CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-38327
5.3 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web …

Jul 11, 2025
CVE-2025-51591
3.7 LOW

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. …

Jul 11, 2025
CVE-2025-53862
3.5 LOW

A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data …

Jul 11, 2025
CVE-2025-53861
3.1 LOW

A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing …

Jul 11, 2025
CVE-2025-6788

A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with …

Jul 11, 2025
CVE-2025-50125

A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge …

Jul 11, 2025
CVE-2025-50124

A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and …

Jul 11, 2025
CVE-2025-50123

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server …

Jul 11, 2025
CVE-2025-50122

A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or …

Jul 11, 2025
CVE-2025-50121

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when …

Jul 11, 2025
CVE-2025-3933
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability …

Jul 11, 2025
CVE-2025-6851
7.2 HIGH

The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function …

Jul 11, 2025
CVE-2025-6838
4.1 MEDIUM

The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are …

Jul 11, 2025
CVE-2025-6438

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting …

Jul 11, 2025
CVE-2025-7442
7.5 HIGH

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters in the MJ_gmgt_delete_class_limit_for_member, MJ_gmgt_get_yearly_income_expense, MJ_gmgt_get_monthly_income_expense, MJ_gmgt_add_class_limit, MJ_gmgt_view_meeting_detail, …

Jul 11, 2025
CVE-2025-6745
5.3 MEDIUM

The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_query() function due to insufficient …

Jul 11, 2025
CVE-2025-6068
6.4 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & …

Jul 11, 2025
CVE-2025-5530
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shortcode_btn' shortcode in all versions up to, …

Jul 11, 2025
CVE-2025-4593
6.5 MEDIUM

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the …

Jul 11, 2025
CVE-2025-6716
6.4 MEDIUM

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress …

Jul 11, 2025
CVE-2025-5992

When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a …

Jul 11, 2025
CVE-2025-5392
9.8 CRITICAL

The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front() function. …

Jul 11, 2025
CVE-2025-5028

Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.

Jul 11, 2025
CVE-2025-6200
5.9 MEDIUM

The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Jul 11, 2025
CVE-2025-30026
9.8 CRITICAL

The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.

Jul 11, 2025
CVE-2025-30025
7.8 HIGH

The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.

Jul 11, 2025
CVE-2025-30024
6.8 MEDIUM

The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

Jul 11, 2025
CVE-2025-30023
9.0 CRITICAL

The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

Jul 11, 2025
CVE-2025-2942
4.3 MEDIUM

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing …

Jul 11, 2025
CVE-2025-7401
9.8 CRITICAL

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an …

Jul 11, 2025
CVE-2025-7436
7.3 HIGH

A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 11, 2025
CVE-2025-53852

Rejected reason: Not used

Jul 11, 2025
CVE-2025-53851

Rejected reason: Not used

Jul 11, 2025
CVE-2025-53850

Rejected reason: Not used

Jul 11, 2025
CVE-2025-53849

Rejected reason: Not used

Jul 11, 2025
CVE-2025-53848

Rejected reason: Not used

Jul 11, 2025
CVE-2025-7435
3.5 LOW

A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file …

Jul 11, 2025
CVE-2025-53864
5.8 MEDIUM

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply …

Jul 11, 2025
CVE-2025-7434
8.8 HIGH

A vulnerability was found in Tenda FH451 up to 1.0.0.9 and classified as critical. Affected by this issue is the function fromAddressNat of the file …

Jul 11, 2025
CVE-2025-7423
8.8 HIGH

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). Affected by this vulnerability is the function formWifiMacFilterSet of the file /goform/setWrlFilterList of the …

Jul 11, 2025
CVE-2025-7422
8.8 HIGH

A vulnerability classified as critical has been found in Tenda O3V2 1.0.0.12(3880). Affected is the function setAutoReboot of the file /goform/setNetworkService of the component httpd. …

Jul 11, 2025
CVE-2025-7421
8.8 HIGH

A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been rated as critical. This issue affects the function fromMacFilterModify of the file /goform/operateMacFilter of …

Jul 11, 2025
CVE-2025-5241
5.3 MEDIUM

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain …

Jul 11, 2025
CVE-2025-7420
8.8 HIGH

A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been declared as critical. This vulnerability affects the function formWifiBasicSet of the file /goform/setWrlBasicInfo of …

Jul 11, 2025
CVE-2025-53519
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, …

Jul 11, 2025
CVE-2025-53515
8.8 HIGH

A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at …

Jul 11, 2025
CVE-2025-53509
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. …

Jul 11, 2025
CVE-2025-53475
8.8 HIGH

A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with …

Jul 11, 2025
CVE-2025-53471
5.1 MEDIUM

Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to …

Jul 11, 2025
CVE-2025-53397
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, …

Jul 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.