X300 up to 20250611. This vulnerability affects unknown code of the component FTP Service. The manipulation …

Jul 1, 2025
CVE-2025-5314
6.1 MEDIUM

The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the ‘pdf-source’ …

Jul 1, 2025
CVE-2025-49483
5.4 MEDIUM

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure. This vulnerability is associated with program files tr069/tr069_uci.c. This …

Jul 1, 2025
CVE-2025-49482
5.4 MEDIUM

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure. This vulnerability is associated with program files tr069/tr098.c. This …

Jul 1, 2025
CVE-2025-49481
5.4 MEDIUM

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router modules allows Resource Leak Exposure. This vulnerability is associated with program files router/phonebook/pbwork-queue.C. This …

Jul 1, 2025
CVE-2025-6224
6.5 MEDIUM

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker …

Jul 1, 2025
CVE-2025-49491
5.4 MEDIUM

Improper Resource Shutdown or Release vulnerability in ASR Falcon_Linux、Kestrel、Lapwing_Linux on Linux (traffic_stat modules) allows Resource Leak Exposure. This vulnerability is associated with program files traffic_stat/traffic_service/traffic_service.C. …

Jul 1, 2025
CVE-2025-49488
5.4 MEDIUM

Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router components allows Resource Leak Exposure. This vulnerability is associated with program files router/phonebook/pb.c. This …

Jul 1, 2025
CVE-2025-6756
6.4 MEDIUM

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's UACF7_CUSTOM_FIELDS shortcode in all versions up …

Jul 1, 2025
CVE-2025-49490
5.4 MEDIUM

Resource leak vulnerability in ASR180x in router allows Resource Leak Exposure. This vulnerability is associated with program files router/sms/sms.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.

Jul 1, 2025
CVE-2025-49489
5.4 MEDIUM

Improper Resource Shutdown or Release vulnerability in ASR Falcon_Linux、Kestrel、Lapwing_Linux on Linux (con_mgr components) allows Resource Leak Exposure. This vulnerability is associated with program files con_mgr/dialer_task.C. …

Jul 1, 2025
CVE-2025-5072
5.4 MEDIUM

Resource leak vulnerability in ASR180x、ASR190x in con_mgr allows Resource Leak Exposure.This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536.

Jul 1, 2025
CVE-2025-6081
6.8 MEDIUM

Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earlier allows an attacker can reconfigure the target device to …

Jul 1, 2025
CVE-2025-53096
5.4 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Clickjacking attacks. This vulnerability …

Jul 1, 2025
CVE-2025-36056
5.4 MEDIUM

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable …

Jul 1, 2025
CVE-2025-2141
6.1 MEDIUM

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable …

Jul 1, 2025
CVE-2025-6930
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/manage-foreigners-ticket.php. The manipulation …

Jun 30, 2025
CVE-2025-6929
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-52997
5.9 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52901
4.5 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52491
5.8 MEDIUM

Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

Jun 30, 2025
CVE-2025-49493
5.8 MEDIUM

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

Jun 30, 2025
CVE-2025-6925
5.3 MEDIUM

A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java …

Jun 30, 2025
CVE-2025-6915
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by this issue is some unknown functionality of …

Jun 30, 2025
CVE-2025-52896
5.4 MEDIUM

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading …

Jun 30, 2025
CVE-2025-47871
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving …

Jun 30, 2025
CVE-2025-46702
5.4 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions …

Jun 30, 2025
CVE-2025-6914
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability is an unknown functionality of the file /edit-student.php. …

Jun 30, 2025
CVE-2025-6913
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation …

Jun 30, 2025
CVE-2024-12915
4.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS.This issue affects Library Software: …

Jun 30, 2025
CVE-2025-6912
6.3 MEDIUM

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.