CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-47868
9.8 CRITICAL

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This …

Jun 16, 2025
CVE-2025-40916
9.1 CRITICAL

Mojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha. That version uses the built-in rand() function for generating the …

Jun 16, 2025
CVE-2025-6117
7.3 HIGH

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 16, 2025
CVE-2025-6116
7.3 HIGH

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affects an unknown part of the file …

Jun 16, 2025
CVE-2025-25265
4.9 MEDIUM

A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows a high privileged remote attacker to …

Jun 16, 2025
CVE-2025-25264
6.5 MEDIUM

An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the …

Jun 16, 2025
CVE-2025-6172
9.8 CRITICAL

Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation.

Jun 16, 2025
CVE-2025-6115
8.8 HIGH

A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function form_macfilter. The manipulation of the argument …

Jun 16, 2025
CVE-2025-6114
8.8 HIGH

A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is the function form_portforwarding of the file /goform/form_portforwarding. …

Jun 16, 2025
CVE-2025-40729
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter.

Jun 16, 2025
CVE-2025-40728
8.8 HIGH

SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter …

Jun 16, 2025
CVE-2025-40727

A Reflected Cross Site Scripting (XSS) vulnerability was found in '/search' in Phoenix Site CMS from Phoenix, which allows remote attackers to execute arbitrary code …

Jun 16, 2025
CVE-2025-40726

Reflected Cross-Site Scripting (XSS) vulnerability in /pages/search-results-page in Nosto, which allows remote attackers to execute arbitrary code via the q GET request parameter.

Jun 16, 2025
CVE-2025-3464

A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security …

Jun 16, 2025
CVE-2025-2091
5.4 MEDIUM

An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to …

Jun 16, 2025
CVE-2025-6113
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of …

Jun 16, 2025
CVE-2025-6112
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The …

Jun 16, 2025
CVE-2025-4987
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to …

Jun 16, 2025
CVE-2025-6169
9.8 CRITICAL

The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, …

Jun 16, 2025
CVE-2025-6111
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the …

Jun 16, 2025
CVE-2025-6110
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the …

Jun 16, 2025
CVE-2025-6109
4.3 MEDIUM

A vulnerability was found in javahongxi whatsmars 2021.4.0. It has been rated as problematic. Affected by this issue is the function initialize of the file …

Jun 16, 2025
CVE-2025-6108
6.3 MEDIUM

A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has been declared as critical. Affected by this vulnerability is the function watermarkTest of …

Jun 16, 2025
CVE-2025-6107
3.1 LOW

A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the function set_attr of the file /comfy/utils.py. The manipulation …

Jun 16, 2025
CVE-2025-6106
4.3 MEDIUM

A vulnerability was found in WuKongOpenSource WukongCRM 9.0 and classified as problematic. This issue affects some unknown processing of the file AdminRoleController.java. The manipulation leads …

Jun 16, 2025
CVE-2025-6105
4.3 MEDIUM

A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.java. The manipulation of …

Jun 16, 2025
CVE-2025-6104
8.8 HIGH

A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/pms_check.php. …

Jun 16, 2025
CVE-2025-6103
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functionality …

Jun 16, 2025
CVE-2025-6102
8.8 HIGH

A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file …

Jun 16, 2025
CVE-2025-6101
5.5 MEDIUM

A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation …

Jun 16, 2025
CVE-2025-6100
6.3 MEDIUM

A vulnerability was found in realguoshuai open-video-cms 1.0. It has been rated as critical. This issue affects some unknown processing of the file /v1/video/list. The …

Jun 16, 2025
CVE-2025-6099
5.3 MEDIUM

A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerability affects unknown code of the file gin-blog-server/internal/manager.go …

Jun 16, 2025
CVE-2025-6098
9.8 CRITICAL

A vulnerability was found in UTT 进取 750W up to 5.0. It has been classified as critical. This affects the function strcpy of the file …

Jun 16, 2025
CVE-2025-6097
5.3 MEDIUM

A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function formDefineManagement of the …

Jun 16, 2025
CVE-2025-6096
6.3 MEDIUM

A vulnerability has been found in codesiddhant Jasmin Ransomware up to 1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jun 16, 2025
CVE-2025-6095
7.3 HIGH

A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unknown function of the file /checklogin.php. The manipulation …

Jun 15, 2025
CVE-2025-6094
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file …

Jun 15, 2025
CVE-2025-6093
5.5 MEDIUM

A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a275d1007e295. This vulnerability affects the function heartrate1_i2c_hal_write of the file 7.Example/hal/i2c/max30100/Manual/demo2/2/heartrate1_hal.c. The manipulation …

Jun 15, 2025
CVE-2025-5964
6.5 MEDIUM

A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.

Jun 15, 2025
CVE-2025-6092
4.3 MEDIUM

A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jun 15, 2025
CVE-2025-5990
7.6 HIGH

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored …

Jun 15, 2025
CVE-2025-6091
8.8 HIGH

A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation …

Jun 15, 2025
CVE-2024-25573

Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.

Jun 15, 2025
CVE-2025-6090
8.8 HIGH

A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function UpdateWanparamsMulti/UpdateIpv6params of the file /routing/goform/aspForm. The manipulation of …

Jun 15, 2025
CVE-2025-22854

Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.

Jun 15, 2025
CVE-2025-21085

PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.

Jun 15, 2025
CVE-2025-6089
4.3 MEDIUM

A vulnerability has been found in Astun Technology iShare Maps 5.4.0 and classified as problematic. This vulnerability affects unknown code of the file atCheckJS.aspx. The …

Jun 15, 2025
CVE-2025-36041
4.7 MEDIUM

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1 through 3.5.3, and MQ Operator …

Jun 15, 2025
CVE-2025-1411
7.8 HIGH

IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges.

Jun 15, 2025
CVE-2025-5337
6.4 MEDIUM

The Slider, Gallery, and Carousel by MetaSlider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘aria-label’ parameter in all versions up to, …

Jun 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.