CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48913
9.8 CRITICAL

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. …

Aug 8, 2025
CVE-2025-6572
5.9 MEDIUM

The OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.2.0 does not validate and escape some of its block options …

Aug 8, 2025
CVE-2025-54959
4.3 MEDIUM

Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is exploited, an arbitrary file in the affected product may …

Aug 8, 2025
CVE-2025-54958
6.3 MEDIUM

Powered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is exploited, arbitrary OS commands may be executed on …

Aug 8, 2025
CVE-2025-54940
3.4 LOW

An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered …

Aug 8, 2025
CVE-2024-58257
5.7 MEDIUM

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

Aug 8, 2025
CVE-2024-58256
4.5 MEDIUM

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

Aug 8, 2025
CVE-2024-58255
5.0 MEDIUM

EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

Aug 8, 2025
CVE-2025-8708
5.0 MEDIUM

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of …

Aug 8, 2025
CVE-2025-8707
5.3 MEDIUM

A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unknown part of the file …

Aug 8, 2025
CVE-2025-8706
6.3 MEDIUM

A vulnerability has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 and classified as critical. Affected by this vulnerability is an unknown …

Aug 8, 2025
CVE-2025-8705
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Affected is an unknown function of the …

Aug 8, 2025
CVE-2025-8704
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This issue affects some unknown processing …

Aug 8, 2025
CVE-2025-8703
6.3 MEDIUM

A vulnerability classified as critical was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This vulnerability affects unknown code of the file /WEAS_HomePage/GetAreaTrendChartData …

Aug 8, 2025
CVE-2025-54887
9.1 CRITICAL

jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs can …

Aug 8, 2025
CVE-2025-54886
8.4 HIGH

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain …

Aug 8, 2025
CVE-2025-54793
6.1 MEDIUM

Astro is a web framework for content-driven websites. In versions 5.2.0 through 5.12.7, there is an Open Redirect vulnerability in the trailing slash redirection logic …

Aug 8, 2025
CVE-2025-8702
6.3 MEDIUM

A vulnerability classified as critical has been found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. This affects an unknown part of the file …

Aug 8, 2025
CVE-2025-54952
9.8 CRITICAL

An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other …

Aug 8, 2025
CVE-2025-54368

uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, …

Aug 8, 2025
CVE-2025-54951
9.8 CRITICAL

A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution …

Aug 7, 2025
CVE-2025-54950
9.8 CRITICAL

An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable …

Aug 7, 2025
CVE-2025-54949
9.8 CRITICAL

A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch …

Aug 7, 2025
CVE-2025-30405
9.8 CRITICAL

An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area, potentially resulting in code …

Aug 7, 2025
CVE-2025-30404
9.8 CRITICAL

An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execution or other undesirable effects. This issue …

Aug 7, 2025
CVE-2025-54787
3.7 LOW

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any …

Aug 7, 2025
CVE-2025-8701
6.3 MEDIUM

A vulnerability was found in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. It has been rated as critical. Affected by this issue is some …

Aug 7, 2025
CVE-2025-8698
3.3 LOW

A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_nsmf_pdusession_handle_release_sm_context of the file src/amf/nsmf-handler.c of …

Aug 7, 2025
CVE-2025-53792
9.1 CRITICAL

Azure Portal Elevation of Privilege Vulnerability

Aug 7, 2025
CVE-2025-53787
8.2 HIGH

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

Aug 7, 2025
CVE-2025-53774
6.5 MEDIUM

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

Aug 7, 2025
CVE-2025-53767
10.0 CRITICAL

Azure OpenAI Elevation of Privilege Vulnerability

Aug 7, 2025
CVE-2025-45765
9.1 CRITICAL

ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more …

Aug 7, 2025
CVE-2025-26513
7.0 HIGH

The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local …

Aug 7, 2025
CVE-2025-48709
3.8 LOW

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them …

Aug 7, 2025
CVE-2025-47808
5.6 MEDIUM

In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.

Aug 7, 2025
CVE-2025-47807
5.5 MEDIUM

In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.

Aug 7, 2025
CVE-2025-47806
5.6 MEDIUM

In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.

Aug 7, 2025
CVE-2025-47219
8.1 HIGH

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading …

Aug 7, 2025
CVE-2025-47183
6.6 MEDIUM

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to …

Aug 7, 2025
CVE-2025-8697
6.3 MEDIUM

A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the component MCPSessionManager/MCPTool/MCPToolkit. The manipulation …

Aug 7, 2025
CVE-2025-7195
6.4 MEDIUM

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided …

Aug 7, 2025
CVE-2025-55077
7.4 HIGH

Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows …

Aug 7, 2025
CVE-2025-51533
5.3 MEDIUM

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.

Aug 7, 2025
CVE-2025-50692
9.8 CRITICAL

FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

Aug 7, 2025
CVE-2025-50675
7.8 HIGH

GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory is accessible with full read, …

Aug 7, 2025
CVE-2025-51629
8.8 HIGH

A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting …

Aug 7, 2025
CVE-2023-41532
8.8 HIGH

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.

Aug 7, 2025
CVE-2023-41531
8.8 HIGH

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.

Aug 7, 2025
CVE-2023-41530
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

Aug 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.