CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53876

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53875

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53874

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53873

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53872

Rejected reason: Not used

Jul 12, 2025
CVE-2025-53871

Rejected reason: Not used

Jul 12, 2025
CVE-2025-5199
7.3 HIGH

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed …

Jul 12, 2025
CVE-2025-7460
8.8 HIGH

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi …

Jul 11, 2025
CVE-2025-53636
5.4 MEDIUM

Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs …

Jul 11, 2025
CVE-2025-7459
7.3 HIGH

A vulnerability classified as critical was found in code-projects Mobile Shop 1.0. This vulnerability affects unknown code of the file /EditMobile.php. The manipulation of the …

Jul 11, 2025
CVE-2025-7457
7.3 HIGH

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects an unknown part of the …

Jul 11, 2025
CVE-2025-7456
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this issue is some …

Jul 11, 2025
CVE-2025-7455
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of …

Jul 11, 2025
CVE-2025-7503

An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credentials. The Telnet service is …

Jul 11, 2025
CVE-2025-7454
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected is an unknown function of the file …

Jul 11, 2025
CVE-2025-7453
3.7 LOW

A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file …

Jul 11, 2025
CVE-2025-3631
6.5 MEDIUM

An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it.

Jul 11, 2025
CVE-2025-30403
8.1 HIGH

A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.

Jul 11, 2025
CVE-2013-3307
8.3 HIGH

Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip …

Jul 11, 2025
CVE-2025-7452
6.3 MEDIUM

A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as critical. This vulnerability affects the function GetFile of the file …

Jul 11, 2025
CVE-2025-53642
4.8 MEDIUM

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the …

Jul 11, 2025
CVE-2025-53641
8.2 HIGH

Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into …

Jul 11, 2025
CVE-2025-30402
8.1 HIGH

A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. …

Jul 11, 2025
CVE-2025-7450
5.4 MEDIUM

A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the function ResetUserAvatar of the file controller/api/v1/user.go …

Jul 11, 2025
CVE-2025-47964
5.4 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jul 11, 2025
CVE-2025-47963
6.3 MEDIUM

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Jul 11, 2025
CVE-2025-47182
5.6 MEDIUM

Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

Jul 11, 2025
CVE-2025-45582
4.1 MEDIUM

GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an …

Jul 11, 2025
CVE-2025-43856

immich is a high performance self-hosted photo and video management solution. Prior to 1.132.0, immich is vulnerable to account hijacking through oauth2, because the state …

Jul 11, 2025
CVE-2024-47065
6.5 MEDIUM

Meshtastic is an open source mesh networking solution. Prior to 2.5.1, traceroute responses from the remote node are not rate limited. Given that there are …

Jul 11, 2025
CVE-2025-7029
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHeader, …

Jul 11, 2025
CVE-2025-7028
7.8 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0x20) allows a local attacker to supply a crafted pointer (FuncBlock) through RBX and RCX register values. …

Jul 11, 2025
CVE-2025-7027
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and write addresses used by the CommandRcx1 …

Jul 11, 2025
CVE-2025-7026
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer …

Jul 11, 2025
CVE-2025-6549
6.5 MEDIUM

An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to reach the Juniper …

Jul 11, 2025
CVE-2025-52989
5.1 MEDIUM

An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high …

Jul 11, 2025
CVE-2025-52988
6.7 MEDIUM

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS and Junos …

Jul 11, 2025
CVE-2025-52986
5.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jul 11, 2025
CVE-2025-52985
5.3 MEDIUM

A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security …

Jul 11, 2025
CVE-2025-52984
5.9 MEDIUM

A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker …

Jul 11, 2025
CVE-2025-52983
7.2 HIGH

A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to …

Jul 11, 2025
CVE-2025-52982
5.9 MEDIUM

An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based …

Jul 11, 2025
CVE-2025-52981
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX1600, SRX2300, SRX 4000 …

Jul 11, 2025
CVE-2025-52980
7.5 HIGH

A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on SRX300 Series allows an unauthenticated, network-based …

Jul 11, 2025
CVE-2025-52994
4.9 MEDIUM

gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.

Jul 11, 2025
CVE-2025-52964
6.5 MEDIUM

A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to …

Jul 11, 2025
CVE-2025-52963
5.5 MEDIUM

An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, …

Jul 11, 2025
CVE-2025-52958
5.3 MEDIUM

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to …

Jul 11, 2025
CVE-2025-52955
6.5 MEDIUM

An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent …

Jul 11, 2025
CVE-2025-52954
7.8 HIGH

A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain …

Jul 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.