CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48731
6.4 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for …

Aug 11, 2025
CVE-2025-44004
7.2 HIGH

Mattermost Confluence Plugin version <1.5.0 fails to check the authorization of the user to the Mattermost instance which allows attackers to create a channel subscription …

Aug 11, 2025
CVE-2025-44001
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without …

Aug 11, 2025
CVE-2025-25229
5.4 MEDIUM

Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system …

Aug 11, 2025
CVE-2025-54063
8.0 HIGH

Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability …

Aug 11, 2025
CVE-2025-53187
9.8 CRITICAL

Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an …

Aug 11, 2025
CVE-2025-25231
7.5 HIGH

Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending …

Aug 11, 2025
CVE-2025-8866

YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking …

Aug 11, 2025
CVE-2025-45146
9.8 CRITICAL

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via …

Aug 11, 2025
CVE-2025-38499
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is …

Aug 11, 2025
CVE-2025-8865

The YugabyteDB tablet server contains a flaw in its YCQL query handling that can trigger a null pointer dereference when processing certain malformed inputs. An …

Aug 11, 2025
CVE-2025-8859
6.3 MEDIUM

A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File …

Aug 11, 2025
CVE-2012-10040

Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, whose constructor in network.inc …

Aug 11, 2025
CVE-2012-10039

ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call …

Aug 11, 2025
CVE-2012-10038

Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote …

Aug 11, 2025
CVE-2012-10037

PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A …

Aug 11, 2025
CVE-2025-8864

Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs

Aug 11, 2025
CVE-2025-8852
4.3 MEDIUM

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation …

Aug 11, 2025
CVE-2025-8851
5.3 MEDIUM

A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. …

Aug 11, 2025
CVE-2025-8863

YugabyteDB diagnostic information was transmitted over HTTP, which could expose sensitive data during transmission

Aug 11, 2025
CVE-2025-8862

YugabyteDB has been collecting diagnostics information from YugabyteDB servers, which may include sensitive gflag configurations. To mitigate this, we recommend upgrading the database to a …

Aug 11, 2025
CVE-2025-8847
3.5 LOW

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /system/notice/edit. The manipulation of …

Aug 11, 2025
CVE-2025-8846
5.3 MEDIUM

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer …

Aug 11, 2025
CVE-2025-8845
5.3 MEDIUM

A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer …

Aug 11, 2025
CVE-2025-8672
7.8 HIGH

MacOS version of GIMP bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application …

Aug 11, 2025
CVE-2025-8844
3.3 LOW

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer …

Aug 11, 2025
CVE-2025-8843
5.3 MEDIUM

A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. …

Aug 11, 2025
CVE-2025-8842
5.3 MEDIUM

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads …

Aug 11, 2025
CVE-2025-8841
6.3 MEDIUM

A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads …

Aug 11, 2025
CVE-2025-8840
5.4 MEDIUM

A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of …

Aug 11, 2025
CVE-2025-8853
9.8 CRITICAL

Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use …

Aug 11, 2025
CVE-2025-8839
6.3 MEDIUM

A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation …

Aug 11, 2025
CVE-2025-8838
7.3 HIGH

A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHandle of the file /admin/ of the component Backend …

Aug 11, 2025
CVE-2025-8837
5.3 MEDIUM

A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. The …

Aug 11, 2025
CVE-2025-8836
3.3 LOW

A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 …

Aug 11, 2025
CVE-2025-8747
7.8 HIGH

A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing …

Aug 11, 2025
CVE-2025-8661
6.1 MEDIUM

A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data entered by the user.

Aug 11, 2025
CVE-2025-8660
9.8 CRITICAL

Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.

Aug 11, 2025
CVE-2025-8835
3.3 LOW

A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image …

Aug 11, 2025
CVE-2025-8834
2.4 LOW

A vulnerability has been found in JCG Link-net LW-N915R 17s.20.001.908. Affected is an unknown function of the file /wireless/basic.asp of the component Wireless Basic Settings …

Aug 11, 2025
CVE-2025-8833
8.8 HIGH

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function langSwitchBack of the file …

Aug 11, 2025
CVE-2025-8832
8.8 HIGH

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnerability affects the function setDMZ of the file …

Aug 11, 2025
CVE-2025-7965
4.3 MEDIUM

The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Aug 11, 2025
CVE-2025-8854
9.8 CRITICAL

Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file …

Aug 11, 2025
CVE-2025-8831
8.8 HIGH

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the function remoteManagement of the file /goform/remoteManagement. …

Aug 11, 2025
CVE-2025-8830
6.3 MEDIUM

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this issue is the function sub_3517C …

Aug 11, 2025
CVE-2025-8829
6.3 MEDIUM

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by this vulnerability is the function um_red of …

Aug 11, 2025
CVE-2025-8828
6.3 MEDIUM

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is the function ipv6cmd of the file /goform/setIpv6. …

Aug 11, 2025
CVE-2025-8827
6.3 MEDIUM

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affects the function um_inspect_cross_band of the file …

Aug 11, 2025
CVE-2025-27577
8.4 HIGH

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

Aug 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.