CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40626
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim …

May 12, 2025
CVE-2025-22247
6.1 MEDIUM

VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger …

May 12, 2025
CVE-2025-41393
6.1 MEDIUM

Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may …

May 12, 2025
CVE-2025-4560
6.5 MEDIUM

The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system functions. These functions include viewing the administrator list, …

May 12, 2025
CVE-2025-3649
6.8 MEDIUM

The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role …

May 12, 2025
CVE-2025-3597
5.9 MEDIUM

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is …

May 12, 2025
CVE-2025-4552
5.4 MEDIUM

A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

May 12, 2025
CVE-2025-4546
4.7 MEDIUM

A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 11, 2025
CVE-2025-4545
5.4 MEDIUM

A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\controllers\admin\Tpl.php …

May 11, 2025
CVE-2025-4544
6.6 MEDIUM

A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of …

May 11, 2025
CVE-2025-4541
6.3 MEDIUM

A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\admin\ZtAction.class.php of the component POST Request …

May 11, 2025
CVE-2025-4538
6.3 MEDIUM

A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of …

May 11, 2025
CVE-2025-4536
5.3 MEDIUM

A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classified as critical. Affected by this vulnerability is an unknown …

May 11, 2025
CVE-2025-4535
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0. Affected is an unknown function of the …

May 11, 2025
CVE-2025-4531
6.3 MEDIUM

A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected by this issue is the …

May 11, 2025
CVE-2025-4530
4.3 MEDIUM

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. It has been declared as problematic. Affected by this vulnerability is the function handleFileDownload of …

May 11, 2025
CVE-2025-4529
4.3 MEDIUM

A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been classified as problematic. Affected is the function Download of …

May 11, 2025
CVE-2025-4528
4.3 MEDIUM

A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic. This issue affects some unknown processing. The manipulation leads to …

May 11, 2025
CVE-2025-47828
6.4 MEDIUM

Lumi H5P-Nodejs-library before 9.3.3 omits a sanitizeHtml call for plain text strings.

May 11, 2025
CVE-2025-4526
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Dígitro NGC Explorer 3.44.15. This affects an unknown part of the component Configuration Page. The …

May 11, 2025
CVE-2025-47815
4.5 MEDIUM

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.

May 10, 2025
CVE-2025-47814
4.5 MEDIUM

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.

May 10, 2025
CVE-2025-4515
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The …

May 10, 2025
CVE-2025-4514
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Zhengzhou Jiuhua Electronic Technology mayicms up to 5.8E. Affected by this issue is some …

May 10, 2025
CVE-2025-4513
4.3 MEDIUM

A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of …

May 10, 2025
CVE-2025-4512
4.3 MEDIUM

A vulnerability classified as problematic has been found in Inetum IODAS 7.2-LTS.4.1-JDK7/7.2-RC3.2-JDK7. Affected is an unknown function of the file /astre/iodasweb/app.jsp. The manipulation of the …

May 10, 2025
CVE-2025-4511
6.3 MEDIUM

A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file …

May 10, 2025
CVE-2025-4510
6.3 MEDIUM

A vulnerability was found in Changjietong UFIDA CRM 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /optnty/optntyday.php. The …

May 10, 2025
CVE-2025-4501
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0. This affects the function searchalbum of the component Search Albums. …

May 10, 2025
CVE-2025-4500
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected by this issue is the function Edit of …

May 10, 2025
CVE-2025-4499
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component …

May 10, 2025
CVE-2025-3878
6.4 MEDIUM

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up …

May 10, 2025
CVE-2025-4498
5.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. …

May 10, 2025
CVE-2025-4497
5.3 MEDIUM

A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of …

May 10, 2025
CVE-2025-2944
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button and Countdown Widgets in all versions up …

May 10, 2025
CVE-2025-3794
5.4 MEDIUM

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

May 9, 2025
CVE-2025-1993
5.1 MEDIUM

IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, …

May 9, 2025
CVE-2025-4480
5.3 MEDIUM

A vulnerability was found in code-projects Simple College Management System 1.0. It has been declared as critical. This vulnerability affects the function input of the …

May 9, 2025
CVE-2025-1278
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions …

May 9, 2025
CVE-2025-0549
6.8 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 …

May 9, 2025
CVE-2024-8973
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 …

May 9, 2025
CVE-2025-4432
5.3 MEDIUM

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows …

May 9, 2025
CVE-2025-28201
6.8 MEDIUM

An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.

May 9, 2025
CVE-2025-4382
5.9 MEDIUM

A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys …

May 9, 2025
CVE-2025-3897
5.9 MEDIUM

The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' function. This makes …

May 9, 2025
CVE-2025-46392
6.5 MEDIUM

Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption …

May 9, 2025
CVE-2025-3949
4.3 MEDIUM

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of …

May 9, 2025
CVE-2025-4472
5.3 MEDIUM

A vulnerability was found in code-projects Departmental Store Management System 1.0. It has been classified as critical. Affected is the function bill. The manipulation of …

May 9, 2025
CVE-2025-4471
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Jewelery Store Management system 1.0. Affected by this issue is some unknown functionality …

May 9, 2025
CVE-2025-37889
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Consistently treat platform_max as control value This reverts commit 9bdd10d57a88 ("ASoC: ops: Shift …

May 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.