CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5859
6.3 MEDIUM

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Jun 9, 2025
CVE-2025-5858
6.3 MEDIUM

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Jun 9, 2025
CVE-2025-5857
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /urinalysis_record.php. …

Jun 9, 2025
CVE-2025-27247
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

Jun 8, 2025
CVE-2025-27131
6.1 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

Jun 8, 2025
CVE-2025-26691
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

Jun 8, 2025
CVE-2025-24493
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.

Jun 8, 2025
CVE-2025-38003
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is …

Jun 8, 2025
CVE-2025-5838
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file …

Jun 7, 2025
CVE-2025-5837
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The …

Jun 7, 2025
CVE-2025-5836
6.3 MEDIUM

A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of …

Jun 7, 2025
CVE-2025-5568
6.4 MEDIUM

The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient …

Jun 7, 2025
CVE-2025-5528
6.1 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up …

Jun 7, 2025
CVE-2024-9994
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2025
CVE-2024-9993
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2025
CVE-2025-5814
5.3 MEDIUM

The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 7, 2025
CVE-2025-49128
4.0 MEDIUM

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a …

Jun 6, 2025
CVE-2025-49599
4.1 MEDIUM

Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V5R021C00S184 allow the Epuser account to disable ONT firewall functionality, e.g., to …

Jun 6, 2025
CVE-2025-5784
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the file /myexp.php. …

Jun 6, 2025
CVE-2025-5783
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Employee Record Management System 1.3. This affects an unknown part of the file /editmyexp.php. …

Jun 6, 2025
CVE-2025-5751
6.8 MEDIUM

WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of …

Jun 6, 2025
CVE-2025-33035
6.5 MEDIUM

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the …

Jun 6, 2025
CVE-2025-29871
5.5 MEDIUM

An out-of-bounds read vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the …

Jun 6, 2025
CVE-2024-56805
5.4 MEDIUM

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Jun 6, 2025
CVE-2024-50406
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access …

Jun 6, 2025
CVE-2024-13087
6.7 MEDIUM

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they …

Jun 6, 2025
CVE-2025-5782
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. Affected by this issue is some unknown functionality …

Jun 6, 2025
CVE-2025-5780
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jun 6, 2025
CVE-2025-5779
6.3 MEDIUM

A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jun 6, 2025
CVE-2025-38002
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo() Not everything requires locking in there, which is why the …

Jun 6, 2025
CVE-2025-38001
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice Savino says: "We are writing …

Jun 6, 2025
CVE-2025-0620
4.9 MEDIUM

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue …

Jun 6, 2025
CVE-2025-5766
4.3 MEDIUM

A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site …

Jun 6, 2025
CVE-2025-49450
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mhallmann SEPA Girocode sepa-girocode allows Stored XSS.This issue affects SEPA Girocode: from n/a …

Jun 6, 2025
CVE-2025-49449
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa interactive-map-of-africa allows Cross Site Request Forgery.This issue affects Interactive Regional Map …

Jun 6, 2025
CVE-2025-49446
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.This issue affects Admin Notes: from n/a through <= 1.1.

Jun 6, 2025
CVE-2025-49445
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map interactive-uk-regional-map allows Cross Site Request Forgery.This issue affects Interactive UK Regional Map: …

Jun 6, 2025
CVE-2025-49443
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris McCoy Bacon Ipsum bacon-ipsum allows Stored XSS.This issue affects Bacon Ipsum: from …

Jun 6, 2025
CVE-2025-49442
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Simple Nested Menu simple-nested-menu allows Stored XSS.This issue affects Simple Nested …

Jun 6, 2025
CVE-2025-49441
5.3 MEDIUM

Missing Authorization vulnerability in WP Map Plugins Interactive Regional Map of Florida interactive-map-of-florida allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Interactive Regional …

Jun 6, 2025
CVE-2025-49440
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master wp-security-master allows Cross Site Request Forgery.This issue affects WP Security Master: from n/a through …

Jun 6, 2025
CVE-2025-49439
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in mariusz88atelierweb Atelier Create CV atelier-create-cv allows Cross Site Request Forgery.This issue affects Atelier Create CV: from n/a through <= …

Jun 6, 2025
CVE-2025-49435
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Hasina77 Wp Easy Allopass wordpress-easy-allopass allows Cross Site Request Forgery.This issue affects Wp Easy Allopass: from n/a through <= …

Jun 6, 2025
CVE-2025-49429
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Video Embeds video-embeds allows Stored XSS.This issue affects Video Embeds: from …

Jun 6, 2025
CVE-2025-49427
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Burnette Abbie Expander abbie-expander allows Stored XSS.This issue affects Abbie Expander: from …

Jun 6, 2025
CVE-2025-49419
5.5 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for WordPress esign-genie-for-wp allows Retrieve Embedded Sensitive Data.This issue affects …

Jun 6, 2025
CVE-2025-49333
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wp.insider Simple Membership simple-membership allows Stored XSS.This issue affects Simple Membership: from n/a …

Jun 6, 2025
CVE-2025-49332
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Cross Site Request Forgery.This issue affects WP Time Slots Booking Form: …

Jun 6, 2025
CVE-2025-49329
6.6 MEDIUM

Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to a Web Server.This issue …

Jun 6, 2025
CVE-2025-49325
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Automattic Newspack Newsletters newspack-newsletters allows Phishing.This issue affects Newspack Newsletters: from n/a through <= 3.13.0.

Jun 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.