CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6122
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Restaurant Order System 1.0. This affects an unknown part of the file /table.php. The …

Jun 16, 2025
CVE-2025-6120
5.3 MEDIUM

A vulnerability classified as critical was found in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function read_meshes in …

Jun 16, 2025
CVE-2025-46710
5.7 MEDIUM

Possible kernel exceptions caused by reading and writing kernel heap data after free.

Jun 16, 2025
CVE-2025-6119
5.3 MEDIUM

A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the function Assimp::BVHLoader::ReadNodeChannels in the library …

Jun 16, 2025
CVE-2025-25265
4.9 MEDIUM

A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to …

Jun 16, 2025
CVE-2025-25264
6.5 MEDIUM

An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the …

Jun 16, 2025
CVE-2025-40729
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter.

Jun 16, 2025
CVE-2025-2091
5.4 MEDIUM

An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to …

Jun 16, 2025
CVE-2025-6109
4.3 MEDIUM

A vulnerability was found in javahongxi whatsmars 2021.4.0. It has been rated as problematic. Affected by this issue is the function initialize of the file …

Jun 16, 2025
CVE-2025-6108
6.3 MEDIUM

A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has been declared as critical. Affected by this vulnerability is the function watermarkTest of …

Jun 16, 2025
CVE-2025-6106
4.3 MEDIUM

A vulnerability was found in WuKongOpenSource WukongCRM 9.0 and classified as problematic. This issue affects some unknown processing of the file AdminRoleController.java. The manipulation leads …

Jun 16, 2025
CVE-2025-6105
4.3 MEDIUM

A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.java. The manipulation of …

Jun 16, 2025
CVE-2025-6101
5.5 MEDIUM

A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation …

Jun 16, 2025
CVE-2025-6100
6.3 MEDIUM

A vulnerability was found in realguoshuai open-video-cms 1.0. It has been rated as critical. This issue affects some unknown processing of the file /v1/video/list. The …

Jun 16, 2025
CVE-2025-6099
5.3 MEDIUM

A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerability affects unknown code of the file gin-blog-server/internal/manager.go …

Jun 16, 2025
CVE-2025-6097
5.3 MEDIUM

A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function formDefineManagement of the …

Jun 16, 2025
CVE-2025-6096
6.3 MEDIUM

A vulnerability has been found in codesiddhant Jasmin Ransomware up to 1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jun 16, 2025
CVE-2025-6094
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file …

Jun 15, 2025
CVE-2025-6093
5.5 MEDIUM

A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a275d1007e295. This vulnerability affects the function heartrate1_i2c_hal_write of the file 7.Example/hal/i2c/max30100/Manual/demo2/2/heartrate1_hal.c. The manipulation …

Jun 15, 2025
CVE-2025-5964
6.5 MEDIUM

A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.

Jun 15, 2025
CVE-2025-6092
4.3 MEDIUM

A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jun 15, 2025
CVE-2025-6089
4.3 MEDIUM

A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the file atCheckJS.aspx. The …

Jun 15, 2025
CVE-2025-36041
4.7 MEDIUM

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator …

Jun 15, 2025
CVE-2025-5337
6.4 MEDIUM

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, …

Jun 14, 2025
CVE-2025-5238
6.4 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.5.0 …

Jun 14, 2025
CVE-2025-4667
6.4 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and …

Jun 14, 2025
CVE-2025-6070
6.5 MEDIUM

The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.2 via the output() function. This …

Jun 14, 2025
CVE-2025-6064
6.1 MEDIUM

The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to …

Jun 14, 2025
CVE-2025-6063
6.1 MEDIUM

The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing …

Jun 14, 2025
CVE-2025-6062
4.3 MEDIUM

The Yougler Blogger Profile Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, v1.01. This is due …

Jun 14, 2025
CVE-2025-6061
6.4 MEDIUM

The kk Youtube Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kkytv' shortcode in all versions up to, and including, …

Jun 14, 2025
CVE-2025-6055
6.1 MEDIUM

The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to …

Jun 14, 2025
CVE-2025-6040
6.1 MEDIUM

The Easy Flashcards plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1. This is due to missing …

Jun 14, 2025
CVE-2025-5589
6.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘status-classic-offline-text’ parameter in all versions up to, and including, 1.1.3 …

Jun 14, 2025
CVE-2025-5336
6.4 MEDIUM

The Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-no_number’ parameter in all versions up to, and including, 4.22 …

Jun 14, 2025
CVE-2025-4592
4.3 MEDIUM

The AI Image Lab – Free AI Image Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 14, 2025
CVE-2025-4216
6.4 MEDIUM

The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and …

Jun 14, 2025
CVE-2025-4187
5.9 MEDIUM

The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.1.10 …

Jun 14, 2025
CVE-2025-6059
4.3 MEDIUM

The Seraphinite Accelerator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.27.21. This is due to missing …

Jun 14, 2025
CVE-2025-6083
4.3 MEDIUM

In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search …

Jun 13, 2025
CVE-2025-6035
6.1 MEDIUM

A flaw was found in GIMP. An integer overflow vulnerability exists in the GIMP "Despeckle" plug-in. The issue occurs due to unchecked multiplication of image …

Jun 13, 2025
CVE-2025-48919
5.0 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 …

Jun 13, 2025
CVE-2025-48917
5.0 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal EU Cookie Compliance (GDPR Compliance) allows Cross-Site Scripting (XSS).This issue affects EU …

Jun 13, 2025
CVE-2025-48916
6.5 MEDIUM

Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.13.

Jun 13, 2025
CVE-2025-28380
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Jun 13, 2025
CVE-2025-46096
6.1 MEDIUM

Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component

Jun 13, 2025
CVE-2025-36506
6.5 MEDIUM

External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a …

Jun 13, 2025
CVE-2025-6012
5.5 MEDIUM

The Auto Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.5 due to …

Jun 13, 2025
CVE-2025-5923
6.4 MEDIUM

The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 4.8.1 …

Jun 13, 2025
CVE-2025-22242
5.6 MEDIUM

Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method which is exposed to all minions. The un-sanitized …

Jun 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.