CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-50492
7.5 HIGH

Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50491
7.1 HIGH

Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50489
7.5 HIGH

Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50488
7.1 HIGH

Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-43023
9.1 CRITICAL

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of …

Jul 28, 2025
CVE-2025-7676

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can …

Jul 28, 2025
CVE-2025-54538
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

Jul 28, 2025
CVE-2025-54537
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

Jul 28, 2025
CVE-2025-54536
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint

Jul 28, 2025
CVE-2025-54535
5.8 MEDIUM

In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

Jul 28, 2025
CVE-2025-54534
4.8 MEDIUM

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

Jul 28, 2025
CVE-2025-54533
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

Jul 28, 2025
CVE-2025-54532
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

Jul 28, 2025
CVE-2025-54531
7.7 HIGH

In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

Jul 28, 2025
CVE-2025-54530
7.5 HIGH

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

Jul 28, 2025
CVE-2025-54529
3.7 LOW

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

Jul 28, 2025
CVE-2025-54528
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

Jul 28, 2025
CVE-2025-54527
6.1 MEDIUM

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

Jul 28, 2025
CVE-2025-50494
7.5 HIGH

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50493
7.5 HIGH

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50490
7.5 HIGH

Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-6250
6.7 MEDIUM

Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service …

Jul 28, 2025
CVE-2025-2297
7.8 HIGH

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under …

Jul 28, 2025
CVE-2024-49343
5.4 MEDIUM

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Jul 28, 2025
CVE-2024-49342
7.5 HIGH

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Jul 28, 2025
CVE-2025-54418
9.8 CRITICAL

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler for …

Jul 28, 2025
CVE-2025-53696

iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious …

Jul 28, 2025
CVE-2025-30125
9.8 CRITICAL

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an …

Jul 28, 2025
CVE-2025-8279
8.7 HIGH

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

Jul 28, 2025
CVE-2025-53695

OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.

Jul 28, 2025
CVE-2025-32731
6.1 MEDIUM

A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream MedDream PACS Premium 7.3.5.860. A specially crafted malicious url can lead to …

Jul 28, 2025
CVE-2025-30133
9.8 CRITICAL

An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app …

Jul 28, 2025
CVE-2025-30126
5.3 MEDIUM

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a …

Jul 28, 2025
CVE-2025-30124
9.8 CRITICAL

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is …

Jul 28, 2025
CVE-2025-27724
9.3 CRITICAL

A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilities. …

Jul 28, 2025
CVE-2025-26469
9.3 CRITICAL

An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application can decrypt credentials stored in a …

Jul 28, 2025
CVE-2025-24485
5.8 MEDIUM

A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP request can lead to SSRF. An …

Jul 28, 2025
CVE-2025-8275
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown …

Jul 28, 2025
CVE-2025-54569
4.5 MEDIUM

In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation.

Jul 28, 2025
CVE-2025-4056
7.5 HIGH

A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long …

Jul 28, 2025
CVE-2025-8274
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jul 28, 2025
CVE-2025-5997
8.8 HIGH

Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse.This issue affects PhishPro: before 7.5.4.2.

Jul 28, 2025
CVE-2025-38497
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Fix OOB read on empty string write When writing an empty string …

Jul 28, 2025
CVE-2025-38496
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dm-bufio: fix sched in atomic context If "try_verify_in_tasklet" is set for dm-verity, DM_BUFIO_CLIENT_NO_SLEEP is enabled …

Jul 28, 2025
CVE-2025-38495
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can contain the reserved report ID When the …

Jul 28, 2025
CVE-2025-38494
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer …

Jul 28, 2025
CVE-2025-38493
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix crash in timerlat_dump_stack() We have observed kernel panics when using timerlat with stack …

Jul 28, 2025
CVE-2025-38492
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix race between cache write completion and ALL_QUEUED being set When netfslib is issuing …

Jul 28, 2025
CVE-2025-38491
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision atomic Syzkaller reported the following splat: WARNING: CPU: …

Jul 28, 2025
CVE-2025-38490
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: libwx: remove duplicate page_pool_put_full_page() page_pool_put_full_page() should only be invoked when freeing Rx buffers or …

Jul 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.