CVE Database

10779+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-41530
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

Aug 7, 2025
CVE-2023-41528
9.8 CRITICAL

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.

Aug 7, 2025
CVE-2023-41527
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.

Aug 7, 2025
CVE-2023-41526
9.8 CRITICAL

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.

Aug 7, 2025
CVE-2023-41525
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

Aug 7, 2025
CVE-2025-30127
9.8 CRITICAL

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings …

Aug 6, 2025
CVE-2025-23317
9.1 CRITICAL

NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP …

Aug 6, 2025
CVE-2025-23311
9.8 CRITICAL

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requests. A successful exploit of this …

Aug 6, 2025
CVE-2025-23310
9.8 CRITICAL

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specially crafted inputs. A successful …

Aug 6, 2025
CVE-2025-22470
9.8 CRITICAL

CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrary Lua script …

Aug 6, 2025
CVE-2025-6994
9.8 CRITICAL

The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to the …

Aug 6, 2025
CVE-2025-54594
9.1 CRITICAL

react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the …

Aug 6, 2025
CVE-2013-10069
9.8 CRITICAL

The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in …

Aug 5, 2025
CVE-2012-10030
9.8 CRITICAL

FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty …

Aug 5, 2025
CVE-2012-10023
9.8 CRITICAL

A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing …

Aug 5, 2025
CVE-2025-54253
10.0 CRITICAL KEV

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this …

Aug 5, 2025
CVE-2025-46658
9.8 CRITICAL

An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages.

Aug 5, 2025
CVE-2025-54874
9.8 CRITICAL

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when …

Aug 5, 2025
CVE-2025-50707
9.8 CRITICAL

An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

Aug 5, 2025
CVE-2025-50706
9.8 CRITICAL

An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function

Aug 5, 2025
CVE-2025-54987
9.4 CRITICAL

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected …

Aug 5, 2025
CVE-2025-54948
9.4 CRITICAL KEV

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected …

Aug 5, 2025
CVE-2025-54982
9.6 CRITICAL

An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.

Aug 5, 2025
CVE-2025-54802
9.8 CRITICAL

pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path traversal in …

Aug 5, 2025
CVE-2025-54795
9.8 CRITICAL

Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmation …

Aug 5, 2025
CVE-2025-54794
9.1 CRITICAL

Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison, makes it …

Aug 5, 2025
CVE-2025-54387
9.8 CRITICAL

IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 through 3.1.0, the approach used …

Aug 5, 2025
CVE-2025-54119
10.0 CRITICAL

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a …

Aug 5, 2025
CVE-2025-46093
9.9 CRITICAL

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging …

Aug 4, 2025
CVE-2025-27212
9.8 CRITICAL

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. …

Aug 4, 2025
CVE-2025-51387
9.8 CRITICAL

The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is …

Aug 4, 2025
CVE-2025-50754
9.6 CRITICAL

Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by an attacker is rendered in …

Aug 4, 2025
CVE-2025-50341
9.8 CRITICAL

A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL query logic and determine true/false …

Aug 4, 2025
CVE-2025-52239
9.8 CRITICAL

An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.

Aug 4, 2025
CVE-2025-51390
9.8 CRITICAL

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.

Aug 4, 2025
CVE-2025-51535
9.1 CRITICAL

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.

Aug 4, 2025
CVE-2025-44963
9.0 CRITICAL

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

Aug 4, 2025
CVE-2025-44961
9.9 CRITICAL

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

Aug 4, 2025
CVE-2025-44954
9.0 CRITICAL

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

Aug 4, 2025
CVE-2025-51536
9.8 CRITICAL

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

Aug 4, 2025
CVE-2025-36594
9.8 CRITICAL

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-6205
9.1 CRITICAL KEV

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

Aug 4, 2025
CVE-2025-7710
9.8 CRITICAL

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to …

Aug 2, 2025
CVE-2025-6077
9.8 CRITICAL

Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.

Aug 2, 2025
CVE-2025-54386
9.8 CRITICAL

Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered …

Aug 2, 2025
CVE-2025-54133
9.6 CRITICAL

Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's MCP …

Aug 2, 2025
CVE-2013-10051
9.8 CRITICAL

A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, …

Aug 1, 2025
CVE-2013-10048
9.8 CRITICAL

An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper …

Aug 1, 2025
CVE-2025-6000
9.1 CRITICAL

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory …

Aug 1, 2025
CVE-2025-54574
9.3 CRITICAL

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code …

Aug 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.