CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7434
8.8 HIGH

A vulnerability was found in Tenda FH451 up to 1.0.0.9 and classified as critical. Affected by this issue is the function fromAddressNat of the file …

Jul 11, 2025
CVE-2025-7423
8.8 HIGH

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). Affected by this vulnerability is the function formWifiMacFilterSet of the file /goform/setWrlFilterList of the …

Jul 11, 2025
CVE-2025-7422
8.8 HIGH

A vulnerability classified as critical has been found in Tenda O3V2 1.0.0.12(3880). Affected is the function setAutoReboot of the file /goform/setNetworkService of the component httpd. …

Jul 11, 2025
CVE-2025-7421
8.8 HIGH

A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been rated as critical. This issue affects the function fromMacFilterModify of the file /goform/operateMacFilter of …

Jul 11, 2025
CVE-2025-5241
5.3 MEDIUM

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain …

Jul 11, 2025
CVE-2025-7420
8.8 HIGH

A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been declared as critical. This vulnerability affects the function formWifiBasicSet of the file /goform/setWrlBasicInfo of …

Jul 11, 2025
CVE-2025-53519
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, …

Jul 11, 2025
CVE-2025-53515
8.8 HIGH

A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at …

Jul 11, 2025
CVE-2025-53509
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. …

Jul 11, 2025
CVE-2025-53475
8.8 HIGH

A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with …

Jul 11, 2025
CVE-2025-53471
5.1 MEDIUM

Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to …

Jul 11, 2025
CVE-2025-53397
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, …

Jul 11, 2025
CVE-2025-52579
9.4 CRITICAL

Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain …

Jul 11, 2025
CVE-2025-52577
8.8 HIGH

A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at …

Jul 11, 2025
CVE-2025-52459
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain …

Jul 11, 2025
CVE-2025-50109
7.7 HIGH

Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.

Jul 11, 2025
CVE-2025-48891
7.6 HIGH

A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker …

Jul 11, 2025
CVE-2025-48496
5.1 MEDIUM

Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the …

Jul 11, 2025
CVE-2025-46704
4.3 MEDIUM

A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least …

Jul 11, 2025
CVE-2025-46358
7.7 HIGH

Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Jul 11, 2025
CVE-2025-41442
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input …

Jul 11, 2025
CVE-2025-7419
8.8 HIGH

A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fromSpeedTestSet of the file /goform/setRateTest of the …

Jul 10, 2025
CVE-2025-7418
8.8 HIGH

A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the function fromPingResultGet of the file /goform/setPing of …

Jul 10, 2025
CVE-2025-31267
4.6 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an …

Jul 10, 2025
CVE-2025-1727
8.1 HIGH

The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. …

Jul 10, 2025
CVE-2025-7417
8.8 HIGH

A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability is the function fromNetToolGet of the file /goform/setPingInfo …

Jul 10, 2025
CVE-2025-7416
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function fromSysToolTime of the file /goform/setSysTimeInfo of the component …

Jul 10, 2025
CVE-2025-6392
4.4 MEDIUM

Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec …

Jul 10, 2025
CVE-2025-53637
4.1 MEDIUM

Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be …

Jul 10, 2025
CVE-2025-24798
4.3 MEDIUM

Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. …

Jul 10, 2025
CVE-2025-7415
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of …

Jul 10, 2025
CVE-2025-7414
6.3 MEDIUM

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. …

Jul 10, 2025
CVE-2025-6390
4.4 MEDIUM

Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit …

Jul 10, 2025
CVE-2025-4662
4.4 MEDIUM

Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the …

Jul 10, 2025
CVE-2025-3947
8.2 HIGH

The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to …

Jul 10, 2025
CVE-2025-3946
8.2 HIGH

The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Control Data Access (CDA). An attacker could potentially …

Jul 10, 2025
CVE-2025-2523
9.4 CRITICAL

The Honeywell Experion PKS and OneWireless WDM contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this …

Jul 10, 2025
CVE-2025-2522
6.5 MEDIUM

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit …

Jul 10, 2025
CVE-2025-2521
8.6 HIGH

The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this …

Jul 10, 2025
CVE-2025-7413
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/profile.php. The manipulation of …

Jul 10, 2025
CVE-2025-7412
6.3 MEDIUM

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 10, 2025
CVE-2025-7021
6.5 MEDIUM

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker …

Jul 10, 2025
CVE-2025-53634
7.5 HIGH

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout set. With …

Jul 10, 2025
CVE-2025-53633
9.8 CRITICAL

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the size of …

Jul 10, 2025
CVE-2025-53632
9.1 CRITICAL

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the path of …

Jul 10, 2025
CVE-2025-53630

llama.cpp is an inference of several LLM models in C/C++. Integer Overflow in the gguf_init_from_file_impl function in ggml/src/gguf.cpp can lead to Heap Out-of-Bounds Read/Write. This …

Jul 10, 2025
CVE-2025-53629
7.5 HIGH

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily …

Jul 10, 2025
CVE-2025-53628
8.8 HIGH

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an …

Jul 10, 2025
CVE-2025-53506
7.5 HIGH

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. …

Jul 10, 2025
CVE-2025-45662
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's …

Jul 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.