CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-41529
6.1 MEDIUM

Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.

Aug 7, 2025
CVE-2023-41528
9.8 CRITICAL

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.

Aug 7, 2025
CVE-2023-41527
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.

Aug 7, 2025
CVE-2023-41526
9.8 CRITICAL

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.

Aug 7, 2025
CVE-2023-41525
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

Aug 7, 2025
CVE-2023-41524
8.8 HIGH

Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.

Aug 7, 2025
CVE-2023-41523
8.8 HIGH

Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.

Aug 7, 2025
CVE-2023-41522
8.8 HIGH

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.

Aug 7, 2025
CVE-2023-41521
8.8 HIGH

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters.

Aug 7, 2025
CVE-2023-41520
8.8 HIGH

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.

Aug 7, 2025
CVE-2023-41519
6.1 MEDIUM

Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.

Aug 7, 2025
CVE-2023-40992
6.5 MEDIUM

Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.

Aug 7, 2025
CVE-2025-55138
7.4 HIGH

LinkJoin through 882f196 mishandles token ownership in password reset.

Aug 7, 2025
CVE-2025-55137
7.4 HIGH

LinkJoin through 882f196 mishandles lacks type checking in password reset.

Aug 7, 2025
CVE-2025-54397
4.3 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.

Aug 7, 2025
CVE-2025-54396
5.4 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.

Aug 7, 2025
CVE-2025-54395
6.1 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.

Aug 7, 2025
CVE-2025-54394
5.3 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.

Aug 7, 2025
CVE-2025-54393
5.4 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.

Aug 7, 2025
CVE-2025-54392
6.1 MEDIUM

Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.

Aug 7, 2025
CVE-2025-34152

An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. …

Aug 7, 2025
CVE-2025-34151

A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The …

Aug 7, 2025
CVE-2025-34150

The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to command injection via the 'user' parameter. Input is …

Aug 7, 2025
CVE-2025-34149

A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 configuration. The 'key' parameter is interpreted directly by the …

Aug 7, 2025
CVE-2025-34148

An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the …

Aug 7, 2025
CVE-2025-24000
8.8 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authentication Bypass.This issue affects Post SMTP: from n/a through …

Aug 7, 2025
CVE-2024-42048
6.5 MEDIUM

OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In …

Aug 7, 2025
CVE-2025-7054
6.5 MEDIUM

Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers …

Aug 7, 2025
CVE-2025-55136
5.7 MEDIUM

ERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used.

Aug 7, 2025
CVE-2025-55135
6.4 MEDIUM

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted …

Aug 7, 2025
CVE-2025-55134
6.4 MEDIUM

In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.

Aug 7, 2025
CVE-2025-55133
6.4 MEDIUM

In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManager.js.

Aug 7, 2025
CVE-2025-47907
7.0 HIGH

Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned …

Aug 7, 2025
CVE-2025-44779
6.6 MEDIUM

An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

Aug 7, 2025
CVE-2024-56339
3.7 LOW

IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 could allow a remote attacker to bypass security restrictions caused by a …

Aug 7, 2025
CVE-2025-50952
6.5 MEDIUM

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

Aug 7, 2025
CVE-2025-47188
6.5 MEDIUM

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 …

Aug 7, 2025
CVE-2024-55401
6.5 MEDIUM

An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.

Aug 7, 2025
CVE-2024-52680
6.1 MEDIUM

EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.

Aug 7, 2025
CVE-2025-8533

A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listener:shouldAcceptNewConnection method, unconditionally accepting …

Aug 7, 2025
CVE-2025-35970
7.5 HIGH

On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available via SNMP. If the …

Aug 7, 2025
CVE-2025-29866

: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free Uploader: from 1.0.1.0084 before …

Aug 7, 2025
CVE-2025-32094
4.0 MEDIUM

An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS …

Aug 7, 2025
CVE-2025-8583
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Aug 7, 2025
CVE-2025-8582
4.3 MEDIUM

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL …

Aug 7, 2025
CVE-2025-8581
4.3 MEDIUM

Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Aug 7, 2025
CVE-2025-8580
4.3 MEDIUM

Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Aug 7, 2025
CVE-2025-8579
4.3 MEDIUM

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI …

Aug 7, 2025
CVE-2025-8578
8.8 HIGH

Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 7, 2025
CVE-2025-8577
4.3 MEDIUM

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI …

Aug 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.