CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4080
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 29, 2025
CVE-2025-4078
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. …

Apr 29, 2025
CVE-2025-4077
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects School Billing System 1.0. This vulnerability affects the function searchrec. The manipulation of the argument Name …

Apr 29, 2025
CVE-2025-4076
6.3 MEDIUM

A vulnerability classified as critical has been found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function easy_uci_set_option_string_0 of the file /cgi-bin/lighttpd.cgi of the …

Apr 29, 2025
CVE-2025-4075
4.3 MEDIUM

A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unknown functionality of the …

Apr 29, 2025
CVE-2025-4072
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-nurse.php. …

Apr 29, 2025
CVE-2025-0716
4.8 MEDIUM

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. …

Apr 29, 2025
CVE-2025-4069
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Product Management System 1.0. Affected by this issue is the function add_item. The …

Apr 29, 2025
CVE-2025-4068
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by this vulnerability is the function changeprize. The manipulation …

Apr 29, 2025
CVE-2025-46346
5.4 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, a stored cross-site scripting (XSS) vulnerability was discovered in the application’s comments feature. …

Apr 29, 2025
CVE-2025-40616
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL …

Apr 29, 2025
CVE-2025-40615
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL …

Apr 29, 2025
CVE-2025-23179
5.5 MEDIUM

CWE-798: Use of Hard-coded Credentials

Apr 29, 2025
CVE-2025-1551
6.1 MEDIUM

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code …

Apr 29, 2025
CVE-2025-4067
5.3 MEDIUM

A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to …

Apr 29, 2025
CVE-2025-4092
6.5 MEDIUM

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Apr 29, 2025
CVE-2025-4090
5.3 MEDIUM

A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed in Firefox 138 and Thunderbird …

Apr 29, 2025
CVE-2025-4089
5.1 MEDIUM

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading …

Apr 29, 2025
CVE-2025-4088
6.5 MEDIUM

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the …

Apr 29, 2025
CVE-2025-4087
4.8 MEDIUM

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to …

Apr 29, 2025
CVE-2025-4086
6.5 MEDIUM

A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug …

Apr 29, 2025
CVE-2025-4084
5.7 MEDIUM

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially …

Apr 29, 2025
CVE-2025-4082
5.9 MEDIUM

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug …

Apr 29, 2025
CVE-2025-4064
5.3 MEDIUM

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation …

Apr 29, 2025
CVE-2025-4063
5.3 MEDIUM

A vulnerability was found in code-projects Student Information Management System 1.0 and classified as critical. Affected by this issue is the function cancel. The manipulation …

Apr 29, 2025
CVE-2025-4062
5.3 MEDIUM

A vulnerability has been found in code-projects Theater Seat Booking System 1.0 and classified as critical. Affected by this vulnerability is the function cancel. The …

Apr 29, 2025
CVE-2025-4061
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Clothing Store Management System up to 1.0. Affected is the function add_item. The manipulation …

Apr 29, 2025
CVE-2025-4035
4.3 MEDIUM

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains …

Apr 29, 2025
CVE-2025-4059
5.3 MEDIUM

A vulnerability classified as critical was found in code-projects Prison Management System 1.0. This vulnerability affects the function addrecord of the component Prison_Mgmt_Sys. The manipulation …

Apr 29, 2025
CVE-2025-3929
6.1 MEDIUM

An XSS issue was discovered in MDaemon Email Server version 25.0.1 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript …

Apr 29, 2025
CVE-2025-1194
6.5 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file `tokenization_gpt_neox_japanese.py` of the GPT-NeoX-Japanese model. The vulnerability …

Apr 29, 2025
CVE-2024-58099
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported connectivity issues with Cilium's service …

Apr 29, 2025
CVE-2025-3452
4.3 MEDIUM

The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'secupress_reinstall_plugins_admin_ajax_cb' …

Apr 29, 2025
CVE-2025-2893
6.4 MEDIUM

The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown …

Apr 29, 2025
CVE-2025-46343
5.0 MEDIUM

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows …

Apr 29, 2025
CVE-2025-46338
6.1 MEDIUM

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to …

Apr 29, 2025
CVE-2025-31203
6.5 MEDIUM

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-31202
5.5 MEDIUM

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, …

Apr 29, 2025
CVE-2025-31197
5.7 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, …

Apr 29, 2025
CVE-2025-30445
6.5 MEDIUM

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-24271
5.4 MEDIUM

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-24270
5.7 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS …

Apr 29, 2025
CVE-2025-24251
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, …

Apr 29, 2025
CVE-2025-24179
5.7 MEDIUM

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, …

Apr 29, 2025
CVE-2025-4038
5.3 MEDIUM

A vulnerability was found in code-projects Train Ticket Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is the function Reservation …

Apr 28, 2025
CVE-2025-4037
4.4 MEDIUM

A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function moneyDeposit/moneyWithdraw. The manipulation leads to business …

Apr 28, 2025
CVE-2024-11922
6.3 MEDIUM

Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails …

Apr 28, 2025
CVE-2024-10635
6.1 MEDIUM

Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending …

Apr 28, 2025
CVE-2025-4036
6.3 MEDIUM

A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBookChapter of the file src/main/java/io/github/xxyopen/novel/controller/author/AuthorController.java of the component …

Apr 28, 2025
CVE-2025-4032
5.0 MEDIUM

A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the function subprocess.run/subprocess.Popen of the file …

Apr 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.