CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5928
4.3 MEDIUM

The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due …

Jun 13, 2025
CVE-2025-5926
6.1 MEDIUM

The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.4. This is due to missing …

Jun 13, 2025
CVE-2025-5841
6.4 MEDIUM

The ACF Onyx Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.9 …

Jun 13, 2025
CVE-2025-5491
8.8 HIGH

Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this …

Jun 13, 2025
CVE-2025-5288
9.8 CRITICAL

The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to …

Jun 13, 2025
CVE-2025-5233
6.4 MEDIUM

The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versions up to, and including, 4.3.2 due …

Jun 13, 2025
CVE-2025-5123
6.4 MEDIUM

The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, …

Jun 13, 2025
CVE-2025-4586
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-4585
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-4584
6.4 MEDIUM

The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' shortcode in all versions up to, and including, 1.2.19 …

Jun 13, 2025
CVE-2025-47959
7.1 HIGH

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.

Jun 13, 2025
CVE-2025-30399
7.5 HIGH

Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

Jun 13, 2025
CVE-2025-4232
8.8 HIGH

An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to …

Jun 13, 2025
CVE-2025-4231
7.2 HIGH

A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have …

Jun 13, 2025
CVE-2025-4230

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root …

Jun 13, 2025
CVE-2025-4228

An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the …

Jun 13, 2025
CVE-2025-4233

An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies.

Jun 12, 2025
CVE-2025-41234
6.5 MEDIUM

Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when …

Jun 12, 2025
CVE-2025-41233
6.8 MEDIUM

Description: VMware AVI Load Balancer contains an authenticated blind SQL Injection vulnerability. VMware has evaluated the severity of the issue to be in the Moderate …

Jun 12, 2025
CVE-2025-49589

PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of PCSX2 versions up to 2.3.414. …

Jun 12, 2025
CVE-2025-44091
5.4 MEDIUM

yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function.

Jun 12, 2025
CVE-2025-27689
7.8 HIGH

Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, …

Jun 12, 2025
CVE-2025-6031
7.5 HIGH

Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. …

Jun 12, 2025
CVE-2025-5485
8.6 HIGH

User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. …

Jun 12, 2025
CVE-2025-5484
8.3 HIGH

A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on …

Jun 12, 2025
CVE-2025-4418
4.4 MEDIUM

An improper validation of integrity check value vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow a …

Jun 12, 2025
CVE-2025-4417
5.5 MEDIUM

A cross-site scripting vulnerability exists in AVEVA PI Connector for CygNet Versions 1.6.14 and prior that, if exploited, could allow an administrator miscreant with local …

Jun 12, 2025
CVE-2025-48699

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Jun 12, 2025
CVE-2025-44019
7.1 HIGH

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI …

Jun 12, 2025
CVE-2025-36539
6.5 MEDIUM

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI …

Jun 12, 2025
CVE-2025-2745
6.5 MEDIUM

A cross-site scripting vulnerability exists in AVEVA PI Web API version 2023 SP1 and prior that, if exploited, could allow an authenticated attacker (with privileges …

Jun 12, 2025
CVE-2025-49579
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted …

Jun 12, 2025
CVE-2025-49578
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing …

Jun 12, 2025
CVE-2025-49577
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can …

Jun 12, 2025
CVE-2025-49576
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing …

Jun 12, 2025
CVE-2025-49575
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing …

Jun 12, 2025
CVE-2025-49081
4.9 MEDIUM

There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions …

Jun 12, 2025
CVE-2025-43866
7.5 HIGH

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The …

Jun 12, 2025
CVE-2025-43863
9.8 CRITICAL

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access …

Jun 12, 2025
CVE-2025-5982
3.7 LOW

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions …

Jun 12, 2025
CVE-2025-49080
7.5 HIGH

There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a …

Jun 12, 2025
CVE-2024-55567
7.5 HIGH

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The …

Jun 12, 2025
CVE-2023-45256
5.4 MEDIUM

Multiple SQL injection vulnerabilities in the EuroInformation MoneticoPaiement module before 1.1.1 for PrestaShop allow remote attackers to execute arbitrary SQL commands via the TPE, societe, …

Jun 12, 2025
CVE-2025-49467

A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible …

Jun 12, 2025
CVE-2025-46035
7.5 HIGH

Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in …

Jun 12, 2025
CVE-2025-36573
7.1 HIGH

Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially …

Jun 12, 2025
CVE-2025-29744
5.4 MEDIUM

pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.

Jun 12, 2025
CVE-2024-7562

A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield 2023 …

Jun 12, 2025
CVE-2024-44906
6.5 MEDIUM

uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is …

Jun 12, 2025
CVE-2024-44905
6.5 MEDIUM

go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.

Jun 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.