CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7382
8.8 HIGH

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on …

Jul 21, 2025
CVE-2025-6704
9.8 CRITICAL

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth …

Jul 21, 2025
CVE-2025-6235
6.1 MEDIUM

In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling …

Jul 21, 2025
CVE-2025-4130
7.5 HIGH

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.

Jul 21, 2025
CVE-2025-4129
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers.This issue affects PAVO Pay: before 13.05.2025.

Jul 21, 2025
CVE-2024-13974
8.1 HIGH

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS …

Jul 21, 2025
CVE-2024-13973
6.8 MEDIUM

A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.

Jul 21, 2025
CVE-2025-7925
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Banquet Booking System 1.0. Affected by this issue is some unknown functionality …

Jul 21, 2025
CVE-2025-4040
7.1 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation.This issue affects Automatic Station Monitoring System: before 5.0.6.51.

Jul 21, 2025
CVE-2025-41100

Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible to operate the device without the access being logged in the application and even …

Jul 21, 2025
CVE-2025-30192
7.5 HIGH

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated …

Jul 21, 2025
CVE-2025-2301
4.4 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploitation of Trusted Identifiers.This issue affects Online Exam Registration: before 14.03.2025.

Jul 21, 2025
CVE-2025-7924
3.5 LOW

A vulnerability classified as problematic was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jul 21, 2025
CVE-2025-5681
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers.This issue affects Eyotek: before 23.06.2025.

Jul 21, 2025
CVE-2025-41459
7.8 HIGH

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass …

Jul 21, 2025
CVE-2025-41458
5.5 MEDIUM

Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the …

Jul 21, 2025
CVE-2025-50151
8.8 HIGH

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users …

Jul 21, 2025
CVE-2025-49656
7.5 HIGH

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. …

Jul 21, 2025
CVE-2025-41681
4.8 MEDIUM

A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content.

Jul 21, 2025
CVE-2025-41679
5.3 MEDIUM

An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard …

Jul 21, 2025
CVE-2025-41678
6.5 MEDIUM

A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement.

Jul 21, 2025
CVE-2025-41677
4.9 MEDIUM

A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession.

Jul 21, 2025
CVE-2025-41676
4.9 MEDIUM

A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession.

Jul 21, 2025
CVE-2025-41675
7.2 HIGH

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special …

Jul 21, 2025
CVE-2025-41674
7.2 HIGH

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used …

Jul 21, 2025
CVE-2025-41673
7.2 HIGH

A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used …

Jul 21, 2025
CVE-2025-1469
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers.This issue affects Eyotek: before 11.03.2025.

Jul 21, 2025
CVE-2024-6107
9.6 CRITICAL

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been …

Jul 21, 2025
CVE-2025-7369
6.1 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This …

Jul 21, 2025
CVE-2025-7354
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, …

Jul 21, 2025
CVE-2025-4685
6.4 MEDIUM

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML data attributes …

Jul 21, 2025
CVE-2025-4570

An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with …

Jul 21, 2025
CVE-2025-4569

An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with …

Jul 21, 2025
CVE-2025-4049

Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA: …

Jul 21, 2025
CVE-2025-7921
9.8 CRITICAL

Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and potentially execute …

Jul 21, 2025
CVE-2025-7920
6.1 MEDIUM

WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser …

Jul 21, 2025
CVE-2025-7919
6.5 MEDIUM

WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and …

Jul 21, 2025
CVE-2025-7344
8.8 HIGH

The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to administrator level via a …

Jul 21, 2025
CVE-2025-7343
9.8 CRITICAL

The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database …

Jul 21, 2025
CVE-2025-24938
8.4 HIGH

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (administrator) …

Jul 21, 2025
CVE-2025-24937
9.0 CRITICAL

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a …

Jul 21, 2025
CVE-2025-24936
9.0 CRITICAL

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the …

Jul 21, 2025
CVE-2025-0664

A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library. This may impair …

Jul 21, 2025
CVE-2025-7918
9.8 CRITICAL

WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and …

Jul 21, 2025
CVE-2025-7917
7.2 HIGH

WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell …

Jul 21, 2025
CVE-2025-7916
9.8 CRITICAL

WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted …

Jul 21, 2025
CVE-2025-54352
3.7 LOW

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing …

Jul 21, 2025
CVE-2025-7915
7.3 HIGH

A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mail/mailinactive.php of …

Jul 21, 2025
CVE-2025-7914
8.8 HIGH

A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the component httpd. …

Jul 21, 2025
CVE-2025-7913
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function updateWifiInfo of the component MQTT Service. The manipulation …

Jul 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.