CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6434
4.3 MEDIUM

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick …

Jun 24, 2025
CVE-2025-6433
9.8 CRITICAL

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that …

Jun 24, 2025
CVE-2025-6432
8.6 HIGH

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not …

Jun 24, 2025
CVE-2025-6431
6.5 MEDIUM

When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could …

Jun 24, 2025
CVE-2025-6430
6.1 MEDIUM

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` …

Jun 24, 2025
CVE-2025-6429
6.5 MEDIUM

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could …

Jun 24, 2025
CVE-2025-6428
4.3 MEDIUM

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to …

Jun 24, 2025
CVE-2025-6427
9.1 CRITICAL

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from …

Jun 24, 2025
CVE-2025-6426
8.8 HIGH

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of …

Jun 24, 2025
CVE-2025-6425
4.3 MEDIUM

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private …

Jun 24, 2025
CVE-2025-6424
9.8 CRITICAL

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, …

Jun 24, 2025
CVE-2025-39205
6.5 MEDIUM

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to …

Jun 24, 2025
CVE-2025-39204
6.5 MEDIUM

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning …

Jun 24, 2025
CVE-2025-39203
6.5 MEDIUM

A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can …

Jun 24, 2025
CVE-2025-39202
7.3 HIGH

A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite …

Jun 24, 2025
CVE-2025-39201
6.1 MEDIUM

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of …

Jun 24, 2025
CVE-2025-2403
7.5 HIGH

A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO series device that if exploited could …

Jun 24, 2025
CVE-2025-1718
6.5 MEDIUM

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk …

Jun 24, 2025
CVE-2025-6206
7.5 HIGH

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file …

Jun 24, 2025
CVE-2025-3092
7.5 HIGH

An unauthenticated remote attacker can enumerate valid user names from an unprotected endpoint.

Jun 24, 2025
CVE-2025-3091
7.5 HIGH

An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s …

Jun 24, 2025
CVE-2025-5258
6.4 MEDIUM

The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due …

Jun 24, 2025
CVE-2025-50213
9.8 CRITICAL

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: …

Jun 24, 2025
CVE-2025-3090
8.2 HIGH

An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.

Jun 24, 2025
CVE-2025-2962
7.5 HIGH

A denial-of-service issue in the dns implemenation could cause an infinite loop.

Jun 24, 2025
CVE-2025-48890
9.8 CRITICAL

WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a …

Jun 24, 2025
CVE-2025-43879
9.8 CRITICAL

WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the telnet function. If a …

Jun 24, 2025
CVE-2025-43877
5.4 MEDIUM

WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be executed on the web browser of the user who …

Jun 24, 2025
CVE-2025-41427
8.8 HIGH

WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If …

Jun 24, 2025
CVE-2025-36519
4.3 MEDIUM

Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially …

Jun 24, 2025
CVE-2025-52570

Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary amount of simultaneously incoming connections …

Jun 24, 2025
CVE-2025-52568

NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory corruption, …

Jun 24, 2025
CVE-2025-52566
8.6 HIGH

llama.cpp is an inference of several LLM models in C/C++. Prior to version b5721, there is a signed vs. unsigned integer overflow in llama.cpp's tokenizer …

Jun 24, 2025
CVE-2025-47943
6.3 MEDIUM

Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, …

Jun 24, 2025
CVE-2024-56731
10.0 CRITICAL

Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote …

Jun 24, 2025
CVE-2025-6560
9.8 CRITICAL

Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and …

Jun 24, 2025
CVE-2025-6559
9.8 CRITICAL

Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on …

Jun 24, 2025
CVE-2025-6552
4.3 MEDIUM

A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the …

Jun 24, 2025
CVE-2025-52979

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52978

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52977

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52976

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52975

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52974

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52973

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52972

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52971

Rejected reason: Not used

Jun 24, 2025
CVE-2025-52574
7.5 HIGH

SysmonElixir is a system monitor HTTP service in Elixir. Prior to version 1.0.1, the /read endpoint reads any file from the server's /etc/passwd by default. …

Jun 24, 2025
CVE-2025-52560
8.1 HIGH

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be sent with URLs …

Jun 24, 2025
CVE-2025-48470
4.1 MEDIUM

Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, …

Jun 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.