CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-47029
9.8 CRITICAL

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to …

Jun 23, 2025
CVE-2025-6516
5.3 MEDIUM

A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5F_addr_decode_len of the file /hdf5/src/H5Fint.c. The …

Jun 23, 2025
CVE-2025-6511
8.8 HIGH

A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_410090. The manipulation leads to stack-based buffer overflow. It …

Jun 23, 2025
CVE-2025-52969

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 23, 2025
CVE-2023-47031
9.8 CRITICAL

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization …

Jun 23, 2025
CVE-2025-6510
8.8 HIGH

A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is the function sub_415EF8. The manipulation leads …

Jun 23, 2025
CVE-2025-6509
3.5 LOW

A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been declared as problematic. Affected by this vulnerability is the function echo of …

Jun 23, 2025
CVE-2025-4563
2.7 LOW

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the …

Jun 23, 2025
CVE-2023-50450
8.4 HIGH

An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges.

Jun 23, 2025
CVE-2023-47295
9.8 CRITICAL

A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that …

Jun 23, 2025
CVE-2023-47294
8.1 HIGH

An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.

Jun 23, 2025
CVE-2023-47032
9.8 CRITICAL

Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function.

Jun 23, 2025
CVE-2025-52968
2.7 LOW

xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, associate …

Jun 23, 2025
CVE-2025-52967
5.8 MEDIUM

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

Jun 23, 2025
CVE-2025-52879
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible

Jun 23, 2025
CVE-2025-52878
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions

Jun 23, 2025
CVE-2025-52877
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

Jun 23, 2025
CVE-2025-52876
5.4 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

Jun 23, 2025
CVE-2025-52875
5.4 MEDIUM

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

Jun 23, 2025
CVE-2025-48700
6.1 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI …

Jun 23, 2025
CVE-2025-46101
9.8 CRITICAL

SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain …

Jun 23, 2025
CVE-2023-48978
9.8 CRITICAL

An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP …

Jun 23, 2025
CVE-2023-47298
4.3 MEDIUM

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of …

Jun 23, 2025
CVE-2023-47297
9.8 CRITICAL

A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.

Jun 23, 2025
CVE-2025-52542

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 23, 2025
CVE-2025-2172

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command …

Jun 23, 2025
CVE-2025-2171

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the …

Jun 23, 2025
CVE-2025-6513
9.3 CRITICAL

Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.

Jun 23, 2025
CVE-2025-6512
10.0 CRITICAL

On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server …

Jun 23, 2025
CVE-2025-52922
7.4 HIGH

Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully …

Jun 23, 2025
CVE-2025-52921
9.9 CRITICAL

In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by …

Jun 23, 2025
CVE-2025-52920
6.4 MEDIUM

Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit …

Jun 23, 2025
CVE-2025-23049

Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.

Jun 23, 2025
CVE-2025-52939

Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C. This issue affects NotepadNext: through v0.11.

Jun 23, 2025
CVE-2025-52938

Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files lparser.C. This issue affects NotepadNext: through v0.11. The singlevar() in …

Jun 23, 2025
CVE-2025-52937

Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C. This vulnerability is only relevant if the PCL version is older …

Jun 23, 2025
CVE-2025-52936

Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.

Jun 23, 2025
CVE-2025-52935

Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly (src/redis/lua/struct modules). This vulnerability is associated with program files lua_struct.C. This issue affects dragonfly: 1.30.1, 1.30.0, 1.28.18.

Jun 23, 2025
CVE-2025-27387
7.4 HIGH

OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.

Jun 23, 2025
CVE-2024-45347
9.6 CRITICAL

An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be …

Jun 23, 2025
CVE-2024-3511
4.3 MEDIUM

An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, …

Jun 23, 2025
CVE-2025-6503
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/fetchSelectedCategories.php. The …

Jun 23, 2025
CVE-2025-6502
7.3 HIGH

A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php_action/changePassword.php. The …

Jun 23, 2025
CVE-2025-6501
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affects an unknown part of the file /php_action/createCategories.php. The …

Jun 23, 2025
CVE-2025-6500
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown functionality of …

Jun 23, 2025
CVE-2025-6499
3.3 LOW

A vulnerability classified as problematic was found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_parse_multiline_string of the file src/ucl_parser.c. …

Jun 23, 2025
CVE-2025-6498
3.3 LOW

A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to …

Jun 23, 2025
CVE-2025-6497
3.3 LOW

A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The …

Jun 23, 2025
CVE-2025-52926
2.7 LOW

In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the interactive user interface.

Jun 23, 2025
CVE-2025-6496
3.3 LOW

A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the function InsertNodeAsParent of the file src/parser.c. The …

Jun 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.