CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41169
7.5 HIGH

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue …

Jul 12, 2025
CVE-2025-7480
7.3 HIGH

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 12, 2025
CVE-2025-7479
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 12, 2025
CVE-2025-7478
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. Affected is an unknown function of the file /admin/category-list.php. The manipulation …

Jul 12, 2025
CVE-2025-7477
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the …

Jul 12, 2025
CVE-2025-7476
7.3 HIGH

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /admin/approve.php. The manipulation …

Jul 12, 2025
CVE-2025-7475
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part of the file /pay.php. The …

Jul 12, 2025
CVE-2025-7474
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 12, 2025
CVE-2025-7471
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 12, 2025
CVE-2025-36104
6.5 MEDIUM

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the …

Jul 12, 2025
CVE-2021-4458
5.9 MEDIUM

The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions …

Jul 12, 2025
CVE-2020-36849
9.8 CRITICAL

The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file in versions …

Jul 12, 2025
CVE-2020-36848
7.5 HIGH

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Jul 12, 2025
CVE-2025-7470
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jul 12, 2025
CVE-2025-7469
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/product_add.php. …

Jul 12, 2025
CVE-2025-7518
4.9 MEDIUM

The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via the get_local_filename() function. This makes it …

Jul 12, 2025
CVE-2020-36847
9.8 CRITICAL

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be …

Jul 12, 2025
CVE-2025-7504
7.5 HIGH

The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes …

Jul 12, 2025
CVE-2025-7468
8.8 HIGH

A vulnerability has been found in Tenda FH1201 1.2.0.14 and classified as critical. This vulnerability affects the function fromSafeUrlFilter of the file /goform/fromSafeUrlFilter of the …

Jul 12, 2025
CVE-2025-7467
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /product-detail.php. The manipulation …

Jul 12, 2025
CVE-2025-7466
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000projects ABC Courier Management 1.0. Affected by this issue is some unknown functionality of …

Jul 12, 2025
CVE-2025-6423
8.8 HIGH

The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_upload_file() function in all versions …

Jul 12, 2025
CVE-2025-7465
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH1201 1.2.0.14. Affected by this vulnerability is the function fromRouteStatic of the file /goform/fromRouteStatic of the …

Jul 12, 2025
CVE-2025-7464
3.7 LOW

A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR of the file pkg/packet/rtr/rtr.go. The manipulation …

Jul 12, 2025
CVE-2025-7463
8.8 HIGH

A vulnerability was found in Tenda FH1201 1.2.0.14. It has been declared as critical. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of …

Jul 12, 2025
CVE-2025-7462
4.3 MEDIUM

A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. This affects the function pdf_ferror of the file devices/vector/gdevpdf.c …

Jul 12, 2025
CVE-2025-1313
8.8 HIGH

The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, …

Jul 12, 2025
CVE-2025-7461
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. …

Jul 12, 2025
CVE-2025-6058
9.8 CRITICAL

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' …

Jul 12, 2025
CVE-2025-6057
8.8 HIGH

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up …

Jul 12, 2025
CVE-2025-24294
7.5 HIGH

The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain …

Jul 12, 2025
CVE-2024-38648
5.7 MEDIUM

A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.

Jul 12, 2025
CVE-2023-39339
4.9 MEDIUM

A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can perform an arbitrary file read via a maliciously …

Jul 12, 2025
CVE-2023-39338
6.8 MEDIUM

Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry policy to …

Jul 12, 2025
CVE-2023-38036
9.8 CRITICAL

A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service …

Jul 12, 2025
CVE-2025-53879

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53878

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53877

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53876

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53875

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53874

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53873

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53872

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53871

Rejected reason: Not used

Jul 12, 2025
CVE-2025-5199
7.3 HIGH

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed …

Jul 12, 2025
CVE-2025-7460
8.8 HIGH

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi …

Jul 11, 2025
CVE-2025-53636
5.4 MEDIUM

Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs …

Jul 11, 2025
CVE-2025-7459
7.3 HIGH

A vulnerability classified as critical was found in code-projects Mobile Shop 1.0. This vulnerability affects unknown code of the file /EditMobile.php. The manipulation of the …

Jul 11, 2025
CVE-2025-7457
7.3 HIGH

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects an unknown part of the …

Jul 11, 2025
CVE-2025-7456
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this issue is some …

Jul 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.