CVE Database

116228+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24477
4.2 MEDIUM

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its …

Jul 15, 2025
CVE-2025-7672
4.3 MEDIUM

The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XSS. This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23.

Jul 15, 2025
CVE-2025-3621
9.6 CRITICAL

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. * vulnerabilities: * Improper Neutralization of Special …

Jul 15, 2025
CVE-2025-7367
6.4 MEDIUM

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 …

Jul 15, 2025
CVE-2025-7360
9.1 CRITICAL

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving due …

Jul 15, 2025
CVE-2025-7341
9.1 CRITICAL

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due …

Jul 15, 2025
CVE-2025-7340
9.8 CRITICAL

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due …

Jul 15, 2025
CVE-2025-5394
9.8 CRITICAL

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the …

Jul 15, 2025
CVE-2025-5393
9.1 CRITICAL

The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the …

Jul 15, 2025
CVE-2025-6265
7.2 HIGH

A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator …

Jul 15, 2025
CVE-2025-53891
4.3 MEDIUM

The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found in the TIME LINE website where uploaded files (instruction/message …

Jul 15, 2025
CVE-2025-53890
9.8 CRITICAL

pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows unauthenticated remote attackers to …

Jul 15, 2025
CVE-2025-53889
6.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with …

Jul 15, 2025
CVE-2025-53887
5.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus …

Jul 15, 2025
CVE-2025-53886
4.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus …

Jul 15, 2025
CVE-2025-53885
4.2 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus …

Jul 15, 2025
CVE-2025-53839
4.0 MEDIUM

DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON …

Jul 15, 2025
CVE-2025-53836
9.9 CRITICAL

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting …

Jul 15, 2025
CVE-2025-53835
9.0 CRITICAL

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting …

Jul 14, 2025
CVE-2025-53834
6.3 MEDIUM

Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s toast UI component in versions prior to 0.49.0. …

Jul 14, 2025
CVE-2025-53833
10.0 CRITICAL

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template …

Jul 14, 2025
CVE-2025-53825
9.4 CRITICAL

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to …

Jul 14, 2025
CVE-2025-53824
5.4 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jul 14, 2025
CVE-2025-53823
8.8 HIGH

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection …

Jul 14, 2025
CVE-2025-53822
6.5 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jul 14, 2025
CVE-2025-53821
4.7 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the web …

Jul 14, 2025
CVE-2025-53820
6.5 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified …

Jul 14, 2025
CVE-2025-53819
7.9 HIGH

Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of …

Jul 14, 2025
CVE-2025-53818

GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version …

Jul 14, 2025
CVE-2025-53643
7.5 HIGH

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability …

Jul 14, 2025
CVE-2025-53640
6.5 MEDIUM

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an …

Jul 14, 2025
CVE-2025-53639
9.8 CRITICAL

MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not properly validated or sanitized. …

Jul 14, 2025
CVE-2025-53623

The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11.0 have an arbitrary code execution …

Jul 14, 2025
CVE-2025-53101
7.4 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, …

Jul 14, 2025
CVE-2025-53019
3.7 LOW

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, …

Jul 14, 2025
CVE-2025-53015
7.5 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a …

Jul 14, 2025
CVE-2025-7628
5.4 MEDIUM

A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects the function deleteFile of the file /deleteFile. …

Jul 14, 2025
CVE-2025-7627
6.3 MEDIUM

A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this issue is the function fileUpload of the file …

Jul 14, 2025
CVE-2025-53014
3.7 LOW

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in …

Jul 14, 2025
CVE-2025-52363
6.8 MEDIUM

Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image …

Jul 14, 2025
CVE-2025-7626
4.3 MEDIUM

A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the …

Jul 14, 2025
CVE-2025-7625
4.3 MEDIUM

A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function Download of the file /download. The …

Jul 14, 2025
CVE-2025-51660
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.

Jul 14, 2025
CVE-2025-51659
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.

Jul 14, 2025
CVE-2025-51658
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.

Jul 14, 2025
CVE-2025-51657
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.

Jul 14, 2025
CVE-2025-51656
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.

Jul 14, 2025
CVE-2025-51655
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.

Jul 14, 2025
CVE-2025-51654
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.

Jul 14, 2025
CVE-2025-51653
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.

Jul 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.