CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8462
6.4 MEDIUM

The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the social URL parameter in all …

Aug 12, 2025
CVE-2025-5391
8.1 HIGH

The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all …

Aug 12, 2025
CVE-2025-4390
5.3 MEDIUM

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' …

Aug 12, 2025
CVE-2025-42976
8.1 HIGH

SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause …

Aug 12, 2025
CVE-2025-42975
6.1 MEDIUM

SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds …

Aug 12, 2025
CVE-2025-42957
9.9 CRITICAL

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of …

Aug 12, 2025
CVE-2025-42955
3.5 LOW

Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to …

Aug 12, 2025
CVE-2025-42951
8.8 HIGH

Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a …

Aug 12, 2025
CVE-2025-42950
9.9 CRITICAL

SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the …

Aug 12, 2025
CVE-2025-42949
4.9 MEDIUM

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging …

Aug 12, 2025
CVE-2025-42948
6.1 MEDIUM

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. …

Aug 12, 2025
CVE-2025-42946
6.9 MEDIUM

Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in …

Aug 12, 2025
CVE-2025-42945
6.1 MEDIUM

SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick …

Aug 12, 2025
CVE-2025-42943
4.5 MEDIUM

SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, …

Aug 12, 2025
CVE-2025-42942
6.1 MEDIUM

SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and …

Aug 12, 2025
CVE-2025-42941
3.5 LOW

SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user …

Aug 12, 2025
CVE-2025-42936
5.4 MEDIUM

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users …

Aug 12, 2025
CVE-2025-42935
4.1 MEDIUM

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files …

Aug 12, 2025
CVE-2025-42934
4.3 MEDIUM

SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted …

Aug 12, 2025
CVE-2025-55161
8.6 HIGH

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/markdown/pdf endpoint to convert …

Aug 11, 2025
CVE-2025-55159

slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity …

Aug 11, 2025
CVE-2025-55158
8.8 HIGH

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, …

Aug 11, 2025
CVE-2025-55157
8.8 HIGH

Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error …

Aug 11, 2025
CVE-2025-55156

pyLoad is the free and open-source Download Manager written in pure Python. Prior to version 0.5.0b3.dev91, the parameter add_links in API /json/add_package is vulnerable to …

Aug 11, 2025
CVE-2025-55151
8.6 HIGH

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, the "convert file to pdf" functionality (/api/v1/convert/file/pdf) …

Aug 11, 2025
CVE-2025-55150
8.6 HIGH

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert …

Aug 11, 2025
CVE-2025-55012

Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution …

Aug 11, 2025
CVE-2025-54992

OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKilda which in combination with …

Aug 11, 2025
CVE-2025-25235
8.6 HIGH

Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on …

Aug 11, 2025
CVE-2025-54878
8.6 HIGH

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the …

Aug 11, 2025
CVE-2025-40920
8.6 HIGH

Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl generate nonces using the Perl Data::UUID library. * Data::UUID does not use a strong cryptographic source for generating …

Aug 11, 2025
CVE-2024-32640
9.8 CRITICAL

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability …

Aug 11, 2025
CVE-2025-8285
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper …

Aug 11, 2025
CVE-2025-7679
8.1 HIGH

The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT

Aug 11, 2025
CVE-2025-7677
5.9 MEDIUM

A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue …

Aug 11, 2025
CVE-2025-54525
7.5 HIGH

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription …

Aug 11, 2025
CVE-2025-54478
7.2 HIGH

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via …

Aug 11, 2025
CVE-2025-54463
5.9 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint …

Aug 11, 2025
CVE-2025-54458
5.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for …

Aug 11, 2025
CVE-2025-53910
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without …

Aug 11, 2025
CVE-2025-53857
3.7 LOW

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without …

Aug 11, 2025
CVE-2025-53514
5.9 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint …

Aug 11, 2025
CVE-2025-53191

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 11, 2025
CVE-2025-53190

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 11, 2025
CVE-2025-53189

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 11, 2025
CVE-2025-53188

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 11, 2025
CVE-2025-52931
7.5 HIGH

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription …

Aug 11, 2025
CVE-2025-51824
6.5 MEDIUM

libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.

Aug 11, 2025
CVE-2025-51823
6.5 MEDIUM

libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function uses strcpy to copy …

Aug 11, 2025
CVE-2025-49221
3.7 LOW

Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to access subscription details without …

Aug 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.