CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6462
6.4 MEDIUM

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all …

Jun 29, 2025
CVE-2025-6842
4.7 MEDIUM

A vulnerability was found in code-projects Product Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit_user.php. The …

Jun 29, 2025
CVE-2025-6841
4.7 MEDIUM

A vulnerability has been found in code-projects Product Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit_product.php. The …

Jun 29, 2025
CVE-2025-6839
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue …

Jun 29, 2025
CVE-2025-6837
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of the file /profile.php. The …

Jun 29, 2025
CVE-2025-6829
6.3 MEDIUM

A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function outAddress of the component External Address …

Jun 28, 2025
CVE-2025-53393
6.0 MEDIUM

In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.

Jun 28, 2025
CVE-2025-53392
5.0 MEDIUM

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is …

Jun 28, 2025
CVE-2023-29113
6.3 MEDIUM

The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with …

Jun 28, 2025
CVE-2023-28912
5.7 MEDIUM

The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access …

Jun 28, 2025
CVE-2023-28911
6.5 MEDIUM

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28908
5.4 MEDIUM

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28907
6.7 MEDIUM

There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to …

Jun 28, 2025
CVE-2023-28904
5.2 MEDIUM

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to …

Jun 28, 2025
CVE-2025-5937
4.3 MEDIUM

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jun 28, 2025
CVE-2025-38086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nway_restart In mii_nway_restart() the code attempts to call mii->mdio_read …

Jun 28, 2025
CVE-2025-38085
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that …

Jun 28, 2025
CVE-2025-38084
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table …

Jun 28, 2025
CVE-2025-6252
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.9.1 …

Jun 28, 2025
CVE-2025-6350
6.4 MEDIUM

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ …

Jun 28, 2025
CVE-2025-36027
5.4 MEDIUM

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Jun 28, 2025
CVE-2025-36026
4.3 MEDIUM

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the …

Jun 28, 2025
CVE-2024-52900
6.4 MEDIUM

IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to …

Jun 28, 2025
CVE-2024-39730
5.4 MEDIUM

IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to …

Jun 28, 2025
CVE-2024-36347
6.4 MEDIUM

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in …

Jun 27, 2025
CVE-2025-53097
5.9 MEDIUM

Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent's `search_files` tool did not …

Jun 27, 2025
CVE-2025-6775
6.3 MEDIUM

A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file /app/api/v1/openvpn.py of the …

Jun 27, 2025
CVE-2025-6774
6.3 MEDIUM

A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is the function AddTemp of …

Jun 27, 2025
CVE-2025-6773
5.3 MEDIUM

A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_input_dir of …

Jun 27, 2025
CVE-2025-6522
5.4 MEDIUM

Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on …

Jun 27, 2025
CVE-2025-46708
4.3 MEDIUM

Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.

Jun 27, 2025
CVE-2025-46707
5.2 MEDIUM

Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.

Jun 27, 2025
CVE-2025-44559
6.5 MEDIUM

An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a Denial of …

Jun 27, 2025
CVE-2025-50370
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows …

Jun 27, 2025
CVE-2025-50369
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an …

Jun 27, 2025
CVE-2025-50367
6.1 MEDIUM

A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly …

Jun 27, 2025
CVE-2025-6705
5.3 MEDIUM

A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed …

Jun 27, 2025
CVE-2023-38007
5.4 MEDIUM

IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems is vulnerable to …

Jun 27, 2025
CVE-2025-6768
6.3 MEDIUM

A vulnerability classified as critical has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is the function findAllHosByCondition of the file HospitalServiceImpl.java. The manipulation …

Jun 27, 2025
CVE-2025-53336
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in abditsori My Resume Builder my-resume-builder allows Stored XSS.This issue affects My Resume Builder: …

Jun 27, 2025
CVE-2025-53327
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in rui_mashita Aioseo Multibyte Descriptions aioseo-multibyte-descriptions allows Cross Site Request Forgery.This issue affects Aioseo Multibyte Descriptions: from n/a through <= …

Jun 27, 2025
CVE-2025-53325
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dilip kumar Beauty Contact Popup Form beauty-contact-popup-form allows Stored XSS.This issue affects Beauty …

Jun 27, 2025
CVE-2025-53323
4.3 MEDIUM

Missing Authorization vulnerability in danbriapps Pre-Publish Post Checklist pre-publish-post-checklist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pre-Publish Post Checklist: from n/a through …

Jun 27, 2025
CVE-2025-53322
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 accept-authorize-net-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects …

Jun 27, 2025
CVE-2025-53321
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raise The Money Raise The Money raise-the-money allows DOM-Based XSS.This issue affects Raise …

Jun 27, 2025
CVE-2025-53320
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wp Enhanced Free Downloads EDD allows DOM-Based XSS. This issue affects Free Downloads …

Jun 27, 2025
CVE-2025-53318
5.4 MEDIUM

Missing Authorization vulnerability in WPManiax WP DB Booster wp-db-booster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP DB Booster: from n/a through …

Jun 27, 2025
CVE-2025-53309
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Stripe Payments Using Contact Form 7 accept-stripe-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects …

Jun 27, 2025
CVE-2025-53304
5.3 MEDIUM

Missing Authorization vulnerability in Rohil Contact Form – 7 : Hide Success Message contact-form-7-hide-success-message allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contact …

Jun 27, 2025
CVE-2025-53301
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Junkie Theme Junkie Team Content theme-junkie-team-content allows DOM-Based XSS.This issue affects Theme …

Jun 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.