CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9302
7.3 HIGH

A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid …

Aug 21, 2025
CVE-2025-9301
3.3 LOW

A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to …

Aug 21, 2025
CVE-2025-55564
7.5 HIGH

Tenda AC15 v15.03.05.19_multi_TD01 has a stack overflow via the list parameter in the fromSetIpMacBind function.

Aug 21, 2025
CVE-2025-55370
8.8 HIGH

Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.

Aug 21, 2025
CVE-2025-55368
8.8 HIGH

Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

Aug 21, 2025
CVE-2025-55367
5.3 MEDIUM

Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

Aug 21, 2025
CVE-2025-55366
5.3 MEDIUM

Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.

Aug 21, 2025
CVE-2025-51818
5.4 MEDIUM

MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

Aug 21, 2025
CVE-2025-34158
8.5 HIGH

Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server …

Aug 21, 2025
CVE-2025-9300
5.3 MEDIUM

A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component …

Aug 21, 2025
CVE-2025-9299
8.8 HIGH

A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /goform/getMasterPassengerAnalyseData. The manipulation of the …

Aug 21, 2025
CVE-2025-9298
8.8 HIGH

A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can …

Aug 21, 2025
CVE-2025-9297
8.8 HIGH

A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /goform/wxportalauth. Performing manipulation of the argument Type results in …

Aug 21, 2025
CVE-2025-47184
5.3 MEDIUM

An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 P12, and 7.2.0 P08 allows an …

Aug 21, 2025
CVE-2025-9296
4.7 MEDIUM

A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the …

Aug 21, 2025
CVE-2025-8064
6.4 MEDIUM

The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘selector_height’ parameter in all versions up to, and including, 6.0.1 due …

Aug 21, 2025
CVE-2025-8895
9.8 CRITICAL

The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and …

Aug 21, 2025
CVE-2025-8023
6.8 MEDIUM

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, …

Aug 21, 2025
CVE-2025-53971
3.8 LOW

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team …

Aug 21, 2025
CVE-2025-49810
3.5 LOW

Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts

Aug 21, 2025
CVE-2025-49222
6.8 MEDIUM

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster …

Aug 21, 2025
CVE-2025-47870
4.3 MEDIUM

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore …

Aug 21, 2025
CVE-2025-47700
3.5 LOW

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious …

Aug 21, 2025
CVE-2025-36530
6.8 MEDIUM

Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which …

Aug 21, 2025
CVE-2025-8607
6.4 MEDIUM

The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown block's attributes in …

Aug 21, 2025
CVE-2025-8592
8.1 HIGH

The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or …

Aug 21, 2025
CVE-2025-7390
9.1 CRITICAL

A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.

Aug 21, 2025
CVE-2025-7221
4.3 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Aug 21, 2025
CVE-2025-53505
5.3 MEDIUM

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited, information on …

Aug 21, 2025
CVE-2025-53504
5.4 MEDIUM

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary …

Aug 21, 2025
CVE-2025-57832

Rejected reason: Not used

Aug 21, 2025
CVE-2025-57831

Rejected reason: Not used

Aug 21, 2025
CVE-2025-57830

Rejected reason: Not used

Aug 21, 2025
CVE-2025-57829

Rejected reason: Not used

Aug 21, 2025
CVE-2025-57828

Rejected reason: Not used

Aug 21, 2025
CVE-2025-57827

Rejected reason: Not used

Aug 21, 2025
CVE-2025-57826

Rejected reason: Not used

Aug 21, 2025
CVE-2025-57825

Rejected reason: Not used

Aug 21, 2025
CVE-2025-57824

Rejected reason: Not used

Aug 21, 2025
CVE-2025-48355
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ProveSource LTD ProveSource Social Proof provesource allows Retrieve Embedded Sensitive Data.This issue affects …

Aug 21, 2025
CVE-2025-48978
7.5 HIGH

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent …

Aug 21, 2025
CVE-2025-43300
10.0 CRITICAL KEV

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, …

Aug 21, 2025
CVE-2025-27217
9.1 CRITICAL

A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP Application scope.

Aug 21, 2025
CVE-2025-27216
8.8 HIGH

Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate privileges.

Aug 21, 2025
CVE-2025-27215
8.1 HIGH

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to …

Aug 21, 2025
CVE-2025-27214
9.8 CRITICAL

A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent access to …

Aug 21, 2025
CVE-2025-27213
4.9 MEDIUM

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and …

Aug 21, 2025
CVE-2025-24285
9.8 CRITICAL

Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network access to the …

Aug 21, 2025
CVE-2025-9264
5.4 MEDIUM

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component …

Aug 21, 2025
CVE-2025-9263
4.3 MEDIUM

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation …

Aug 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.