CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-46958
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Aug 5, 2025
CVE-2025-44964
3.9 LOW

A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information.

Aug 5, 2025
CVE-2025-2611

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed …

Aug 5, 2025
CVE-2025-29745
7.5 HIGH

A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a …

Aug 5, 2025
CVE-2025-27931
6.5 MEDIUM

An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit …

Aug 5, 2025
CVE-2025-7033
7.8 HIGH

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end …

Aug 5, 2025
CVE-2025-7032
7.8 HIGH

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end …

Aug 5, 2025
CVE-2025-7025
7.8 HIGH

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end …

Aug 5, 2025
CVE-2024-52890
6.1 MEDIUM

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

Aug 5, 2025
CVE-2025-54987
9.4 CRITICAL

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected …

Aug 5, 2025
CVE-2025-54948
9.4 CRITICAL KEV

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected …

Aug 5, 2025
CVE-2025-8555
3.5 LOW

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown function of the file /search. The …

Aug 5, 2025
CVE-2025-8554
2.4 LOW

A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some unknown processing of the file …

Aug 5, 2025
CVE-2025-8553
2.4 LOW

A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code of the file /admin/sensitive_word/list. The manipulation of …

Aug 5, 2025
CVE-2025-8552
2.4 LOW

A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the file /admin/tag/list. The manipulation …

Aug 5, 2025
CVE-2025-8551
3.5 LOW

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Aug 5, 2025
CVE-2025-8295
6.4 MEDIUM

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due …

Aug 5, 2025
CVE-2025-8294
6.4 MEDIUM

The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3 due …

Aug 5, 2025
CVE-2025-6207
7.5 HIGH

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in …

Aug 5, 2025
CVE-2025-5061
7.5 HIGH

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in …

Aug 5, 2025
CVE-2025-41698
7.8 HIGH

A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.

Aug 5, 2025
CVE-2025-2810
5.5 MEDIUM

A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.

Aug 5, 2025
CVE-2025-8550
2.4 LOW

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Aug 5, 2025
CVE-2025-8549
3.7 LOW

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function update of the file src/main/java/co/yiiu/pybbs/controller/admin/UserAdminController.java. …

Aug 5, 2025
CVE-2025-8548
3.7 LOW

A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function sendEmailCode of the file src/main/java/co/yiiu/pybbs/controller/api/SettingsApiController.java of …

Aug 5, 2025
CVE-2025-8315
6.4 MEDIUM

The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.0.1 …

Aug 5, 2025
CVE-2025-8313
6.4 MEDIUM

The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due …

Aug 5, 2025
CVE-2025-7050
7.2 HIGH

The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in file metadata in …

Aug 5, 2025
CVE-2025-8547
5.3 MEDIUM

A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email Verification …

Aug 5, 2025
CVE-2025-54982
9.6 CRITICAL

An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.

Aug 5, 2025
CVE-2025-8546
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code …

Aug 5, 2025
CVE-2025-8545
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue is some unknown functionality of the file …

Aug 5, 2025
CVE-2025-8544
2.4 LOW

A vulnerability classified as problematic was found in Portabilis i-Educar 2.10. Affected by this vulnerability is an unknown functionality of the file /module/RegraAvaliacao/edit. The manipulation …

Aug 5, 2025
CVE-2025-54868
7.5 HIGH

LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch …

Aug 5, 2025
CVE-2025-8543
2.4 LOW

A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. Affected is an unknown function of the file /intranet/educar_raca_cad.php. The manipulation of the …

Aug 5, 2025
CVE-2025-8542
2.4 LOW

A vulnerability was found in Portabilis i-Educar 2.10. It has been rated as problematic. This issue affects some unknown processing of the file /intranet/empresas_cad.php. The …

Aug 5, 2025
CVE-2025-54980

Rejected reason: Not used

Aug 5, 2025
CVE-2025-54979

Rejected reason: Not used

Aug 5, 2025
CVE-2025-54978

Rejected reason: Not used

Aug 5, 2025
CVE-2025-54977

Rejected reason: Not used

Aug 5, 2025
CVE-2025-54976

Rejected reason: Not used

Aug 5, 2025
CVE-2025-54975

Rejected reason: Not used

Aug 5, 2025
CVE-2025-54974

Rejected reason: Not used

Aug 5, 2025
CVE-2025-8541
2.4 LOW

A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. This vulnerability affects unknown code of the file /intranet/public_uf_cad.php. The manipulation …

Aug 5, 2025
CVE-2025-8540
2.4 LOW

A vulnerability was found in Portabilis i-Educar 2.10. It has been classified as problematic. This affects an unknown part of the file /intranet/public_municipio_cad.php. The manipulation …

Aug 5, 2025
CVE-2025-53417

DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability

Aug 5, 2025
CVE-2025-8539
2.4 LOW

A vulnerability was found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this issue is some unknown functionality of the file /intranet/public_distrito_cad.php. The …

Aug 5, 2025
CVE-2025-8538
2.4 LOW

A vulnerability has been found in Portabilis i-Educar 2.10 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /usuarios/tipos/novo. …

Aug 5, 2025
CVE-2025-8537
3.7 LOW

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of …

Aug 5, 2025
CVE-2025-8535
3.5 LOW

A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file …

Aug 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.