CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-42984
5.4 MEDIUM

SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function …

Jun 10, 2025
CVE-2025-31325
5.8 MEDIUM

Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an …

Jun 10, 2025
CVE-2025-0037
6.6 MEDIUM

In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated …

Jun 10, 2025
CVE-2025-30507
5.3 MEDIUM

CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.

Jun 9, 2025
CVE-2025-5900
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. …

Jun 9, 2025
CVE-2025-5899
5.3 MEDIUM

A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation …

Jun 9, 2025
CVE-2025-5898
5.3 MEDIUM

A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to …

Jun 9, 2025
CVE-2025-5897
4.3 MEDIUM

A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file …

Jun 9, 2025
CVE-2025-5896
4.3 MEDIUM

A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. …

Jun 9, 2025
CVE-2025-49139
5.3 MEDIUM

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can …

Jun 9, 2025
CVE-2025-49138
6.5 MEDIUM

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability …

Jun 9, 2025
CVE-2025-5915
6.6 MEDIUM

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter …

Jun 9, 2025
CVE-2025-5895
4.3 MEDIUM

A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads …

Jun 9, 2025
CVE-2025-5892
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. …

Jun 9, 2025
CVE-2025-5891
4.3 MEDIUM

A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code of the file /lib/tools/Config.js. The manipulation leads …

Jun 9, 2025
CVE-2025-5890
4.3 MEDIUM

A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. …

Jun 9, 2025
CVE-2025-5888
4.3 MEDIUM

A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads …

Jun 9, 2025
CVE-2024-47081
5.3 MEDIUM

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific …

Jun 9, 2025
CVE-2025-46041
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation …

Jun 9, 2025
CVE-2025-45002
5.4 MEDIUM

Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my profile.

Jun 9, 2025
CVE-2025-29627
6.8 MEDIUM

An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module

Jun 9, 2025
CVE-2024-46452
6.1 MEDIUM

A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b allows attackers to redirect victim users to …

Jun 9, 2025
CVE-2025-48147
6.5 MEDIUM

Missing Authorization vulnerability in Crypto Cloud CryptoCloud - Crypto Payment Gateway cryptocloud-crypto-payment-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CryptoCloud - Crypto …

Jun 9, 2025
CVE-2025-48139
6.5 MEDIUM

Missing Authorization vulnerability in relentlo StyleAI relentlosoftware allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects StyleAI: from n/a through <= 1.0.4.

Jun 9, 2025
CVE-2025-47598
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in click5 History Log by click5 history-log-by-click5 allows Stored XSS.This issue affects History Log …

Jun 9, 2025
CVE-2025-47511
6.8 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Path Traversal.This issue affects Welcart e-Commerce: from …

Jun 9, 2025
CVE-2025-46178
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in …

Jun 9, 2025
CVE-2025-45055
5.4 MEDIUM

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an …

Jun 9, 2025
CVE-2025-5885
4.3 MEDIUM

A vulnerability has been found in Konica Minolta bizhub up to 20250202 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to …

Jun 9, 2025
CVE-2025-5881
6.3 MEDIUM

A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. …

Jun 9, 2025
CVE-2025-5880
4.3 MEDIUM

A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the …

Jun 9, 2025
CVE-2025-5877
6.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the …

Jun 9, 2025
CVE-2025-49131
6.3 MEDIUM

FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-sandbox) is a …

Jun 9, 2025
CVE-2025-40669
6.5 MEDIUM

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including …

Jun 9, 2025
CVE-2025-40668
6.5 MEDIUM

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a …

Jun 9, 2025
CVE-2025-5876
5.3 MEDIUM

A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability is an unknown functionality. The …

Jun 9, 2025
CVE-2025-5874
4.6 MEDIUM

A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as problematic. This issue affects the function run_query of the file /query_runner/python.py …

Jun 9, 2025
CVE-2025-5873
6.3 MEDIUM

A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmware.php …

Jun 9, 2025
CVE-2025-41437
4.3 MEDIUM

Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.

Jun 9, 2025
CVE-2025-5872
5.3 MEDIUM

A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting …

Jun 9, 2025
CVE-2025-5871
5.3 MEDIUM

A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality of the component …

Jun 9, 2025
CVE-2025-40675
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser …

Jun 9, 2025
CVE-2025-4652
6.1 MEDIUM

The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jun 9, 2025
CVE-2025-47712
6.5 MEDIUM

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status …

Jun 9, 2025
CVE-2025-47711
6.5 MEDIUM

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific …

Jun 9, 2025
CVE-2025-3582
4.8 MEDIUM

The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin …

Jun 9, 2025
CVE-2025-3581
4.8 MEDIUM

The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the …

Jun 9, 2025
CVE-2025-25209
5.7 MEDIUM

The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead …

Jun 9, 2025
CVE-2025-25208
5.7 MEDIUM

A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster

Jun 9, 2025
CVE-2025-25207
5.7 MEDIUM

The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona …

Jun 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.