CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2013-10054

An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitrary file upload vulnerability in its File Manager …

Aug 4, 2025
CVE-2013-10052

ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be invoked …

Aug 4, 2025
CVE-2025-8518
4.7 MEDIUM

A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file …

Aug 4, 2025
CVE-2025-51535
9.1 CRITICAL

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.

Aug 4, 2025
CVE-2025-51534
8.1 HIGH

A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted …

Aug 4, 2025
CVE-2025-50422
2.9 LOW

Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

Aug 4, 2025
CVE-2025-50420
6.5 MEDIUM

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can …

Aug 4, 2025
CVE-2025-44963
9.0 CRITICAL

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

Aug 4, 2025
CVE-2025-44962
5.0 MEDIUM

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.

Aug 4, 2025
CVE-2025-44961
9.9 CRITICAL

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

Aug 4, 2025
CVE-2025-44960
8.5 HIGH

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

Aug 4, 2025
CVE-2025-44958
5.3 MEDIUM

RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.

Aug 4, 2025
CVE-2025-44957
8.5 HIGH

Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.

Aug 4, 2025
CVE-2025-44954
9.0 CRITICAL

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

Aug 4, 2025
CVE-2025-8517
6.3 MEDIUM

A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. …

Aug 4, 2025
CVE-2025-8516
5.3 MEDIUM

A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file K3Cloud\BBCMallSite\WEB-INF\lib\Kingdee.K3.O2O.Base.WebApp.jar!\kingdee\k3\o2o\base\webapp\action\FileUploadAction.class of …

Aug 4, 2025
CVE-2025-5988
5.3 MEDIUM

A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, …

Aug 4, 2025
CVE-2025-44955
8.8 HIGH

RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.

Aug 4, 2025
CVE-2025-38739
7.2 HIGH

Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to Information …

Aug 4, 2025
CVE-2025-51536
9.8 CRITICAL

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

Aug 4, 2025
CVE-2025-44643
8.6 HIGH

Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the password property in …

Aug 4, 2025
CVE-2025-36594
9.8 CRITICAL

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-30099
7.8 HIGH

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-30098
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-30097
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-30096
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-26065
7.3 HIGH

A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted …

Aug 4, 2025
CVE-2025-8109
8.8 HIGH

Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory.

Aug 4, 2025
CVE-2025-36607
7.8 HIGH

Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping …

Aug 4, 2025
CVE-2025-36606
7.8 HIGH

Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping …

Aug 4, 2025
CVE-2025-36605
6.1 MEDIUM

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the CWE-79: Improper Neutralization of …

Aug 4, 2025
CVE-2025-36604
7.3 HIGH

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker …

Aug 4, 2025
CVE-2025-8515
3.1 LOW

A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation …

Aug 4, 2025
CVE-2025-6205
9.1 CRITICAL KEV

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

Aug 4, 2025
CVE-2025-6204
8.0 HIGH KEV

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute …

Aug 4, 2025
CVE-2025-0932
4.3 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace …

Aug 4, 2025
CVE-2025-8341
5.0 MEDIUM

Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, …

Aug 4, 2025
CVE-2025-41691
7.5 HIGH

An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading …

Aug 4, 2025
CVE-2025-41659
8.3 HIGH

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This …

Aug 4, 2025
CVE-2025-41658
5.5 MEDIUM

CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

Aug 4, 2025
CVE-2025-20702
8.8 HIGH

In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with …

Aug 4, 2025
CVE-2025-20701
8.8 HIGH

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation …

Aug 4, 2025
CVE-2025-20700
8.8 HIGH

In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. …

Aug 4, 2025
CVE-2025-48499
5.3 MEDIUM

Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (Line Printer Daemon) packet may cause a …

Aug 4, 2025
CVE-2025-54962
6.4 MEDIUM

/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then …

Aug 4, 2025
CVE-2025-20698
6.7 MEDIUM

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Aug 4, 2025
CVE-2025-20697
6.7 MEDIUM

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Aug 4, 2025
CVE-2025-20696
6.8 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Aug 4, 2025
CVE-2025-54956
3.2 LOW

The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.

Aug 3, 2025
CVE-2025-8513
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Caixin News App 8.0.1 on Android. Affected is an unknown function of the file AndroidManifest.xml …

Aug 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.