CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8576
8.8 HIGH

Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. …

Aug 7, 2025
CVE-2025-29865

: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path Traversal.This issue affects X-Free Uploader: …

Aug 7, 2025
CVE-2025-54885

Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. In versions 2.0.0 and below, a protocol compliance bug causes the …

Aug 7, 2025
CVE-2025-54882
7.1 HIGH

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.0.0-beta through 1.1.0, Himmelblau stores the cloud …

Aug 7, 2025
CVE-2025-54799

Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego …

Aug 7, 2025
CVE-2025-54798
2.5 LOW

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory …

Aug 7, 2025
CVE-2025-54784
6.1 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions …

Aug 7, 2025
CVE-2025-54783
6.1 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability allows …

Aug 7, 2025
CVE-2025-3770
7.0 HIGH

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to …

Aug 7, 2025
CVE-2025-54788
8.8 HIGH

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in …

Aug 7, 2025
CVE-2025-54786
5.3 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows …

Aug 7, 2025
CVE-2025-54785
8.8 HIGH

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed …

Aug 7, 2025
CVE-2025-8086

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 6, 2025
CVE-2023-3194

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 6, 2025
CVE-2025-7770

Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based …

Aug 6, 2025
CVE-2025-7769

Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due …

Aug 6, 2025
CVE-2025-7768

Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This vulnerability enables attackers to escalate privileges …

Aug 6, 2025
CVE-2025-6634
7.8 HIGH

A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this …

Aug 6, 2025
CVE-2025-6633
7.8 HIGH

A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Aug 6, 2025
CVE-2025-6632
5.3 MEDIUM

A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this …

Aug 6, 2025
CVE-2025-51058
6.5 MEDIUM

Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to Server-side Request Forgery (SSRF) in the /api_vedo/video/preview endpoint, which allows remote authenticated attackers to trigger HTTP requests …

Aug 6, 2025
CVE-2025-51057
6.5 MEDIUM

A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' …

Aug 6, 2025
CVE-2025-51056
8.2 HIGH

An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' …

Aug 6, 2025
CVE-2025-51055
8.6 HIGH

Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains clear-text credentials, secret keys, and database …

Aug 6, 2025
CVE-2025-51054
6.5 MEDIUM

Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via …

Aug 6, 2025
CVE-2025-51053
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject arbitrary Javascript or HTML code and potentially trigger …

Aug 6, 2025
CVE-2025-51052
6.5 MEDIUM

A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in …

Aug 6, 2025
CVE-2025-50740
6.1 MEDIUM

AutoConnect 1.4.2, an Arduino library, is vulnerable to a cross site scripting (xss) vulnerability. The AutoConnect web interface /_ac/config allows HTML/JS code to be executed …

Aug 6, 2025
CVE-2025-47908
7.5 HIGH

Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Headers (ACRH) header whose value contains many commas. This …

Aug 6, 2025
CVE-2025-46660
5.3 MEDIUM

An issue was discovered in 4C Strategies Exonaut 21.6. Passwords, stored in the database, are hashed without a salt.

Aug 6, 2025
CVE-2024-55402
5.3 MEDIUM

4C Strategies Exonaut before v22.4 was discovered to contain an access control issue.

Aug 6, 2025
CVE-2024-55399
6.5 MEDIUM

4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).

Aug 6, 2025
CVE-2024-55398
6.5 MEDIUM

4C Strategies Exonaut before v22.4 was discovered to contain insecure permissions.

Aug 6, 2025
CVE-2025-51624
7.6 HIGH

Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.

Aug 6, 2025
CVE-2025-46659
7.5 HIGH

An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request.

Aug 6, 2025
CVE-2025-45766
7.0 HIGH

poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set …

Aug 6, 2025
CVE-2025-45764
3.2 LOW

jsrsasign v11.1.0 was discovered to contain weak encryption. NOTE: this issue has been disputed by a third party who believes that CVE IDs can be …

Aug 6, 2025
CVE-2025-38747
7.8 HIGH

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit …

Aug 6, 2025
CVE-2025-38746
3.5 LOW

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access …

Aug 6, 2025
CVE-2025-8130

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 6, 2025
CVE-2025-8667
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2. Affected is the function from_code/from_dict/from_mcp of the file src/tools/tools.py. The …

Aug 6, 2025
CVE-2025-8665
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the function MCPTools/MultiMCPTools in the library …

Aug 6, 2025
CVE-2025-8419
5.3 MEDIUM

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is …

Aug 6, 2025
CVE-2025-30127
9.8 CRITICAL

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings …

Aug 6, 2025
CVE-2025-20332
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected …

Aug 6, 2025
CVE-2025-20331
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a stored XSS attack …

Aug 6, 2025
CVE-2025-20215
5.4 MEDIUM

A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of …

Aug 6, 2025
CVE-2025-53786
8.0 HIGH

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general …

Aug 6, 2025
CVE-2025-51532
7.5 HIGH

Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has …

Aug 6, 2025
CVE-2025-51531
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arbitrary JavaScript in the context of a victim's browser …

Aug 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.