CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7196
7.3 HIGH

A vulnerability was found in code-projects Jonnys Liquor 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 8, 2025
CVE-2025-7194
8.8 HIGH

A vulnerability was found in D-Link DI-500WF 17.04.10A1T. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file …

Jul 8, 2025
CVE-2025-7031
5.3 MEDIUM

Missing Authentication for Critical Function vulnerability in Drupal Config Pages Viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Config Pages Viewer: from …

Jul 8, 2025
CVE-2025-7030
6.5 MEDIUM

Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from …

Jul 8, 2025
CVE-2025-49551
8.8 HIGH

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could …

Jul 8, 2025
CVE-2025-49546
2.4 LOW

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged …

Jul 8, 2025
CVE-2025-49545
6.2 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A …

Jul 8, 2025
CVE-2025-49544
6.8 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a …

Jul 8, 2025
CVE-2025-49543
4.3 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to …

Jul 8, 2025
CVE-2025-49542
5.2 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a …

Jul 8, 2025
CVE-2025-49541
4.3 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to …

Jul 8, 2025
CVE-2025-49540
4.3 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to …

Jul 8, 2025
CVE-2025-49539
4.5 MEDIUM

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a …

Jul 8, 2025
CVE-2025-49538
7.4 HIGH

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can …

Jul 8, 2025
CVE-2025-49537
7.9 HIGH

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability …

Jul 8, 2025
CVE-2025-49536
7.3 HIGH

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker …

Jul 8, 2025
CVE-2025-49535
9.3 CRITICAL

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a …

Jul 8, 2025
CVE-2025-43584
5.5 MEDIUM

Substance3D - Viewer versions 0.22 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Jul 8, 2025
CVE-2025-43583
5.5 MEDIUM

Substance3D - Viewer versions 0.22 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

Jul 8, 2025
CVE-2025-43582
7.8 HIGH

Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jul 8, 2025
CVE-2025-7193
7.3 HIGH

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as critical. Affected is an unknown function of …

Jul 8, 2025
CVE-2025-7192
6.3 MEDIUM

A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of …

Jul 8, 2025
CVE-2025-53355
7.5 HIGH

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulnerability exists in the mcp-server-kubernetes …

Jul 8, 2025
CVE-2025-37103
9.8 CRITICAL

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation …

Jul 8, 2025
CVE-2025-7191
7.3 HIGH

A vulnerability has been found in code-projects Student Enrollment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The …

Jul 8, 2025
CVE-2025-7190
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The …

Jul 8, 2025
CVE-2025-48386
6.3 MEDIUM

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. …

Jul 8, 2025
CVE-2025-48385

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. …

Jul 8, 2025
CVE-2025-48384
8.0 HIGH KEV

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. …

Jul 8, 2025
CVE-2025-37102
7.2 HIGH

An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote …

Jul 8, 2025
CVE-2025-27369
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST …

Jul 8, 2025
CVE-2025-27367
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to improper input validation due to bypassing of client-side validation for the data types and requiredness …

Jul 8, 2025
CVE-2024-49784
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data with AES encryption and CBC mode. If …

Jul 8, 2025
CVE-2024-49783
5.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in storage of encrypted data. If an authenticated remote attacker with access …

Jul 8, 2025
CVE-2023-43039
6.1 MEDIUM

IBM OpenPages with Watson 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Jul 8, 2025
CVE-2025-7363
5.4 MEDIUM

The TitleIcon extension for MediaWiki is vulnerable to stored XSS through the #titleicon_unicode parser function. User input passed to this function is wrapped in an …

Jul 8, 2025
CVE-2025-7362
5.4 MEDIUM

The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted into the DOM without proper sanitization. The …

Jul 8, 2025
CVE-2025-7189
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the …

Jul 8, 2025
CVE-2025-7188
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The …

Jul 8, 2025
CVE-2025-53479
5.4 MEDIUM

The CheckUser extension’s Special:CheckUser interface is vulnerable to reflected XSS via the rev-deleted-user message. This message is rendered without proper escaping, making it possible to …

Jul 8, 2025
CVE-2025-4663
4.9 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in Brocade Fabric OS before 9.2.2.a could allow an authenticated, network-based attacker to cause a Denial-of-Service …

Jul 8, 2025
CVE-2025-47135
5.5 MEDIUM

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Jul 8, 2025
CVE-2025-30312
7.8 HIGH

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current …

Jul 8, 2025
CVE-2025-0928
8.8 HIGH

In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the …

Jul 8, 2025
CVE-2025-7187
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The manipulation of …

Jul 8, 2025
CVE-2025-7186
6.3 MEDIUM

A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_chat.php. …

Jul 8, 2025
CVE-2025-53513
8.8 HIGH

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading …

Jul 8, 2025
CVE-2025-53512
6.5 MEDIUM

The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.

Jul 8, 2025
CVE-2025-49760
3.5 LOW

External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.

Jul 8, 2025
CVE-2025-49756
3.3 LOW

Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.