CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-52363
6.8 MEDIUM

Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image …

Jul 14, 2025
CVE-2025-7626
4.3 MEDIUM

A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the …

Jul 14, 2025
CVE-2025-7625
4.3 MEDIUM

A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function Download of the file /download. The …

Jul 14, 2025
CVE-2025-51660
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.

Jul 14, 2025
CVE-2025-51659
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.

Jul 14, 2025
CVE-2025-51658
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.

Jul 14, 2025
CVE-2025-51657
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.

Jul 14, 2025
CVE-2025-51656
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.

Jul 14, 2025
CVE-2025-51655
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.

Jul 14, 2025
CVE-2025-51654
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.

Jul 14, 2025
CVE-2025-51653
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.

Jul 14, 2025
CVE-2025-51652
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.

Jul 14, 2025
CVE-2025-51651
5.5 MEDIUM

An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.

Jul 14, 2025
CVE-2025-51650
5.6 MEDIUM

An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.

Jul 14, 2025
CVE-2024-42649
6.5 MEDIUM

NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

Jul 14, 2025
CVE-2024-42648
6.5 MEDIUM

NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

Jul 14, 2025
CVE-2024-42646
7.5 HIGH

A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.

Jul 14, 2025
CVE-2025-7616
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of …

Jul 14, 2025
CVE-2025-7615
6.3 MEDIUM

A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file /cgi-bin/cstecgi.cgi of the …

Jul 14, 2025
CVE-2025-7614
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi of the component HTTP …

Jul 14, 2025
CVE-2025-7613
6.3 MEDIUM

A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file /cgi-bin/cstecgi.cgi of …

Jul 14, 2025
CVE-2025-7612
7.3 HIGH

A vulnerability was found in code-projects Mobile Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /login.php. The …

Jul 14, 2025
CVE-2025-7611
7.3 HIGH

A vulnerability was found in code-projects Wedding Reservation 1.0. It has been classified as critical. This affects an unknown part of the file /global.php. The …

Jul 14, 2025
CVE-2025-50756
9.8 CRITICAL

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute …

Jul 14, 2025
CVE-2025-7610
7.3 HIGH

A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jul 14, 2025
CVE-2025-7609
7.3 HIGH

A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 14, 2025
CVE-2025-7608
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The …

Jul 14, 2025
CVE-2025-7607
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file …

Jul 14, 2025
CVE-2025-7519
6.7 MEDIUM

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. …

Jul 14, 2025
CVE-2025-7606
7.3 HIGH

A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of the file /city.php. The manipulation of …

Jul 14, 2025
CVE-2025-7605
7.3 HIGH

A vulnerability was found in code-projects AVL Rooms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 14, 2025
CVE-2025-7604
7.3 HIGH

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 14, 2025
CVE-2025-7603
7.2 HIGH

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown function of the file /jingx.asp of the …

Jul 14, 2025
CVE-2025-27582
7.6 HIGH

The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within …

Jul 14, 2025
CVE-2025-7602
7.2 HIGH

A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /arp_sys.asp of the component …

Jul 14, 2025
CVE-2025-7601
3.5 LOW

A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/student-history.php. …

Jul 14, 2025
CVE-2025-7600
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Online Library Management System 3.0. This affects an unknown part of the file /admin/student-history.php. …

Jul 14, 2025
CVE-2025-7599
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected by this issue is some unknown …

Jul 14, 2025
CVE-2025-7618

A stored Cross-Site Scripting (XSS) vulnerability vulnerability was found in the File Explorer and Text Editor of ADM. An attacker could exploit this vulnerability to …

Jul 14, 2025
CVE-2025-7598
8.8 HIGH

A vulnerability classified as critical was found in Tenda AX1803 1.0.0.1. Affected by this vulnerability is the function formSetWifiMacFilterCfg of the file /goform/setWifiFilterCfg. The manipulation …

Jul 14, 2025
CVE-2025-7597
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AX1803 1.0.0.1. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the …

Jul 14, 2025
CVE-2025-7596
8.8 HIGH

A vulnerability was found in Tenda FH1205 2.0.0.7(775). It has been rated as critical. This issue affects the function formWifiExtraSet of the file /goform/WifiExtraSet. The …

Jul 14, 2025
CVE-2025-7595
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view-cad.php. The …

Jul 14, 2025
CVE-2024-51770
7.5 HIGH

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Jul 14, 2025
CVE-2024-51769
7.5 HIGH

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Jul 14, 2025
CVE-2024-51768
8.0 HIGH

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Jul 14, 2025
CVE-2024-51767
7.3 HIGH

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Jul 14, 2025
CVE-2025-7594
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0. It has been classified as critical. This affects an unknown part of the file /view-emp.php. The …

Jul 14, 2025
CVE-2025-7593
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-all.php. …

Jul 14, 2025
CVE-2025-7592
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality …

Jul 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.