CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5937
4.3 MEDIUM

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jun 28, 2025
CVE-2025-38086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nway_restart In mii_nway_restart() the code attempts to call mii->mdio_read …

Jun 28, 2025
CVE-2025-38085
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that …

Jun 28, 2025
CVE-2025-38084
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table …

Jun 28, 2025
CVE-2025-6755
8.8 HIGH

The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDeleteTheme() function in …

Jun 28, 2025
CVE-2025-5304
9.8 CRITICAL

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. …

Jun 28, 2025
CVE-2025-6252
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.9.1 …

Jun 28, 2025
CVE-2025-6381
8.8 HIGH

The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file() function. This makes …

Jun 28, 2025
CVE-2025-6379
8.8 HIGH

The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_live_fn() function. This …

Jun 28, 2025
CVE-2025-6350
6.4 MEDIUM

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ …

Jun 28, 2025
CVE-2025-53388

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53387

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53386

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53385

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53384

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53383

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53382

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53381

Rejected reason: Not used

Jun 28, 2025
CVE-2025-53380

Rejected reason: Not used

Jun 28, 2025
CVE-2025-36027
5.4 MEDIUM

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Jun 28, 2025
CVE-2025-36026
4.3 MEDIUM

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the …

Jun 28, 2025
CVE-2024-52900
6.4 MEDIUM

IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to …

Jun 28, 2025
CVE-2024-39730
5.4 MEDIUM

IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to …

Jun 28, 2025
CVE-2024-36347
6.4 MEDIUM

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in …

Jun 27, 2025
CVE-2025-53098
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within the …

Jun 27, 2025
CVE-2025-53097
5.9 MEDIUM

Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent's `search_files` tool did not …

Jun 27, 2025
CVE-2025-6778
2.4 LOW

A vulnerability, which was classified as problematic, was found in code-projects Food Distributor Site 1.0. Affected is an unknown function of the file /admin/save_settings.php. The …

Jun 27, 2025
CVE-2025-6777
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Food Distributor Site 1.0. This issue affects some unknown processing of the file …

Jun 27, 2025
CVE-2025-6776
7.3 HIGH

A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the …

Jun 27, 2025
CVE-2025-6775
6.3 MEDIUM

A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file /app/api/v1/openvpn.py of the …

Jun 27, 2025
CVE-2025-6774
6.3 MEDIUM

A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is the function AddTemp of …

Jun 27, 2025
CVE-2025-53094

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage …

Jun 27, 2025
CVE-2025-6773
5.3 MEDIUM

A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_input_dir of …

Jun 27, 2025
CVE-2025-6772
7.3 HIGH

A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import. …

Jun 27, 2025
CVE-2025-6522
5.4 MEDIUM

Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on …

Jun 27, 2025
CVE-2025-5310
9.8 CRITICAL

Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, …

Jun 27, 2025
CVE-2025-53093
8.6 HIGH

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert …

Jun 27, 2025
CVE-2025-6521
7.6 HIGH

During the initial setup of the device the user connects to an access point broadcast by the Sight Bulb Pro. During the negotiation, AES Encryption …

Jun 27, 2025
CVE-2025-52207
9.9 CRITICAL

PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.

Jun 27, 2025
CVE-2025-46708
4.3 MEDIUM

Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.

Jun 27, 2025
CVE-2025-46707
5.2 MEDIUM

Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.

Jun 27, 2025
CVE-2025-44559
6.5 MEDIUM

An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a Denial of …

Jun 27, 2025
CVE-2025-44557
8.1 HIGH

A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypass the pairing process and authentication …

Jun 27, 2025
CVE-2024-12364
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Software Guest Tracking Software allows SQL Injection.This issue affects …

Jun 27, 2025
CVE-2024-12150
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Wowwo CRM allows Blind SQL Injection.This issue affects Wowwo …

Jun 27, 2025
CVE-2024-12143
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile Informatics Mikro Hand Terminal - MikroDB allows SQL Injection.This …

Jun 27, 2025
CVE-2025-50370
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows …

Jun 27, 2025
CVE-2025-50369
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an …

Jun 27, 2025
CVE-2025-50367
6.1 MEDIUM

A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly …

Jun 27, 2025
CVE-2024-11739
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics Case ERP allows SQL Injection.This issue affects Case ERP: …

Jun 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.