CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54871
5.5 MEDIUM

Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass …

Aug 5, 2025
CVE-2025-54870

VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules might cause reversion to plaintext due to …

Aug 5, 2025
CVE-2025-54865
7.3 HIGH

Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query executed by …

Aug 5, 2025
CVE-2025-54804
6.5 MEDIUM

Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used …

Aug 5, 2025
CVE-2025-54803
7.5 HIGH

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in js-toml allows …

Aug 5, 2025
CVE-2025-54802
9.8 CRITICAL

pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path traversal in …

Aug 5, 2025
CVE-2025-54795
9.8 CRITICAL

Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation …

Aug 5, 2025
CVE-2025-54794
9.1 CRITICAL

Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, makes it …

Aug 5, 2025
CVE-2025-54780
7.7 HIGH

The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to …

Aug 5, 2025
CVE-2025-54387
9.8 CRITICAL

IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 through 3.1.0, the approach used …

Aug 5, 2025
CVE-2025-54135
8.5 HIGH

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the …

Aug 5, 2025
CVE-2025-54130
7.5 HIGH

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If …

Aug 5, 2025
CVE-2025-54119
10.0 CRITICAL

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a …

Aug 5, 2025
CVE-2025-53544
7.5 HIGH

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. In versions below 0.97.0, a brute-force protection …

Aug 5, 2025
CVE-2025-52892
4.5 MEDIUM

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and …

Aug 5, 2025
CVE-2025-8534
2.5 LOW

A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The …

Aug 5, 2025
CVE-2025-54797

Rejected reason: This CVE is a duplicate of CVE-2025-52464.

Aug 5, 2025
CVE-2025-8530
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of …

Aug 4, 2025
CVE-2025-8529
6.3 MEDIUM

A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerability is the function getCollectLogoUrl of the file app/src/main/java/com/favorites/web/CollectController.java. …

Aug 4, 2025
CVE-2025-46094
3.8 LOW

LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.

Aug 4, 2025
CVE-2025-46093
9.9 CRITICAL

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging …

Aug 4, 2025
CVE-2025-27212
9.8 CRITICAL

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. …

Aug 4, 2025
CVE-2025-27211
7.5 HIGH

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with access to EdgeSwitch adjacent …

Aug 4, 2025
CVE-2025-8528
3.7 LOW

A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation …

Aug 4, 2025
CVE-2025-8527
6.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file …

Aug 4, 2025
CVE-2025-7844

Exporting a TPM based RSA key larger than 2048 bits from the TPM could overrun a stack buffer if the default `MAX_RSA_KEY_BITS=2048` is used. If …

Aug 4, 2025
CVE-2025-54554
5.3 MEDIUM

tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.

Aug 4, 2025
CVE-2025-4604
6.1 MEDIUM

The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through …

Aug 4, 2025
CVE-2025-4599
6.1 MEDIUM

The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 …

Aug 4, 2025
CVE-2025-8526
6.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file …

Aug 4, 2025
CVE-2025-8525
5.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring …

Aug 4, 2025
CVE-2025-51726
8.4 HIGH

CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnerable to collision attacks. This allows a malicious actor to craft …

Aug 4, 2025
CVE-2025-51387
9.8 CRITICAL

The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is …

Aug 4, 2025
CVE-2025-50754
9.6 CRITICAL

Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in …

Aug 4, 2025
CVE-2025-50341
9.8 CRITICAL

A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false …

Aug 4, 2025
CVE-2025-8524
5.3 MEDIUM

A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the …

Aug 4, 2025
CVE-2025-8523
5.3 MEDIUM

A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality …

Aug 4, 2025
CVE-2025-55014
4.7 MEDIUM

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers …

Aug 4, 2025
CVE-2025-50340
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other …

Aug 4, 2025
CVE-2025-8522
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of …

Aug 4, 2025
CVE-2025-8521
2.4 LOW

A vulnerability, which was classified as problematic, has been found in givanz Vvveb up to 1.0.5. This issue affects some unknown processing of the file …

Aug 4, 2025
CVE-2025-53395
7.7 HIGH

Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx backup file and a malicious VSSSvr.dll …

Aug 4, 2025
CVE-2025-53394
7.7 HIGH

Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed …

Aug 4, 2025
CVE-2025-52239
9.8 CRITICAL

An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.

Aug 4, 2025
CVE-2025-38741
7.5 HIGH

Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized …

Aug 4, 2025
CVE-2025-26476
8.4 HIGH

Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially …

Aug 4, 2025
CVE-2025-21120
8.3 HIGH

Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged …

Aug 4, 2025
CVE-2025-8520
4.7 MEDIUM

A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/?module=editor/editor of the component …

Aug 4, 2025
CVE-2025-8519
2.7 LOW

A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of the file /vadmin123/index.php?module=editor/editor of the …

Aug 4, 2025
CVE-2025-51390
9.8 CRITICAL

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.

Aug 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.