CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-47821
2.2 LOW

Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.

Jun 27, 2025
CVE-2025-6749
6.3 MEDIUM

A vulnerability classified as critical was found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this vulnerability is the function searchAdminMessageShow of the file AdminController.java. …

Jun 27, 2025
CVE-2025-6748
2.1 LOW

A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. …

Jun 27, 2025
CVE-2025-47820
2.0 LOW

Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.

Jun 27, 2025
CVE-2025-47819
6.4 MEDIUM

Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.

Jun 27, 2025
CVE-2025-47818
2.2 LOW

Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.

Jun 27, 2025
CVE-2025-6738
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this issue is the function userDao.selectUserByUserNameLike of …

Jun 27, 2025
CVE-2025-6736
6.3 MEDIUM

A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/install of the …

Jun 27, 2025
CVE-2025-6735
6.3 MEDIUM

A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Import …

Jun 27, 2025
CVE-2025-6734
8.8 HIGH

A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. This issue affects the function sub_484E40 of the …

Jun 26, 2025
CVE-2025-6733
8.8 HIGH

A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been declared as critical. This vulnerability affects the function sub_416928 of the …

Jun 26, 2025
CVE-2025-3699
9.8 CRITICAL

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, …

Jun 26, 2025
CVE-2025-6732
8.8 HIGH

A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been classified as critical. This affects the function strcpy of the file …

Jun 26, 2025
CVE-2025-6731
6.3 MEDIUM

A vulnerability was found in yzcheng90 X-SpringBoot up to 5.0 and classified as critical. Affected by this issue is the function uploadApk of the file …

Jun 26, 2025
CVE-2025-5731
5.5 MEDIUM

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command …

Jun 26, 2025
CVE-2015-0849
3.9 LOW

pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability.

Jun 26, 2025
CVE-2015-0843
9.8 CRITICAL

yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.

Jun 26, 2025
CVE-2015-0842
9.8 CRITICAL

yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.

Jun 26, 2025
CVE-2025-52555
6.5 MEDIUM

Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate …

Jun 26, 2025
CVE-2014-7210
9.8 CRITICAL

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql …

Jun 26, 2025
CVE-2014-6274
7.5 HIGH

git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the embedded AWS …

Jun 26, 2025
CVE-2014-0468
9.8 CRITICAL

Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have uploaded in their raw SCM …

Jun 26, 2025
CVE-2013-1440

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 26, 2025
CVE-2025-5995

Canon EOS Webcam Utility Pro for MAC OS version 2.3d (2.3.29) and earlier contains an improper directory permissions vulnerability. Exploitation of this vulnerability requires administrator …

Jun 26, 2025
CVE-2025-53122

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection. Users should upgrade …

Jun 26, 2025
CVE-2025-49592
4.6 MEDIUM

n8n is a workflow automation platform. Versions prior to 1.98.0 have an Open Redirect vulnerability in the login flow. Authenticated users can be redirected to …

Jun 26, 2025
CVE-2013-1424
5.6 MEDIUM

Buffer overflow vulnerability in matplotlib.This issue affects matplotlib: before upstream commit ba4016014cb4fb4927e36ce8ea429fed47dcb787.

Jun 26, 2025
CVE-2025-53121

Multiple stored XSS were found on different nodes with unsanitized parameters in OpenMNS Horizon 33.0.8 and versions earlier than 33.1.6 on multiple platforms that allow …

Jun 26, 2025
CVE-2025-52904
8.0 HIGH

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In …

Jun 26, 2025
CVE-2025-52903
8.0 HIGH

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In …

Jun 26, 2025
CVE-2025-53013
5.2 MEDIUM

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a user to authenticate …

Jun 26, 2025
CVE-2025-49603
9.1 CRITICAL

Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.

Jun 26, 2025
CVE-2025-52477
8.6 HIGH

Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated …

Jun 26, 2025
CVE-2025-30131
9.8 CRITICAL

An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploading a CGI-based …

Jun 26, 2025
CVE-2024-52928
9.6 CRITICAL

Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when …

Jun 26, 2025
CVE-2025-6702
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment/post. The manipulation of …

Jun 26, 2025
CVE-2025-6701
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some unknown processing of the file /xxl-sso-server/doLogin. The …

Jun 26, 2025
CVE-2025-6700
4.3 MEDIUM

A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/login. The manipulation of the argument …

Jun 26, 2025
CVE-2025-6699
3.5 LOW

A vulnerability classified as problematic has been found in LabRedesCefetRJ WeGIA 3.4.0. This affects an unknown part of the file /html/funcionario/cadastro_funcionario.php of the component Cadastro …

Jun 26, 2025
CVE-2025-51671
5.4 MEDIUM

A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code …

Jun 26, 2025
CVE-2025-50350
5.4 MEDIUM

PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php.

Jun 26, 2025
CVE-2025-44141
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.

Jun 26, 2025
CVE-2025-36034
5.3 MEDIUM

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted …

Jun 26, 2025
CVE-2025-34049

An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 1127.190306 and earlier. The router’s web management interface fails …

Jun 26, 2025
CVE-2025-34048

A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. …

Jun 26, 2025
CVE-2025-34047

A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attackers to read arbitrary files on the underlying system via …

Jun 26, 2025
CVE-2025-34046

An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded …

Jun 26, 2025
CVE-2025-34045
7.5 HIGH

A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Technology Co., Ltd. The flaw …

Jun 26, 2025
CVE-2025-34044

A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the …

Jun 26, 2025
CVE-2025-34043

A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability …

Jun 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.