CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5209
4.8 MEDIUM

The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jun 17, 2025
CVE-2025-6163
8.8 HIGH

A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMultiAP of …

Jun 17, 2025
CVE-2025-6162
8.8 HIGH

A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP …

Jun 17, 2025
CVE-2025-6161
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of the file /editproduct.php. …

Jun 17, 2025
CVE-2025-6160
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the …

Jun 17, 2025
CVE-2025-6159
7.3 HIGH

A vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the file /allocate_room.php. The manipulation of …

Jun 17, 2025
CVE-2025-6158
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the component HTTP POST Request Handler. The …

Jun 17, 2025
CVE-2025-3494

Rejected reason: This CVE ID has been rejected by its CNA as it was not a security issue.

Jun 17, 2025
CVE-2025-3493

Rejected reason: This CVE ID has been rejected by its CNA as it was not a security issue.

Jun 17, 2025
CVE-2025-6157
7.3 HIGH

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown …

Jun 17, 2025
CVE-2025-6156
6.3 MEDIUM

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Jun 17, 2025
CVE-2025-6155
7.3 HIGH

A vulnerability was found in PHPGurukul Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /includes/login-hm.inc.php. …

Jun 17, 2025
CVE-2025-6154
7.3 HIGH

A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The …

Jun 17, 2025
CVE-2025-6153
7.3 HIGH

A vulnerability has been found in PHPGurukul Hostel Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/students.php. The …

Jun 17, 2025
CVE-2025-52445

Rejected reason: Not used

Jun 17, 2025
CVE-2025-52444

Rejected reason: Not used

Jun 17, 2025
CVE-2025-52443

Rejected reason: Not used

Jun 17, 2025
CVE-2025-52442

Rejected reason: Not used

Jun 17, 2025
CVE-2025-52441

Rejected reason: Not used

Jun 17, 2025
CVE-2025-52440

Rejected reason: Not used

Jun 17, 2025
CVE-2025-52439

Rejected reason: Not used

Jun 17, 2025
CVE-2025-52438

Rejected reason: Not used

Jun 17, 2025
CVE-2025-52437

Rejected reason: Not used

Jun 17, 2025
CVE-2025-49823
0.0 NONE

(conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to version 3.11.3, shell installer scripts process the …

Jun 17, 2025
CVE-2024-45380

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.

Jun 17, 2025
CVE-2024-45069

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.

Jun 17, 2025
CVE-2024-45065

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.

Jun 17, 2025
CVE-2024-43422

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.

Jun 17, 2025
CVE-2024-21856

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.

Jun 17, 2025
CVE-2025-6152
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The …

Jun 17, 2025
CVE-2025-5673
6.5 MEDIUM

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSortPostType’ parameter in all versions up to, …

Jun 17, 2025
CVE-2025-4775
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions …

Jun 17, 2025
CVE-2025-3774
7.2 HIGH

The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due …

Jun 17, 2025
CVE-2025-6151

A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality of the file /userRpm/WanSlaacCfgRpm.htm, which …

Jun 17, 2025
CVE-2025-6150
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the …

Jun 17, 2025
CVE-2025-6149
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK A3002R 4.0.0-B20230531.1404. Affected is an unknown function of the file /boafrm/formSysLog of the component HTTP …

Jun 17, 2025
CVE-2025-6148
8.8 HIGH

A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formSysLog of …

Jun 17, 2025
CVE-2025-6147
8.8 HIGH

A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formSysLog of the …

Jun 17, 2025
CVE-2025-48993
6.1 MEDIUM

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the …

Jun 17, 2025
CVE-2025-6146
8.8 HIGH

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. This affects an unknown part of the file /boafrm/formSysLog of the …

Jun 17, 2025
CVE-2025-6145
8.8 HIGH

A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formSysLog of …

Jun 16, 2025
CVE-2025-6144
8.8 HIGH

A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formSysCmd …

Jun 16, 2025
CVE-2025-6143
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formNtp of the component …

Jun 16, 2025
CVE-2025-48992
4.8 MEDIUM

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a stored and blind cross-site scripting (XSS) vulnerability exists …

Jun 16, 2025
CVE-2025-6142
6.3 MEDIUM

A vulnerability was found in Intera InHire up to 20250530. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The …

Jun 16, 2025
CVE-2025-6141
3.3 LOW

A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. …

Jun 16, 2025
CVE-2025-6140
3.3 LOW

A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped_padder in the library include/spdlog/pattern_formatter-inl.h. The manipulation …

Jun 16, 2025
CVE-2025-43200
4.2 MEDIUM KEV

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and …

Jun 16, 2025
CVE-2025-27587
5.3 MEDIUM

OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using …

Jun 16, 2025
CVE-2025-6139
3.9 LOW

A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file …

Jun 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.