CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45062
6.4 MEDIUM

A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer that supports IPP-over-USB can cause a buffer overflow which …

Aug 19, 2025
CVE-2025-9139
4.3 MEDIUM

A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information …

Aug 19, 2025
CVE-2025-9138
3.5 LOW

A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Performing manipulation of the argument Title results in cross …

Aug 19, 2025
CVE-2025-9137
3.5 LOW

A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm. Such manipulation of the argument alias leads to …

Aug 19, 2025
CVE-2025-43740
5.4 MEDIUM

A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 …

Aug 19, 2025
CVE-2025-9136
5.3 MEDIUM

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack …

Aug 19, 2025
CVE-2025-9135
5.3 MEDIUM

A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 12.1.1(258) on Android. The impacted element is an unknown function …

Aug 19, 2025
CVE-2025-9134
5.3 MEDIUM

A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected element is an unknown function of the …

Aug 19, 2025
CVE-2025-8783
4.4 MEDIUM

The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all versions up to, and including, 8.6.5 due …

Aug 19, 2025
CVE-2025-8567
6.4 MEDIUM

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to …

Aug 19, 2025
CVE-2025-41689
7.5 HIGH

An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access to the stored measurement data.

Aug 19, 2025
CVE-2025-41685
6.5 MEDIUM

A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.

Aug 19, 2025
CVE-2025-8723
9.8 CRITICAL

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in …

Aug 19, 2025
CVE-2025-8622
6.4 MEDIUM

The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortcode in all versions up to, and including, …

Aug 19, 2025
CVE-2025-7670
7.5 HIGH

The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in all versions up to, and including, 6.1.5 …

Aug 19, 2025
CVE-2025-7654
8.8 HIGH

Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, …

Aug 19, 2025
CVE-2025-8218
8.8 HIGH

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, …

Aug 19, 2025
CVE-2025-6758
9.8 CRITICAL

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, …

Aug 19, 2025
CVE-2025-38553
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: Restrict conditions for adding duplicating netems to qdisc tree netem_enqueue's duplication prevention logic breaks …

Aug 19, 2025
CVE-2025-8357
4.3 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user …

Aug 19, 2025
CVE-2025-5417
6.1 MEDIUM

An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has …

Aug 19, 2025
CVE-2025-7496
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements in all versions up to, and including, …

Aug 19, 2025
CVE-2025-57725

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57724

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57723

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57722

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57721

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57720

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57719

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57718

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57717

Rejected reason: Not used

Aug 19, 2025
CVE-2025-54862
5.4 MEDIUM

Sante PACS Server web portal is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage …

Aug 18, 2025
CVE-2025-54759
6.1 MEDIUM

Sante PACS Server is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage and stealing …

Aug 18, 2025
CVE-2025-54156
7.4 HIGH

The Sante PACS Server Web Portal sends credential information without encryption.

Aug 18, 2025
CVE-2025-53948
7.5 HIGH

The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application …

Aug 18, 2025
CVE-2025-52584
7.8 HIGH

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing XE …

Aug 18, 2025
CVE-2025-46269
7.8 HIGH

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 …

Aug 18, 2025
CVE-2025-9119
2.4 LOW

A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation …

Aug 18, 2025
CVE-2025-53705
7.8 HIGH

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO …

Aug 18, 2025
CVE-2025-41392
7.8 HIGH

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing AR …

Aug 18, 2025
CVE-2025-8098
7.8 HIGH

An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.

Aug 18, 2025
CVE-2025-55591
9.8 CRITICAL

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.

Aug 18, 2025
CVE-2025-55590
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.

Aug 18, 2025
CVE-2025-55589
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.

Aug 18, 2025
CVE-2025-55588
7.5 HIGH

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of …

Aug 18, 2025
CVE-2025-55587
7.5 HIGH

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of …

Aug 18, 2025
CVE-2025-55586
7.5 HIGH

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of …

Aug 18, 2025
CVE-2025-55585
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.

Aug 18, 2025
CVE-2025-55584
5.3 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.

Aug 18, 2025
CVE-2025-55213
9.8 CRITICAL

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart …

Aug 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.