CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40662
7.5 HIGH

Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigating to a non-existent file.

Jun 10, 2025
CVE-2025-40661
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting …

Jun 10, 2025
CVE-2025-40660
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting …

Jun 10, 2025
CVE-2025-40659
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting …

Jun 10, 2025
CVE-2025-40658
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting …

Jun 10, 2025
CVE-2025-40657
9.8 CRITICAL

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the …

Jun 10, 2025
CVE-2025-40656
9.8 CRITICAL

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the …

Jun 10, 2025
CVE-2025-40655
9.8 CRITICAL

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the …

Jun 10, 2025
CVE-2025-40654
9.8 CRITICAL

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the …

Jun 10, 2025
CVE-2025-5743
5.5 MEDIUM

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote control over the charging station …

Jun 10, 2025
CVE-2025-5742
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated user modifies configuration parameters on the web server

Jun 10, 2025
CVE-2025-5741
4.9 MEDIUM

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file reads from the charging station. The …

Jun 10, 2025
CVE-2025-5740
7.2 HIGH

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file writes when an authenticated user on …

Jun 10, 2025
CVE-2025-4681

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affects upKeeper Instant Privilege Access: before 1.4.0.

Jun 10, 2025
CVE-2025-4680

Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects upKeeper Instant Privilege Access: …

Jun 10, 2025
CVE-2025-3905
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting PLC system variables that could cause an unvalidated data injected by …

Jun 10, 2025
CVE-2025-3899
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Certificates page on Webserver that could cause an unvalidated data injected …

Jun 10, 2025
CVE-2025-3898
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request containing invalid data type to …

Jun 10, 2025
CVE-2025-3117
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting configuration file paths that could cause an unvalidated data injected by …

Jun 10, 2025
CVE-2025-3116
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted …

Jun 10, 2025
CVE-2025-3112
6.5 MEDIUM

CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated malicious user sends manipulated HTTPS Content-Length header to the webserver.

Jun 10, 2025
CVE-2025-5945

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 10, 2025
CVE-2025-27819
7.5 HIGH

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is …

Jun 10, 2025
CVE-2025-27818
8.8 HIGH

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and …

Jun 10, 2025
CVE-2025-27817
7.5 HIGH

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER …

Jun 10, 2025
CVE-2025-4954
8.8 HIGH

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload …

Jun 10, 2025
CVE-2025-4840
7.5 HIGH

The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action …

Jun 10, 2025
CVE-2025-1041
9.9 CRITICAL

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include …

Jun 10, 2025
CVE-2025-5952
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the function exec of the file …

Jun 10, 2025
CVE-2025-5935
5.3 MEDIUM

A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the …

Jun 10, 2025
CVE-2025-3076
6.4 MEDIUM

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions up to, and including, …

Jun 10, 2025
CVE-2025-5934
8.8 HIGH

A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function sub_41619C of the file /mtd. …

Jun 10, 2025
CVE-2025-5925
4.3 MEDIUM

The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.95. This is due to …

Jun 10, 2025
CVE-2025-5913
7.3 HIGH

A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 10, 2025
CVE-2025-5912
8.8 HIGH

A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the function do_file of the component HTTP POST …

Jun 10, 2025
CVE-2025-4601
8.8 HIGH

The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is …

Jun 10, 2025
CVE-2025-4387
8.8 HIGH

The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add_to_cart_popup_upload_files function in …

Jun 10, 2025
CVE-2025-5911
8.8 HIGH

A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 10, 2025
CVE-2025-5910
8.8 HIGH

A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 10, 2025
CVE-2024-55595

Rejected reason: Not used

Jun 10, 2025
CVE-2025-5909
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formReflashClientTbl of …

Jun 10, 2025
CVE-2025-5908
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file …

Jun 10, 2025
CVE-2025-5907
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formFilter of the component …

Jun 10, 2025
CVE-2025-5906
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manipulation leads …

Jun 10, 2025
CVE-2025-42998
5.3 MEDIUM

The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted …

Jun 10, 2025
CVE-2025-42996
5.6 MEDIUM

SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to …

Jun 10, 2025
CVE-2025-42995
7.5 HIGH

SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process …

Jun 10, 2025
CVE-2025-42994
7.5 HIGH

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process …

Jun 10, 2025
CVE-2025-42993
6.7 MEDIUM

Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an …

Jun 10, 2025
CVE-2025-42991
4.3 MEDIUM

SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'approver' user to delete attachment from bank account application of …

Jun 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.