CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54362

Rejected reason: Not used

Jul 22, 2025
CVE-2025-54361

Rejected reason: Not used

Jul 22, 2025
CVE-2025-54360

Rejected reason: Not used

Jul 22, 2025
CVE-2025-54359

Rejected reason: Not used

Jul 22, 2025
CVE-2025-54358

Rejected reason: Not used

Jul 22, 2025
CVE-2025-54357

Rejected reason: Not used

Jul 22, 2025
CVE-2025-54356

Rejected reason: Not used

Jul 22, 2025
CVE-2025-54355

Rejected reason: Not used

Jul 22, 2025
CVE-2025-54354

Rejected reason: Not used

Jul 22, 2025
CVE-2025-7949
3.5 LOW

A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 22, 2025
CVE-2025-6831
6.4 MEDIUM

The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 …

Jul 22, 2025
CVE-2025-5240
6.4 MEDIUM

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all versions up to, …

Jul 22, 2025
CVE-2015-10137
9.8 CRITICAL

The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' …

Jul 22, 2025
CVE-2012-10020
9.8 CRITICAL

The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions up to, …

Jul 22, 2025
CVE-2025-7948
4.3 MEDIUM

A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The …

Jul 22, 2025
CVE-2025-7947
5.4 MEDIUM

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component …

Jul 22, 2025
CVE-2025-7946
4.3 MEDIUM

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the …

Jul 22, 2025
CVE-2025-7945
8.8 HIGH

A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file …

Jul 22, 2025
CVE-2025-7944
4.3 MEDIUM

A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0. It has been classified as problematic. This affects an unknown part of the file …

Jul 21, 2025
CVE-2025-7943
4.3 MEDIUM

A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Jul 21, 2025
CVE-2025-7486
4.4 MEDIUM

The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions up to, and including, 5.8012 due …

Jul 21, 2025
CVE-2025-7942
3.5 LOW

A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 21, 2025
CVE-2025-7941
3.5 LOW

A vulnerability, which was classified as problematic, was found in PHPGurukul Time Table Generator System 1.0. Affected is an unknown function of the file /admin/profile.php. …

Jul 21, 2025
CVE-2025-7940
5.3 MEDIUM

A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an …

Jul 21, 2025
CVE-2025-7939
6.3 MEDIUM

A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of the file GoodsController.java. The …

Jul 21, 2025
CVE-2025-54134
6.5 MEDIUM

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes …

Jul 21, 2025
CVE-2025-54129
4.3 MEDIUM

HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below, the application returns …

Jul 21, 2025
CVE-2025-54128
6.1 MEDIUM

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS …

Jul 21, 2025
CVE-2025-54127
9.8 CRITICAL

HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of …

Jul 21, 2025
CVE-2025-54122
10.0 CRITICAL

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified in the proxy handler component of both manager …

Jul 21, 2025
CVE-2025-53832
7.5 HIGH

Lara Translate MCP Server is a Model Context Protocol (MCP) Server for Lara Translate API. Versions 0.0.11 and below contain a command injection vulnerability which …

Jul 21, 2025
CVE-2025-53528
7.6 HIGH

Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of the "/docs" endpoint is vulnerable to a …

Jul 21, 2025
CVE-2025-7938
4.3 MEDIUM

A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the function updateGoods of the file GoodsController.java. The manipulation …

Jul 21, 2025
CVE-2025-7936
6.3 MEDIUM

A vulnerability has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a and classified as critical. Affected by this vulnerability is the function queryPage of the …

Jul 21, 2025
CVE-2025-7325
7.8 HIGH

IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7324
7.8 HIGH

IrfanView CADImage Plugin DXF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7323
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7322
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7321
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7320
7.8 HIGH

IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7319
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7318
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7317
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7316
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7315
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7314
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7313
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7312
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7311
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025
CVE-2025-7310
7.8 HIGH

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jul 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.