CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6853
6.3 MEDIUM

A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the …

Jun 29, 2025
CVE-2025-6850
6.3 MEDIUM

A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jun 29, 2025
CVE-2025-6849
3.5 LOW

A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknown function of the file /forum_edit1.php. The manipulation …

Jun 29, 2025
CVE-2025-6848
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. …

Jun 29, 2025
CVE-2025-6847
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Forum 1.0. This vulnerability affects unknown code of the file /forum_edit.php. The manipulation of the …

Jun 29, 2025
CVE-2025-6846
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Forum 1.0. This affects an unknown part of the file /forum_viewfile.php. The manipulation of …

Jun 29, 2025
CVE-2025-6845
7.3 HIGH

A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jun 29, 2025
CVE-2025-6462
6.4 MEDIUM

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all …

Jun 29, 2025
CVE-2025-6844
7.3 HIGH

A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 29, 2025
CVE-2025-6843
7.3 HIGH

A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file /upload-photo.php. …

Jun 29, 2025
CVE-2025-6842
4.7 MEDIUM

A vulnerability was found in code-projects Product Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit_user.php. The …

Jun 29, 2025
CVE-2025-6841
4.7 MEDIUM

A vulnerability has been found in code-projects Product Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit_product.php. The …

Jun 29, 2025
CVE-2025-6840
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Product Inventory System 1.0. This affects an unknown part of the file /index.php of …

Jun 29, 2025
CVE-2025-6839
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue …

Jun 29, 2025
CVE-2025-6837
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of the file /profile.php. The …

Jun 29, 2025
CVE-2025-6836
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Library System 1.0. Affected is an unknown function of the file /profile.php. The manipulation of …

Jun 29, 2025
CVE-2025-6835
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student-issue-book.php. …

Jun 29, 2025
CVE-2025-6834
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/editPayment.php. …

Jun 29, 2025
CVE-2025-6829
6.3 MEDIUM

A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function outAddress of the component External Address …

Jun 28, 2025
CVE-2025-6828
7.3 HIGH

A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /orders.php. The …

Jun 28, 2025
CVE-2025-5951

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 28, 2025
CVE-2025-53393
6.0 MEDIUM

In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.

Jun 28, 2025
CVE-2025-53392
5.0 MEDIUM

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is …

Jun 28, 2025
CVE-2025-6827
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affects an unknown part of the file /php_action/editOrder.php. The …

Jun 28, 2025
CVE-2025-53391
9.3 CRITICAL

The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to …

Jun 28, 2025
CVE-2025-6826
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Payroll Management System 1.0. Affected by this issue is some unknown functionality of …

Jun 28, 2025
CVE-2025-6825
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK A702R up to 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWlSiteSurvey …

Jun 28, 2025
CVE-2025-6824
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK X15 up to 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formParentControl of the …

Jun 28, 2025
CVE-2025-6823
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 28, 2025
CVE-2025-6822
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. …

Jun 28, 2025
CVE-2025-32897
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 …

Jun 28, 2025
CVE-2025-6821
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /php_action/createOrder.php. …

Jun 28, 2025
CVE-2025-6820
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 28, 2025
CVE-2025-6819
7.3 HIGH

A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 28, 2025
CVE-2025-6818
3.3 LOW

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_protect of the file /src/H5Ochunk.c. The manipulation leads to …

Jun 28, 2025
CVE-2023-29113
6.3 MEDIUM

The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with …

Jun 28, 2025
CVE-2023-28912
5.7 MEDIUM

The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access …

Jun 28, 2025
CVE-2023-28911
6.5 MEDIUM

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28910
8.0 HIGH

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled abortion flag eventually leading to bypassing …

Jun 28, 2025
CVE-2023-28909
8.0 HIGH

A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28908
5.4 MEDIUM

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28907
6.7 MEDIUM

There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to …

Jun 28, 2025
CVE-2023-28906
7.8 HIGH

A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the system to escalate privileges and obtain administrative …

Jun 28, 2025
CVE-2023-28905
8.0 HIGH

A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability …

Jun 28, 2025
CVE-2023-28904
5.2 MEDIUM

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to …

Jun 28, 2025
CVE-2023-28903
3.3 LOW

An integer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause a …

Jun 28, 2025
CVE-2023-28902
3.3 LOW

An integer underflow in the image processing binary of the MIB3 infotainment unit allows an attacker with local access to the vehicle to cause denial-of-service …

Jun 28, 2025
CVE-2025-1991
7.5 HIGH

IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processing packets.

Jun 28, 2025
CVE-2025-6817
3.3 LOW

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation …

Jun 28, 2025
CVE-2025-6816
3.3 LOW

A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based …

Jun 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.