CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54925
7.5 HIGH

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the application to access a malicious …

Aug 20, 2025
CVE-2025-54924
7.5 HIGH

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker sends a specially crafted document to a …

Aug 20, 2025
CVE-2025-54923

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to …

Aug 20, 2025
CVE-2025-50503
8.8 HIGH

A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By …

Aug 20, 2025
CVE-2025-32010
8.1 HIGH

A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary …

Aug 20, 2025
CVE-2025-31355
7.2 HIGH

A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted malicious file can lead to arbitrary …

Aug 20, 2025
CVE-2025-30256
8.6 HIGH

A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HTTP requests can …

Aug 20, 2025
CVE-2025-27129
9.8 CRITICAL

An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code …

Aug 20, 2025
CVE-2025-24496
7.5 HIGH

An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclosure of sensitive …

Aug 20, 2025
CVE-2025-24322
8.1 HIGH

An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to …

Aug 20, 2025
CVE-2025-8453
6.7 MEDIUM

CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a …

Aug 20, 2025
CVE-2025-54175
6.1 MEDIUM

QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality. An attacker can craft a malicious URL that results in arbitrary JavaScript …

Aug 20, 2025
CVE-2025-54174
4.3 MEDIUM

QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically …

Aug 20, 2025
CVE-2025-54172
4.8 MEDIUM

QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into …

Aug 20, 2025
CVE-2025-4877
4.5 MEDIUM

There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer to ssh_get_fingerprint_hash() function. In such cases …

Aug 20, 2025
CVE-2025-4437
5.7 MEDIUM

There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading …

Aug 20, 2025
CVE-2025-43750
6.5 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 …

Aug 20, 2025
CVE-2025-43749
5.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 …

Aug 20, 2025
CVE-2025-8102
5.4 MEDIUM

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to …

Aug 20, 2025
CVE-2025-7777
6.5 MEDIUM

The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or …

Aug 20, 2025
CVE-2025-43742
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, …

Aug 20, 2025
CVE-2025-43741
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.3, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, …

Aug 20, 2025
CVE-2025-57734
4.3 MEDIUM

In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files

Aug 20, 2025
CVE-2025-57733
5.5 MEDIUM

In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content

Aug 20, 2025
CVE-2025-57732
7.5 HIGH

In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership

Aug 20, 2025
CVE-2025-57731
8.7 HIGH

In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content

Aug 20, 2025
CVE-2025-57730
5.2 MEDIUM

In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature

Aug 20, 2025
CVE-2025-57729
6.5 MEDIUM

In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

Aug 20, 2025
CVE-2025-57728
6.5 MEDIUM

In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

Aug 20, 2025
CVE-2025-57727
4.7 MEDIUM

In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference

Aug 20, 2025
CVE-2025-9229
5.3 MEDIUM

Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated attackers to view detailed error information, such as file paths …

Aug 20, 2025
CVE-2025-9228
4.3 MEDIUM

MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowing low-privilege users to create notes which are intended only …

Aug 20, 2025
CVE-2025-5261
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Exploitation of Trusted Identifiers.This issue affects Pik Online: before 3.1.5.

Aug 20, 2025
CVE-2025-5260
8.6 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Request Forgery.This issue affects Pik Online: before 3.1.5.

Aug 20, 2025
CVE-2024-39954
6.3 MEDIUM

CWE-918 Server-Side Request Forgery (SSRF) in eventmesh-runtime module in WebhookUtil.java on windows\linux\mac os e.g. allows the attacker can abuse functionality on the server to read …

Aug 20, 2025
CVE-2025-9225
5.5 MEDIUM

Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fleet allows execution of arbitrary …

Aug 20, 2025
CVE-2025-55715
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Retrieve Embedded Sensitive Data.This issue affects Otter - Gutenberg …

Aug 20, 2025
CVE-2025-54750
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows PHP Local …

Aug 20, 2025
CVE-2025-54735
8.8 HIGH

Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a through <= 1.1.24.

Aug 20, 2025
CVE-2025-54726
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects …

Aug 20, 2025
CVE-2025-54713
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse.This issue affects Taxi Booking Manager …

Aug 20, 2025
CVE-2025-54677
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Malicious Files.This issue …

Aug 20, 2025
CVE-2025-54670
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oik allows Reflected XSS.This issue affects oik: from n/a through <= …

Aug 20, 2025
CVE-2025-54056
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playlist lbg-audio2-html5 allows Reflected XSS.This issue …

Aug 20, 2025
CVE-2025-54055
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Druco druco allows Reflected XSS.This issue affects Druco: from n/a through <= …

Aug 20, 2025
CVE-2025-54053
6.6 MEDIUM

Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2.

Aug 20, 2025
CVE-2025-54052
7.5 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows PHP Local File Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a …

Aug 20, 2025
CVE-2025-54049
9.9 CRITICAL

Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2.

Aug 20, 2025
CVE-2025-54048
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects …

Aug 20, 2025
CVE-2025-54046
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Stored XSS.This issue affects Cost Calculator: from n/a …

Aug 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.