CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7871
3.5 LOW

A vulnerability has been found in Portabilis i-Diario 1.5.0 and classified as problematic. This vulnerability affects unknown code of the file /conteudos. The manipulation of …

Jul 20, 2025
CVE-2025-7870
3.5 LOW

A vulnerability, which was classified as problematic, was found in Portabilis i-Diario 1.5.0. This affects an unknown part of the component justificativas-de-falta Endpoint. The manipulation …

Jul 20, 2025
CVE-2025-7869
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file …

Jul 20, 2025
CVE-2025-7868
3.5 LOW

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /intranet/educar_calendario_dia_motivo_cad.php of the component Calendar Module. …

Jul 20, 2025
CVE-2025-7867
3.5 LOW

A vulnerability has been found in Portabilis i-Educar 2.9.0/2.10.0. This vulnerability affects unknown code of the file /intranet/agenda.php of the component Agenda Module. The manipulation …

Jul 20, 2025
CVE-2025-7866
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.9.0. It has been rated as problematic. This issue affects some unknown processing of the file /intranet/educar_deficiencia_lst.php of …

Jul 20, 2025
CVE-2025-7865
3.5 LOW

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been declared as problematic. This vulnerability affects the function xssFilter of the file …

Jul 20, 2025
CVE-2025-7864
6.3 MEDIUM

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main/java/com/jeesite/modules/file/web/FileUploadController.java. …

Jul 20, 2025
CVE-2025-7863
3.5 LOW

A vulnerability was found in thinkgem JeeSite up to 5.12.0 and classified as problematic. Affected by this issue is the function redirectUrl of the file …

Jul 20, 2025
CVE-2025-7862
7.3 HIGH

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi …

Jul 20, 2025
CVE-2025-54314
2.8 LOW

Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed …

Jul 20, 2025
CVE-2025-7861
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an unknown function of the file /members/search.php. The …

Jul 20, 2025
CVE-2025-7860
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file …

Jul 20, 2025
CVE-2025-7859
7.3 HIGH

A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/update_password_admin.php. The manipulation of …

Jul 20, 2025
CVE-2025-53770
9.8 CRITICAL KEV

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit …

Jul 20, 2025
CVE-2025-7858
3.5 LOW

A vulnerability classified as problematic has been found in PHPGurukul Apartment Visitors Management System 1.0. This affects an unknown part of the file /admin-profile.php of …

Jul 20, 2025
CVE-2025-7857
3.5 LOW

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Jul 19, 2025
CVE-2025-7856
3.5 LOW

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Jul 19, 2025
CVE-2025-7855
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromqossetting of the file /goform/qossetting. The manipulation …

Jul 19, 2025
CVE-2025-7854
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the …

Jul 19, 2025
CVE-2025-7853
8.8 HIGH

A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. The …

Jul 19, 2025
CVE-2025-7840
3.5 LOW

A vulnerability was found in Campcodes Online Movie Theater Seat Reservation System 1.0. It has been classified as problematic. This affects an unknown part of …

Jul 19, 2025
CVE-2025-7838
7.3 HIGH

A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Jul 19, 2025
CVE-2025-7837
8.8 HIGH

A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the component MQTT Service. …

Jul 19, 2025
CVE-2025-7836
6.3 MEDIUM

A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_system of the …

Jul 19, 2025
CVE-2025-54313
7.5 HIGH KEV

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches …

Jul 19, 2025
CVE-2025-7834
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function. The manipulation leads to cross-site …

Jul 19, 2025
CVE-2025-7833
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file …

Jul 19, 2025
CVE-2025-7832
7.3 HIGH

A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/offering.php. The manipulation of …

Jul 19, 2025
CVE-2025-7831
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unknown part of the file /members/Tithes.php. The manipulation …

Jul 19, 2025
CVE-2025-7830
7.3 HIGH

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 19, 2025
CVE-2025-7829
7.3 HIGH

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 19, 2025
CVE-2025-7824
7.3 HIGH

A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The …

Jul 19, 2025
CVE-2025-7823
7.3 HIGH

A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation …

Jul 19, 2025
CVE-2025-7819
2.4 LOW

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as problematic. This affects an unknown part of the file …

Jul 19, 2025
CVE-2025-7818
3.5 LOW

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Jul 19, 2025
CVE-2025-7817
3.5 LOW

A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 19, 2025
CVE-2025-38351
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush In KVM guests with Hyper-V hypercalls …

Jul 19, 2025
CVE-2015-10139
8.8 HIGH

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for …

Jul 19, 2025
CVE-2015-10138
9.8 CRITICAL

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server …

Jul 19, 2025
CVE-2025-7816
3.5 LOW

A vulnerability, which was classified as problematic, was found in PHPGurukul Apartment Visitors Management System 1.0. Affected is an unknown function of the file /visitor-detail.php …

Jul 19, 2025
CVE-2025-7815
2.4 LOW

A vulnerability, which was classified as problematic, has been found in PHPGurukul Apartment Visitors Management System 1.0. This issue affects some unknown processing of the …

Jul 19, 2025
CVE-2016-15043
9.8 CRITICAL

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up …

Jul 19, 2025
CVE-2015-10136
7.5 HIGH

The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read …

Jul 19, 2025
CVE-2015-10135
9.8 CRITICAL

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in …

Jul 19, 2025
CVE-2015-10134
7.5 HIGH

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is …

Jul 19, 2025
CVE-2015-10133
7.2 HIGH

The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. …

Jul 19, 2025
CVE-2012-10019
9.8 CRITICAL

The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions …

Jul 19, 2025
CVE-2025-6997
6.4 MEDIUM

The ThemeREX Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.35.1.1 due …

Jul 19, 2025
CVE-2025-38350
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain classful qdiscs may invoke their …

Jul 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.