CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43921
5.3 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that …

Apr 20, 2025
CVE-2025-43920
5.4 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters …

Apr 20, 2025
CVE-2025-43919
5.8 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private …

Apr 20, 2025
CVE-2025-43918
6.4 MEDIUM

SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain …

Apr 19, 2025
CVE-2025-3818
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of …

Apr 19, 2025
CVE-2025-3817
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file …

Apr 19, 2025
CVE-2025-3816
4.7 MEDIUM

A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task …

Apr 19, 2025
CVE-2025-3808
4.3 MEDIUM

A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. …

Apr 19, 2025
CVE-2025-3807
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/UploadController.java of the component …

Apr 19, 2025
CVE-2025-3805
5.3 MEDIUM

A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file check_id.py …

Apr 19, 2025
CVE-2025-3804
5.3 MEDIUM

A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 …

Apr 19, 2025
CVE-2025-3798
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminController.php of the …

Apr 19, 2025
CVE-2025-3661
6.4 MEDIUM

The SB Chart block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.2.6 …

Apr 19, 2025
CVE-2025-3797
4.7 MEDIUM

A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=delall. The manipulation of the …

Apr 19, 2025
CVE-2025-3275
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, …

Apr 19, 2025
CVE-2025-1457
6.4 MEDIUM

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Apr 19, 2025
CVE-2025-3284
4.3 MEDIUM

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Apr 19, 2025
CVE-2025-43903
4.3 MEDIUM

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Apr 18, 2025
CVE-2025-3796
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The …

Apr 18, 2025
CVE-2025-36625
4.3 MEDIUM

In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application.

Apr 18, 2025
CVE-2025-32377
6.5 MEDIUM

Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa …

Apr 18, 2025
CVE-2025-25984
6.8 MEDIUM

An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.

Apr 18, 2025
CVE-2024-57493
5.5 MEDIUM

An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockopt function.

Apr 18, 2025
CVE-2025-28355
4.7 MEDIUM

Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the …

Apr 18, 2025
CVE-2025-29513
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code in the admin API Access token generator.

Apr 18, 2025
CVE-2025-29512
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until …

Apr 18, 2025
CVE-2024-41447
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 18, 2025
CVE-2025-32796
6.5 MEDIUM

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or …

Apr 18, 2025
CVE-2025-32795
6.5 MEDIUM

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted …

Apr 18, 2025
CVE-2025-32389
6.5 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by …

Apr 18, 2025
CVE-2025-31120
5.3 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in …

Apr 18, 2025
CVE-2025-27599
6.5 MEDIUM

Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed …

Apr 18, 2025
CVE-2025-3792
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. …

Apr 18, 2025
CVE-2025-3791
5.3 MEDIUM

A vulnerability classified as critical was found in symisc UnQLite up to 957c377cb691a4f617db9aba5cc46d90425071e2. This vulnerability affects the function jx9MemObjStore of the file /data/src/benchmarks/unqlite/unqlite.c. The manipulation …

Apr 18, 2025
CVE-2025-2950
5.4 MEDIUM

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM …

Apr 18, 2025
CVE-2025-3790
5.3 MEDIUM

A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the component Apache …

Apr 18, 2025
CVE-2025-32790
6.3 MEDIUM

Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are …

Apr 18, 2025
CVE-2024-46089
6.3 MEDIUM

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

Apr 18, 2025
CVE-2024-49808
6.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization …

Apr 18, 2025
CVE-2024-45651
6.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate …

Apr 18, 2025
CVE-2025-3106
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions …

Apr 18, 2025
CVE-2025-3056
5.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due …

Apr 18, 2025
CVE-2025-40325
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard request with REQ_NOWAIT raid10_handle_discard should wait barrier before returning …

Apr 18, 2025
CVE-2025-39989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-from-user context Patch series "mm/hwpoison: Fix regressions in memory failure …

Apr 18, 2025
CVE-2025-39930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Don't use __free(device_node) at graph_util_parse_dai() commit 419d1918105e ("ASoC: simple-card-utils: use __free(device_node) for device …

Apr 18, 2025
CVE-2025-39755
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: Fix cb7210 pcmcia Oops The pcmcia_driver struct was still only using the old …

Apr 18, 2025
CVE-2025-39728
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: samsung: Fix UBSAN panic in samsung_clk_init() With UBSAN_ARRAY_BOUNDS=y, I'm hitting the below panic due …

Apr 18, 2025
CVE-2025-39688
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against …

Apr 18, 2025
CVE-2025-38637
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue assertions In the current implementation, skbprio enqueue/dequeue contains an …

Apr 18, 2025
CVE-2025-38575
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free() instead of kfree() to properly free memory …

Apr 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.