CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48470
4.1 MEDIUM

Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, …

Jun 24, 2025
CVE-2025-48468
6.4 MEDIUM

Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.

Jun 24, 2025
CVE-2025-48467
6.5 MEDIUM

Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to remote denial-of-service and system unavailability.

Jun 24, 2025
CVE-2025-48462
4.2 MEDIUM

Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block other users from logging in, thereby preventing legitimate …

Jun 24, 2025
CVE-2025-48461
5.0 MEDIUM

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially …

Jun 24, 2025
CVE-2025-6535
6.3 MEDIUM

A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file novel-admin/src/main/resources/mybatis/system/UserMapper.xml …

Jun 24, 2025
CVE-2025-6534
4.2 MEDIUM

A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of …

Jun 24, 2025
CVE-2025-34032
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application …

Jun 24, 2025
CVE-2025-6533
5.6 MEDIUM

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of …

Jun 24, 2025
CVE-2025-6532
4.3 MEDIUM

A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerability is an unknown functionality of the component …

Jun 24, 2025
CVE-2025-6531
4.3 MEDIUM

A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability affects unknown code of the component …

Jun 24, 2025
CVE-2025-6530
4.8 MEDIUM

A vulnerability was found in 70mai M300 up to 20250611. It has been classified as problematic. This affects an unknown part of the file demo.sh …

Jun 23, 2025
CVE-2025-6528
4.3 MEDIUM

A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jun 23, 2025
CVE-2025-6525
4.3 MEDIUM

A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code of the file /cgi-bin/Config.cgi?action=set of the component …

Jun 23, 2025
CVE-2025-49574
6.4 MEDIUM

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential …

Jun 23, 2025
CVE-2021-47688
5.7 MEDIUM

In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be …

Jun 23, 2025
CVE-2025-6518
6.3 MEDIUM

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py …

Jun 23, 2025
CVE-2025-6517
6.3 MEDIUM

A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.java of …

Jun 23, 2025
CVE-2025-6516
5.3 MEDIUM

A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5F_addr_decode_len of the file /hdf5/src/H5Fint.c. The …

Jun 23, 2025
CVE-2025-52967
5.8 MEDIUM

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

Jun 23, 2025
CVE-2025-52879
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible

Jun 23, 2025
CVE-2025-52878
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions

Jun 23, 2025
CVE-2025-52877
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

Jun 23, 2025
CVE-2025-52876
5.4 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

Jun 23, 2025
CVE-2025-52875
5.4 MEDIUM

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

Jun 23, 2025
CVE-2025-48700
6.1 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI …

Jun 23, 2025
CVE-2023-47298
4.3 MEDIUM

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of …

Jun 23, 2025
CVE-2025-52920
6.4 MEDIUM

Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit …

Jun 23, 2025
CVE-2024-3511
4.3 MEDIUM

An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, …

Jun 23, 2025
CVE-2025-6493
5.3 MEDIUM

A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/markdown.js of the component Markdown Mode. This …

Jun 22, 2025
CVE-2025-6492
5.3 MEDIUM

A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is the function getRecommendTitleFromMarkdownString of the file …

Jun 22, 2025
CVE-2025-6485
6.3 MEDIUM

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation …

Jun 22, 2025
CVE-2025-6484
4.7 MEDIUM

A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 22, 2025
CVE-2025-6478
4.3 MEDIUM

A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The …

Jun 22, 2025
CVE-2025-6476
4.3 MEDIUM

A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to …

Jun 22, 2025
CVE-2025-6473
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /fees.php. …

Jun 22, 2025
CVE-2025-6466
6.3 MEDIUM

A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/upload of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/service/impl/SseServiceImpl.java. The …

Jun 22, 2025
CVE-2025-6453
6.3 MEDIUM

A vulnerability classified as critical has been found in diyhi bbs 6.8. Affected is the function Add of the file /src/main/java/cms/web/action/template/ForumManageAction.java of the component API. …

Jun 22, 2025
CVE-2025-52923
4.3 MEDIUM

Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.

Jun 22, 2025
CVE-2025-6422
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 21, 2025
CVE-2025-52919
4.3 MEDIUM

In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.

Jun 21, 2025
CVE-2025-52918
5.0 MEDIUM

Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.

Jun 21, 2025
CVE-2025-52917
4.3 MEDIUM

The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.

Jun 21, 2025
CVE-2025-1987
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type website_password and bookmark, as used in Bitdefender SecurePass. The …

Jun 21, 2025
CVE-2025-6417
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jun 21, 2025
CVE-2025-6416
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /admin/changeimage4.php. …

Jun 21, 2025
CVE-2025-6415
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.1. This issue affects some unknown processing of the …

Jun 21, 2025
CVE-2025-6414
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Art Gallery Management System 1.1. This vulnerability affects unknown code of the file /admin/changeimage2.php. The manipulation …

Jun 21, 2025
CVE-2025-6413
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.1. This affects an unknown part of the file /admin/changeimage1.php. The …

Jun 21, 2025
CVE-2025-6412
6.3 MEDIUM

A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.