CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5406
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an unknown function of the file /admin/posts.php?source=add_post. The …

Jun 1, 2025
CVE-2025-5404
4.3 MEDIUM

A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This vulnerability affects unknown code of the file /search.php of the component …

Jun 1, 2025
CVE-2025-5403
6.3 MEDIUM

A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This affects an unknown part of the file /admin/view_all_posts.php of the …

Jun 1, 2025
CVE-2025-33005
6.3 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on …

Jun 1, 2025
CVE-2025-33004
6.5 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.

Jun 1, 2025
CVE-2025-2896
4.8 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Jun 1, 2025
CVE-2025-25044
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Jun 1, 2025
CVE-2025-1499
6.5 MEDIUM

IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.

Jun 1, 2025
CVE-2025-5390
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the …

May 31, 2025
CVE-2025-5389
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the …

May 31, 2025
CVE-2025-5388
6.3 MEDIUM

A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The …

May 31, 2025
CVE-2025-5387
6.3 MEDIUM

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component …

May 31, 2025
CVE-2025-5386
6.3 MEDIUM

A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function transEditor of the file /cgformTransController.do?transEditor. …

May 31, 2025
CVE-2025-5385
6.3 MEDIUM

A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. …

May 31, 2025
CVE-2025-5384
6.3 MEDIUM

A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAutoListController of the file /cgAutoListController.do?datagrid. The …

May 31, 2025
CVE-2025-5380
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f5615e5a3d8bcbfbb. This issue affects some unknown processing of …

May 31, 2025
CVE-2025-5379
4.3 MEDIUM

A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation …

May 31, 2025
CVE-2025-5378
4.3 MEDIUM

A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown part of the file mycouncil2.aspx. The manipulation …

May 31, 2025
CVE-2025-5377
4.3 MEDIUM

A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

May 31, 2025
CVE-2025-4691
5.3 MEDIUM

The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

May 31, 2025
CVE-2025-5375
6.3 MEDIUM

A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critical. Affected is an unknown function of the …

May 31, 2025
CVE-2025-5374
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affects some unknown processing of the file /admin/all-applications.php. …

May 31, 2025
CVE-2025-5373
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/users-applications.php. …

May 31, 2025
CVE-2025-5290
6.4 MEDIUM

The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, …

May 31, 2025
CVE-2025-3813
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_elementor_data’ parameter in all versions up to, and …

May 31, 2025
CVE-2025-5292
6.4 MEDIUM

The Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder plugin for WordPress is vulnerable to Stored …

May 31, 2025
CVE-2025-5285
6.4 MEDIUM

The Product Subtitle for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmlTag’ parameter in all versions up to, and including, …

May 31, 2025
CVE-2025-4595
6.4 MEDIUM

The FastSpring plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fastspring/block-fastspringblocks-complete-product-catalog' block in all versions up to, and including, 3.0.1 due …

May 31, 2025
CVE-2025-4590
6.4 MEDIUM

The Daisycon prijsvergelijkers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'daisycon_uitvaart' shortcode in all versions up to, and including, 4.9.0 …

May 31, 2025
CVE-2025-5368
6.3 MEDIUM

A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affects some unknown processing of the …

May 31, 2025
CVE-2025-5016
4.7 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and …

May 31, 2025
CVE-2018-25111
5.1 MEDIUM

django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.

May 31, 2025
CVE-2025-48948
6.5 MEDIUM

Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any authenticated regular user …

May 30, 2025
CVE-2025-1479
5.3 MEDIUM

An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary …

May 30, 2025
CVE-2025-48944
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with …

May 30, 2025
CVE-2025-48943
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) …

May 30, 2025
CVE-2025-48942
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with …

May 30, 2025
CVE-2025-5054
4.7 MEDIUM

Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling …

May 30, 2025
CVE-2025-48887
6.5 MEDIUM

vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file `vllm/entrypoints/openai/tool_parsers/pythonic_tool_parser.py` of …

May 30, 2025
CVE-2024-42191
6.5 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with …

May 30, 2025
CVE-2024-42190
6.5 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with …

May 30, 2025
CVE-2024-23589
6.8 MEDIUM

Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware …

May 30, 2025
CVE-2025-3230
5.4 MEDIUM

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing …

May 30, 2025
CVE-2025-2571
4.2 MEDIUM

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to …

May 30, 2025
CVE-2024-7097
4.3 MEDIUM

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of …

May 30, 2025
CVE-2024-7096
4.2 MEDIUM

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a …

May 30, 2025
CVE-2025-4598
4.7 MEDIUM

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary …

May 30, 2025
CVE-2025-40909
5.9 MEDIUM

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the …

May 30, 2025
CVE-2025-1484
6.5 MEDIUM

A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or …

May 30, 2025
CVE-2025-4944
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in …

May 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.