CVE Database

116527+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53626
6.1 MEDIUM

pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading …

Jul 10, 2025
CVE-2025-53625

The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. Several #dpl parameters can leak usernames …

Jul 10, 2025
CVE-2025-53549

The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection vulnerability in the …

Jul 10, 2025
CVE-2025-53542
7.7 HIGH

Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script used in the macOS packaging workflow of the …

Jul 10, 2025
CVE-2025-53503
7.8 HIGH

Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files …

Jul 10, 2025
CVE-2025-53378
7.6 HIGH

A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the …

Jul 10, 2025
CVE-2025-52837
7.8 HIGH

Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity …

Jul 10, 2025
CVE-2025-52521
7.8 HIGH

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged …

Jul 10, 2025
CVE-2025-52520
7.5 HIGH

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This …

Jul 10, 2025
CVE-2025-52473
5.9 MEDIUM

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the …

Jul 10, 2025
CVE-2025-52434
7.5 HIGH

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client …

Jul 10, 2025
CVE-2025-28245
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web script or HTML via the notification body.

Jul 10, 2025
CVE-2025-28244
8.8 HIGH

Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user session tokens from localStorage, leading to account …

Jul 10, 2025
CVE-2025-28243
8.0 HIGH

An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component.

Jul 10, 2025
CVE-2025-53371
9.1 CRITICAL

DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows sending requests via curl and …

Jul 10, 2025
CVE-2025-7410
7.3 HIGH

A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unknown function of the file /cart_remove.php. The …

Jul 10, 2025
CVE-2025-7409
7.3 HIGH

A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown processing of the file /LoginAsAdmin.php. The manipulation …

Jul 10, 2025
CVE-2025-53020
7.5 HIGH

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are …

Jul 10, 2025
CVE-2025-49812
7.4 HIGH

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session …

Jul 10, 2025
CVE-2025-49630
7.5 HIGH

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing …

Jul 10, 2025
CVE-2025-49464
6.5 MEDIUM

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

Jul 10, 2025
CVE-2025-49463
6.5 MEDIUM

Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via …

Jul 10, 2025
CVE-2025-49462
3.5 LOW

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.

Jul 10, 2025
CVE-2025-47813
4.3 MEDIUM KEV

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

Jul 10, 2025
CVE-2025-47812
10.0 CRITICAL KEV

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session …

Jul 10, 2025
CVE-2025-47811
4.1 MEDIUM

In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web …

Jul 10, 2025
CVE-2025-27889
3.4 LOW

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If …

Jul 10, 2025
CVE-2025-23048
9.1 CRITICAL

In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session …

Jul 10, 2025
CVE-2024-47252
7.5 HIGH

Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log …

Jul 10, 2025
CVE-2024-43394
7.5 HIGH

Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions …

Jul 10, 2025
CVE-2024-43204
7.5 HIGH

SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an …

Jul 10, 2025
CVE-2024-42516
7.5 HIGH

HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied …

Jul 10, 2025
CVE-2025-6395
6.5 MEDIUM

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

Jul 10, 2025
CVE-2025-53364
5.3 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and …

Jul 10, 2025
CVE-2025-46789
6.5 MEDIUM

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

Jul 10, 2025
CVE-2025-46788
7.4 HIGH

Improper certificate validation in Zoom Workplace for Linux before version 6.4.13 may allow an unauthorized user to conduct an information disclosure via network access.

Jul 10, 2025
CVE-2025-7408
3.5 LOW

A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/templates/animal_form_template.php. The …

Jul 10, 2025
CVE-2025-7370

Rejected reason: Upon investigtion upstream maintainers discovered this was not a real issue. See the references for more details. See: https://gitlab.gnome.org/GNOME/libsoup/-/issues/430#note_2494090.

Jul 10, 2025
CVE-2025-7365
7.1 HIGH

A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the …

Jul 10, 2025
CVE-2025-46835
8.5 HIGH

Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked …

Jul 10, 2025
CVE-2025-46334
8.6 HIGH

Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical …

Jul 10, 2025
CVE-2025-44251
7.5 HIGH

Ecovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.

Jul 10, 2025
CVE-2025-36090
4.3 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the application framework which could be used …

Jul 10, 2025
CVE-2025-27614
8.6 HIGH

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social …

Jul 10, 2025
CVE-2025-27613
3.6 LOW

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, …

Jul 10, 2025
CVE-2024-39752
6.8 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to …

Jul 10, 2025
CVE-2024-38327
6.8 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exposed JavaScript source map which …

Jul 10, 2025
CVE-2024-37524
5.3 MEDIUM

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is …

Jul 10, 2025
CVE-2025-7425
7.8 HIGH

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, …

Jul 10, 2025
CVE-2025-7424
7.5 HIGH

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to …

Jul 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.