CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7505
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function frmL7ProtForm of the file /goform/L7Prot of the component HTTP …

Jul 12, 2025
CVE-2025-7492
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 12, 2025
CVE-2025-7491
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 12, 2025
CVE-2025-7490
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. Affected is an unknown function of the file …

Jul 12, 2025
CVE-2025-7489
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. This issue affects some unknown processing of the file /admin/search-vehicle.php. …

Jul 12, 2025
CVE-2025-7488
4.3 MEDIUM

A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and classified as critical. This vulnerability affects the function Download of the file /file/download. …

Jul 12, 2025
CVE-2025-7487
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This affects the function SysFileController of the file /file/upload. The …

Jul 12, 2025
CVE-2025-7485
3.3 LOW

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler of the component SCTP Partial …

Jul 12, 2025
CVE-2025-7484
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Vehicle Parking Management System 1.13. Affected is an unknown function of the file /admin/view-outgoingvehicle-detail.php. The …

Jul 12, 2025
CVE-2025-7483
7.3 HIGH

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been rated as critical. This issue affects some unknown processing of the …

Jul 12, 2025
CVE-2025-7482
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 12, 2025
CVE-2025-7481
6.3 MEDIUM

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This affects an unknown part of the file …

Jul 12, 2025
CVE-2024-41169
7.5 HIGH

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue …

Jul 12, 2025
CVE-2025-7480
7.3 HIGH

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 12, 2025
CVE-2025-7479
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 12, 2025
CVE-2025-7478
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. Affected is an unknown function of the file /admin/category-list.php. The manipulation …

Jul 12, 2025
CVE-2025-7477
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the …

Jul 12, 2025
CVE-2025-7476
7.3 HIGH

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /admin/approve.php. The manipulation …

Jul 12, 2025
CVE-2025-7475
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part of the file /pay.php. The …

Jul 12, 2025
CVE-2025-7474
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 12, 2025
CVE-2025-7471
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 12, 2025
CVE-2025-36104
6.5 MEDIUM

IBM Storage Scale 5.2.3.0 and 5.2.3.1 could allow an authenticated user to obtain sensitive information from files due to the insecure permissions inherited through the …

Jul 12, 2025
CVE-2021-4458
5.9 MEDIUM

The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions …

Jul 12, 2025
CVE-2020-36849
9.8 CRITICAL

The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file in versions …

Jul 12, 2025
CVE-2020-36848
7.5 HIGH

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Jul 12, 2025
CVE-2025-7470
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jul 12, 2025
CVE-2025-7469
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/product_add.php. …

Jul 12, 2025
CVE-2025-7518
4.9 MEDIUM

The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via the get_local_filename() function. This makes it …

Jul 12, 2025
CVE-2020-36847
9.8 CRITICAL

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be …

Jul 12, 2025
CVE-2025-7504
7.5 HIGH

The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes …

Jul 12, 2025
CVE-2025-7468
8.8 HIGH

A vulnerability has been found in Tenda FH1201 1.2.0.14 and classified as critical. This vulnerability affects the function fromSafeUrlFilter of the file /goform/fromSafeUrlFilter of the …

Jul 12, 2025
CVE-2025-7467
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /product-detail.php. The manipulation …

Jul 12, 2025
CVE-2025-7466
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000projects ABC Courier Management 1.0. Affected by this issue is some unknown functionality of …

Jul 12, 2025
CVE-2025-6423
8.8 HIGH

The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_upload_file() function in all versions …

Jul 12, 2025
CVE-2025-7465
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH1201 1.2.0.14. Affected by this vulnerability is the function fromRouteStatic of the file /goform/fromRouteStatic of the …

Jul 12, 2025
CVE-2025-7464
3.7 LOW

A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR of the file pkg/packet/rtr/rtr.go. The manipulation …

Jul 12, 2025
CVE-2025-7463
8.8 HIGH

A vulnerability was found in Tenda FH1201 1.2.0.14. It has been declared as critical. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of …

Jul 12, 2025
CVE-2025-7462
4.3 MEDIUM

A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. This affects the function pdf_ferror of the file devices/vector/gdevpdf.c …

Jul 12, 2025
CVE-2025-1313
8.8 HIGH

The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, …

Jul 12, 2025
CVE-2025-7461
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. …

Jul 12, 2025
CVE-2025-6058
9.8 CRITICAL

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' …

Jul 12, 2025
CVE-2025-6057
8.8 HIGH

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up …

Jul 12, 2025
CVE-2025-24294
7.5 HIGH

The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain …

Jul 12, 2025
CVE-2024-38648
5.7 MEDIUM

A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.

Jul 12, 2025
CVE-2023-39339
4.9 MEDIUM

A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can perform an arbitrary file read via a maliciously …

Jul 12, 2025
CVE-2023-39338
6.8 MEDIUM

Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry policy to …

Jul 12, 2025
CVE-2023-38036
9.8 CRITICAL

A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service …

Jul 12, 2025
CVE-2025-53879

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53878

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53877

Rejected reason: Not used

Jul 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.