CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7455
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of …

Jul 11, 2025
CVE-2025-7503

An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credentials. The Telnet service is …

Jul 11, 2025
CVE-2025-7454
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected is an unknown function of the file …

Jul 11, 2025
CVE-2025-7453
3.7 LOW

A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file …

Jul 11, 2025
CVE-2025-3631
6.5 MEDIUM

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

Jul 11, 2025
CVE-2025-30403
8.1 HIGH

A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.

Jul 11, 2025
CVE-2013-3307
8.3 HIGH

Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip …

Jul 11, 2025
CVE-2025-7452
6.3 MEDIUM

A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as critical. This vulnerability affects the function GetFile of the file …

Jul 11, 2025
CVE-2025-53642
4.8 MEDIUM

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the …

Jul 11, 2025
CVE-2025-53641
8.2 HIGH

Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into …

Jul 11, 2025
CVE-2025-30402
8.1 HIGH

A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. …

Jul 11, 2025
CVE-2025-7450
5.4 MEDIUM

A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the function ResetUserAvatar of the file controller/api/v1/user.go …

Jul 11, 2025
CVE-2025-47964
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jul 11, 2025
CVE-2025-47963
6.3 MEDIUM

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 11, 2025
CVE-2025-47182
5.6 MEDIUM

Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

Jul 11, 2025
CVE-2025-45582
4.1 MEDIUM

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an …

Jul 11, 2025
CVE-2025-43856

immich is a high performance self-hosted photo and video management solution. Prior to 1.132.0, immich is vulnerable to account hijacking through oauth2, because the state …

Jul 11, 2025
CVE-2024-47065
6.5 MEDIUM

Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are …

Jul 11, 2025
CVE-2025-7029
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHeader, …

Jul 11, 2025
CVE-2025-7028
7.8 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0x20) allows a local attacker to supply a crafted pointer (FuncBlock) through RBX and RCX register values. …

Jul 11, 2025
CVE-2025-7027
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and write addresses used by the CommandRcx1 …

Jul 11, 2025
CVE-2025-7026
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer …

Jul 11, 2025
CVE-2025-6549
6.5 MEDIUM

An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the Juniper …

Jul 11, 2025
CVE-2025-52989
5.1 MEDIUM

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high …

Jul 11, 2025
CVE-2025-52988
6.7 MEDIUM

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos …

Jul 11, 2025
CVE-2025-52986
5.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jul 11, 2025
CVE-2025-52985
5.3 MEDIUM

A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security …

Jul 11, 2025
CVE-2025-52984
5.9 MEDIUM

A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker …

Jul 11, 2025
CVE-2025-52983
7.2 HIGH

A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to …

Jul 11, 2025
CVE-2025-52982
5.9 MEDIUM

An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based …

Jul 11, 2025
CVE-2025-52981
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX1600, SRX2300, SRX 4000 …

Jul 11, 2025
CVE-2025-52980
7.5 HIGH

A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based …

Jul 11, 2025
CVE-2025-52994
4.9 MEDIUM

gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.

Jul 11, 2025
CVE-2025-52964
6.5 MEDIUM

A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to …

Jul 11, 2025
CVE-2025-52963
5.5 MEDIUM

An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, …

Jul 11, 2025
CVE-2025-52958
5.3 MEDIUM

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to …

Jul 11, 2025
CVE-2025-52955
6.5 MEDIUM

An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent …

Jul 11, 2025
CVE-2025-52954
7.8 HIGH

A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain …

Jul 11, 2025
CVE-2025-52953
6.5 MEDIUM

An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker …

Jul 11, 2025
CVE-2025-52952
6.5 MEDIUM

An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line …

Jul 11, 2025
CVE-2025-52951
5.8 MEDIUM

A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to …

Jul 11, 2025
CVE-2025-52950
9.6 CRITICAL

A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with multiple sensitive resources via the web …

Jul 11, 2025
CVE-2025-52949
6.5 MEDIUM

An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a …

Jul 11, 2025
CVE-2025-52948
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker, in rare cases, sending …

Jul 11, 2025
CVE-2025-52947
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker …

Jul 11, 2025
CVE-2025-52946
7.5 HIGH

A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker …

Jul 11, 2025
CVE-2025-52089
8.8 HIGH

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands …

Jul 11, 2025
CVE-2025-48924
5.3 MEDIUM

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. …

Jul 11, 2025
CVE-2025-30661
7.3 HIGH

An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, low-privileged user to install …

Jul 11, 2025
CVE-2023-38329
6.1 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web …

Jul 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.