CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6607
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/stock.php. …

Jun 25, 2025
CVE-2025-6606
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. This issue affects some unknown processing of the …

Jun 25, 2025
CVE-2025-6605
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability affects unknown code of the file /panel/edit-staff.php. The manipulation …

Jun 25, 2025
CVE-2025-48991
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition …

Jun 25, 2025
CVE-2025-6604
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add-staff.php. The …

Jun 25, 2025
CVE-2025-25012
4.3 MEDIUM

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via …

Jun 25, 2025
CVE-2025-6603
5.3 MEDIUM

A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as problematic. Affected by this issue is the function qcow_make_empty of …

Jun 25, 2025
CVE-2025-41647
5.5 MEDIUM

A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the …

Jun 25, 2025
CVE-2024-51984
6.8 MEDIUM

An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existing …

Jun 25, 2025
CVE-2024-51981
5.3 MEDIUM

An unauthenticated attacker may perform a blind server side request forgery (SSRF), due to a CLRF injection issue that can be leveraged to perform HTTP …

Jun 25, 2025
CVE-2024-51980
5.3 MEDIUM

An unauthenticated attacker may perform a limited server side request forgery (SSRF), forcing the target device to open a TCP connection to an arbitrary port …

Jun 25, 2025
CVE-2024-51977
5.3 MEDIUM

An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port …

Jun 25, 2025
CVE-2025-43880
4.3 MEDIUM

Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may cause a denial of service (DoS) condition.

Jun 25, 2025
CVE-2025-5585
6.4 MEDIUM

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-url` DOM Element Attribute in all versions up to, and …

Jun 25, 2025
CVE-2025-6583
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /view-appointment.php. …

Jun 25, 2025
CVE-2025-6582
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality …

Jun 25, 2025
CVE-2025-6581
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 24, 2025
CVE-2025-52883
5.3 MEDIUM

Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message …

Jun 24, 2025
CVE-2025-6557
5.4 MEDIUM

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific …

Jun 24, 2025
CVE-2025-6556
5.4 MEDIUM

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. …

Jun 24, 2025
CVE-2025-6555
5.4 MEDIUM

Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 24, 2025
CVE-2025-53021
4.2 MEDIUM

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained …

Jun 24, 2025
CVE-2025-52880
4.2 MEDIUM

Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has been discovered in versions 1.8.0 through 1.21.3 …

Jun 24, 2025
CVE-2025-53073
4.2 MEDIUM

In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being …

Jun 24, 2025
CVE-2025-49147
5.3 MEDIUM

Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 and 13.0.0 through 13.9.1. Via a request …

Jun 24, 2025
CVE-2025-23260
5.0 MEDIUM

NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the …

Jun 24, 2025
CVE-2024-56916
6.1 MEDIUM

In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. …

Jun 24, 2025
CVE-2024-56918
6.1 MEDIUM

In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the …

Jun 24, 2025
CVE-2025-6570
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected by this issue is some unknown functionality of …

Jun 24, 2025
CVE-2025-50699
6.1 MEDIUM

PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in odms/admin/view-user-queries.php.

Jun 24, 2025
CVE-2025-50695
6.1 MEDIUM

PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-detail.php and /admin/invoice-generating.php.

Jun 24, 2025
CVE-2025-50693
6.5 MEDIUM

PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/request-details.php.

Jun 24, 2025
CVE-2025-6569
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 24, 2025
CVE-2025-6566
5.3 MEDIUM

A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the function deserializeArray of the file …

Jun 24, 2025
CVE-2025-6434
4.3 MEDIUM

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick …

Jun 24, 2025
CVE-2025-6431
6.5 MEDIUM

When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could …

Jun 24, 2025
CVE-2025-6430
6.1 MEDIUM

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` …

Jun 24, 2025
CVE-2025-6429
6.5 MEDIUM

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could …

Jun 24, 2025
CVE-2025-6428
4.3 MEDIUM

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to …

Jun 24, 2025
CVE-2025-6425
4.3 MEDIUM

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private …

Jun 24, 2025
CVE-2025-39205
6.5 MEDIUM

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to …

Jun 24, 2025
CVE-2025-39204
6.5 MEDIUM

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning …

Jun 24, 2025
CVE-2025-39203
6.5 MEDIUM

A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can …

Jun 24, 2025
CVE-2025-39201
6.1 MEDIUM

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of …

Jun 24, 2025
CVE-2025-1718
6.5 MEDIUM

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk …

Jun 24, 2025
CVE-2025-5258
6.4 MEDIUM

The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due …

Jun 24, 2025
CVE-2025-43877
5.4 MEDIUM

WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be executed on the web browser of the user who …

Jun 24, 2025
CVE-2025-36519
4.3 MEDIUM

Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially …

Jun 24, 2025
CVE-2025-47943
6.3 MEDIUM

Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, …

Jun 24, 2025
CVE-2025-6552
4.3 MEDIUM

A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the …

Jun 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.