CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6744
7.3 HIGH

The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.2.3. This is due to the …

Jul 8, 2025
CVE-2025-7171
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Crime Reporting System 1.0. Affected by this issue is some unknown functionality of …

Jul 8, 2025
CVE-2025-7170
7.3 HIGH

A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. …

Jul 8, 2025
CVE-2025-7169
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknown function of the file /complainer_page.php. The manipulation …

Jul 8, 2025
CVE-2025-7168
7.3 HIGH

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 8, 2025
CVE-2025-38237
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() In fimc_is_hw_change_mode(), the function changes camera …

Jul 8, 2025
CVE-2025-38236
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs. Jann Horn reported a use-after-free in unix_stream_read_generic(). The …

Jul 8, 2025
CVE-2025-7346

Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages

Jul 8, 2025
CVE-2025-7167
6.3 MEDIUM

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. …

Jul 8, 2025
CVE-2025-7166
6.3 MEDIUM

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an unknown part of the file /single.php. …

Jul 8, 2025
CVE-2025-6746
8.8 HIGH

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes …

Jul 8, 2025
CVE-2025-6743
6.4 MEDIUM

The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attribute in all versions up to, and including, 8.2.3 due …

Jul 8, 2025
CVE-2025-42956
6.1 MEDIUM

SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an …

Jul 8, 2025
CVE-2025-41668
8.8 HIGH

A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and …

Jul 8, 2025
CVE-2025-41667
8.8 HIGH

A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access …

Jul 8, 2025
CVE-2025-41666
8.8 HIGH

A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to …

Jul 8, 2025
CVE-2025-41665
6.5 MEDIUM

An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config …

Jul 8, 2025
CVE-2025-25271
8.8 HIGH

An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.

Jul 8, 2025
CVE-2025-25270
9.8 CRITICAL

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

Jul 8, 2025
CVE-2025-25269
8.4 HIGH

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

Jul 8, 2025
CVE-2025-25268
8.8 HIGH

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.

Jul 8, 2025
CVE-2025-24006
7.8 HIGH

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

Jul 8, 2025
CVE-2025-24005
7.8 HIGH

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

Jul 8, 2025
CVE-2025-24004
5.2 MEDIUM

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a …

Jul 8, 2025
CVE-2025-24003
8.2 HIGH

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of …

Jul 8, 2025
CVE-2025-24002
5.3 MEDIUM

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service …

Jul 8, 2025
CVE-2025-7327
8.8 HIGH

The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. …

Jul 8, 2025
CVE-2025-7165
7.3 HIGH

A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 8, 2025
CVE-2025-7164
7.3 HIGH

A vulnerability has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 8, 2025
CVE-2025-7163
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/add-animals.php. The …

Jul 8, 2025
CVE-2025-7162
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue affects some unknown processing of the file …

Jul 8, 2025
CVE-2025-5957
5.3 MEDIUM

The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing …

Jul 8, 2025
CVE-2025-5537
6.4 MEDIUM

The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alternative texts in all versions …

Jul 8, 2025
CVE-2025-7161
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-normal-ticket.php. The manipulation of …

Jul 8, 2025
CVE-2025-7160
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. This affects an unknown part of the file /admin/index.php. The manipulation …

Jul 8, 2025
CVE-2025-7159
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 8, 2025
CVE-2025-7158
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 8, 2025
CVE-2025-7157
7.3 HIGH

A vulnerability was found in code-projects Online Note Sharing 1.0. It has been classified as critical. Affected is an unknown function of the file /login.php. …

Jul 8, 2025
CVE-2025-6244
6.4 MEDIUM

The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And …

Jul 8, 2025
CVE-2025-5570
5.4 MEDIUM

The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, …

Jul 8, 2025
CVE-2025-53617

Rejected reason: Not used

Jul 8, 2025
CVE-2025-53616

Rejected reason: Not used

Jul 8, 2025
CVE-2025-53615

Rejected reason: Not used

Jul 8, 2025
CVE-2025-53614

Rejected reason: Not used

Jul 8, 2025
CVE-2025-53613

Rejected reason: Not used

Jul 8, 2025
CVE-2025-53612

Rejected reason: Not used

Jul 8, 2025
CVE-2025-53611

Rejected reason: Not used

Jul 8, 2025
CVE-2025-53610

Rejected reason: Not used

Jul 8, 2025
CVE-2025-20695
6.5 MEDIUM

In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional …

Jul 8, 2025
CVE-2025-20694
6.5 MEDIUM

In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional …

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.