CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-52953
6.5 MEDIUM

An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker …

Jul 11, 2025
CVE-2025-52952
6.5 MEDIUM

An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line …

Jul 11, 2025
CVE-2025-52951
5.8 MEDIUM

A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to …

Jul 11, 2025
CVE-2025-52950
9.6 CRITICAL

A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with multiple sensitive resources via the web …

Jul 11, 2025
CVE-2025-52949
6.5 MEDIUM

An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a …

Jul 11, 2025
CVE-2025-52948
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker, in rare cases, sending …

Jul 11, 2025
CVE-2025-52947
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker …

Jul 11, 2025
CVE-2025-52946
7.5 HIGH

A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an attacker …

Jul 11, 2025
CVE-2025-52089
8.8 HIGH

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to execute arbitrary OS commands …

Jul 11, 2025
CVE-2025-48924
5.3 MEDIUM

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. …

Jul 11, 2025
CVE-2025-30661
7.3 HIGH

An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Networks Junos OS allows a local, low-privileged user to install …

Jul 11, 2025
CVE-2023-38329
6.1 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web …

Jul 11, 2025
CVE-2023-38327
5.3 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web …

Jul 11, 2025
CVE-2025-51591
3.7 LOW

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. …

Jul 11, 2025
CVE-2025-53862
3.5 LOW

A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data …

Jul 11, 2025
CVE-2025-53861
3.1 LOW

A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing …

Jul 11, 2025
CVE-2025-6788

A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with …

Jul 11, 2025
CVE-2025-50125

A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge …

Jul 11, 2025
CVE-2025-50124

A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and …

Jul 11, 2025
CVE-2025-50123

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server …

Jul 11, 2025
CVE-2025-50122

A CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or …

Jul 11, 2025
CVE-2025-50121

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when …

Jul 11, 2025
CVE-2025-3933
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability …

Jul 11, 2025
CVE-2025-6851
7.2 HIGH

The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function …

Jul 11, 2025
CVE-2025-6838
4.1 MEDIUM

The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are …

Jul 11, 2025
CVE-2025-6438

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting …

Jul 11, 2025
CVE-2025-7442
7.5 HIGH

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters in the MJ_gmgt_delete_class_limit_for_member, MJ_gmgt_get_yearly_income_expense, MJ_gmgt_get_monthly_income_expense, MJ_gmgt_add_class_limit, MJ_gmgt_view_meeting_detail, …

Jul 11, 2025
CVE-2025-6745
5.3 MEDIUM

The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_query() function due to insufficient …

Jul 11, 2025
CVE-2025-6068
6.4 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & …

Jul 11, 2025
CVE-2025-5530
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shortcode_btn' shortcode in all versions up to, …

Jul 11, 2025
CVE-2025-4593
6.5 MEDIUM

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the …

Jul 11, 2025
CVE-2025-6716
6.4 MEDIUM

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress …

Jul 11, 2025
CVE-2025-5992

When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a …

Jul 11, 2025
CVE-2025-5392
9.8 CRITICAL

The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front() function. …

Jul 11, 2025
CVE-2025-5028

Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so.

Jul 11, 2025
CVE-2025-6200
5.9 MEDIUM

The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Jul 11, 2025
CVE-2025-30026
9.8 CRITICAL

The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.

Jul 11, 2025
CVE-2025-30025
7.8 HIGH

The communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalation.

Jul 11, 2025
CVE-2025-30024
6.8 MEDIUM

The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

Jul 11, 2025
CVE-2025-30023
9.0 CRITICAL

The communication protocol used between client and server had a flaw that could lead to an authenticated user performing a remote code execution attack.

Jul 11, 2025
CVE-2025-2942
4.3 MEDIUM

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing …

Jul 11, 2025
CVE-2025-7401
9.8 CRITICAL

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an …

Jul 11, 2025
CVE-2025-7436
7.3 HIGH

A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 11, 2025
CVE-2025-53852

Rejected reason: Not used

Jul 11, 2025
CVE-2025-53851

Rejected reason: Not used

Jul 11, 2025
CVE-2025-53850

Rejected reason: Not used

Jul 11, 2025
CVE-2025-53849

Rejected reason: Not used

Jul 11, 2025
CVE-2025-53848

Rejected reason: Not used

Jul 11, 2025
CVE-2025-7435
3.5 LOW

A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file …

Jul 11, 2025
CVE-2025-53864
5.8 MEDIUM

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply …

Jul 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.