CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46080
5.3 MEDIUM

HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby …

May 29, 2025
CVE-2025-46078
5.3 MEDIUM

HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server

May 29, 2025
CVE-2025-37999
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/erofs/fileio: call erofs_onlinefolio_split() after bio_add_folio() If bio_add_folio() fails (because it is full), erofs_fileio_scan_folio() needs to …

May 29, 2025
CVE-2025-37998
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output_userspace() This patch replaces the manual Netlink attribute iteration …

May 29, 2025
CVE-2025-37997
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4 contained three …

May 29, 2025
CVE-2025-37996
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in user_mem_abort() Commit fce886a60207 ("KVM: arm64: Plumb the pKVM …

May 29, 2025
CVE-2025-37995
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: module: ensure that kobject_put() is safe for module type kobjects In 'lookup_or_create_module_kobject()', an internal kobject …

May 29, 2025
CVE-2025-37994
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix NULL pointer access This patch ensures that the UCSI driver …

May 29, 2025
CVE-2025-37993
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_class_allocate_dev(): initialize spin lock on device probe The spin lock tx_handling_spinlock in struct …

May 29, 2025
CVE-2025-33043
5.8 MEDIUM

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerability can potentially impact of …

May 29, 2025
CVE-2025-48388
6.5 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used …

May 29, 2025
CVE-2025-5286
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘additional_settings’ parameter in all versions up to, and including, 5.3.6 …

May 29, 2025
CVE-2025-5122
6.4 MEDIUM

The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.2.1 …

May 29, 2025
CVE-2025-4670
6.4 MEDIUM

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode …

May 29, 2025
CVE-2025-27151
4.7 MEDIUM

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in …

May 29, 2025
CVE-2024-52588
4.9 MEDIUM

Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching …

May 29, 2025
CVE-2025-5273
6.5 MEDIUM

All versions of the package mcp-markdownify-server are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a …

May 29, 2025
CVE-2025-4583
5.4 MEDIUM

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-plugin` attribute in …

May 29, 2025
CVE-2025-27703
6.0 MEDIUM

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific …

May 28, 2025
CVE-2025-27702
4.9 MEDIUM

CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who …

May 28, 2025
CVE-2025-5256
5.4 MEDIUM

SummaryThis advisory addresses an Open Redirection vulnerability in Mautic's user unlocking endpoint. This vulnerability could be exploited by an attacker to redirect legitimate users to …

May 28, 2025
CVE-2025-48747
5.0 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.

May 28, 2025
CVE-2025-47748
5.3 MEDIUM

Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.

May 28, 2025
CVE-2025-32803
4.0 MEDIUM

In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 …

May 28, 2025
CVE-2025-1461
5.6 MEDIUM

Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows unsanitized HTML to be inserted into the page. This …

May 28, 2025
CVE-2024-57338
6.5 MEDIUM

An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute …

May 28, 2025
CVE-2024-57337
6.5 MEDIUM

An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to …

May 28, 2025
CVE-2024-57336
6.5 MEDIUM

Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.

May 28, 2025
CVE-2024-47057
5.3 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate …

May 28, 2025
CVE-2024-47055
4.3 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper …

May 28, 2025
CVE-2025-5257
6.5 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This …

May 28, 2025
CVE-2025-48929
4.0 MEDIUM

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at …

May 28, 2025
CVE-2025-48928
4.0 MEDIUM KEV

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which …

May 28, 2025
CVE-2025-48927
5.3 MEDIUM KEV

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in …

May 28, 2025
CVE-2025-48926
4.3 MEDIUM

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

May 28, 2025
CVE-2025-48925
4.3 MEDIUM

The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as …

May 28, 2025
CVE-2025-48746
6.5 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.

May 28, 2025
CVE-2025-36572
6.5 MEDIUM

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the …

May 28, 2025
CVE-2025-32802
6.1 MEDIUM

Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, …

May 28, 2025
CVE-2024-47056
5.1 MEDIUM

SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be directly accessible via a web browser. This exposure could lead …

May 28, 2025
CVE-2024-51453
4.3 MEDIUM

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted …

May 28, 2025
CVE-2024-38341
5.9 MEDIUM

IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker …

May 28, 2025
CVE-2025-4493
6.5 MEDIUM

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting …

May 28, 2025
CVE-2025-5297
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file …

May 28, 2025
CVE-2025-4963
6.4 MEDIUM

The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.15 due …

May 28, 2025
CVE-2025-5082
6.1 MEDIUM

The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ parameter in all versions up to, and including, 5.0.12 due …

May 28, 2025
CVE-2025-47294
5.3 MEDIUM

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the …

May 28, 2025
CVE-2025-27526
6.5 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability …

May 28, 2025
CVE-2025-27522
6.5 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for …

May 28, 2025
CVE-2025-5025
4.8 MEDIUM

libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC …

May 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.