CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-42990
3.0 LOW

Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the …

Jun 10, 2025
CVE-2025-42989
9.6 CRITICAL

RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact …

Jun 10, 2025
CVE-2025-42988
3.7 LOW

Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP …

Jun 10, 2025
CVE-2025-42987
4.3 MEDIUM

SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. …

Jun 10, 2025
CVE-2025-42984
5.4 MEDIUM

SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function …

Jun 10, 2025
CVE-2025-42983
8.5 HIGH

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or …

Jun 10, 2025
CVE-2025-42982
8.8 HIGH

SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes …

Jun 10, 2025
CVE-2025-42977
7.6 HIGH

SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker …

Jun 10, 2025
CVE-2025-31325
5.8 MEDIUM

Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an …

Jun 10, 2025
CVE-2025-23192
8.2 HIGH

SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, …

Jun 10, 2025
CVE-2025-5905
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file …

Jun 10, 2025
CVE-2025-5904
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file …

Jun 10, 2025
CVE-2025-5903
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the …

Jun 10, 2025
CVE-2025-0037
6.6 MEDIUM

In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated …

Jun 10, 2025
CVE-2025-0036
3.2 LOW

In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to …

Jun 10, 2025
CVE-2025-5902
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component …

Jun 9, 2025
CVE-2025-5901
8.8 HIGH

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the …

Jun 9, 2025
CVE-2025-30515
9.8 CRITICAL

CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.

Jun 9, 2025
CVE-2025-30507
5.3 MEDIUM

CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.

Jun 9, 2025
CVE-2025-30183
7.5 HIGH

CyberData 011209 Intercom does not properly store or protect web server admin credentials.

Jun 9, 2025
CVE-2025-26468
7.5 HIGH

CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.

Jun 9, 2025
CVE-2025-5900
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. …

Jun 9, 2025
CVE-2025-5899
5.3 MEDIUM

A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation …

Jun 9, 2025
CVE-2025-5898
5.3 MEDIUM

A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to …

Jun 9, 2025
CVE-2025-49140
7.5 HIGH

Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a bug in a RTP packet factory that can be …

Jun 9, 2025
CVE-2025-30184
9.8 CRITICAL

CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.

Jun 9, 2025
CVE-2025-5897
4.3 MEDIUM

A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file …

Jun 9, 2025
CVE-2025-5896
4.3 MEDIUM

A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. …

Jun 9, 2025
CVE-2025-49141
8.5 HIGH

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string …

Jun 9, 2025
CVE-2025-49139
5.3 MEDIUM

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can …

Jun 9, 2025
CVE-2025-49138
6.5 MEDIUM

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability …

Jun 9, 2025
CVE-2025-49137
8.5 HIGH

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user …

Jun 9, 2025
CVE-2025-49004
7.5 HIGH

Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caido can be loaded on …

Jun 9, 2025
CVE-2025-5918
3.9 LOW

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading …

Jun 9, 2025
CVE-2025-5917
2.8 LOW

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can …

Jun 9, 2025
CVE-2025-5916
3.9 LOW

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) …

Jun 9, 2025
CVE-2025-5915
6.6 MEDIUM

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter …

Jun 9, 2025
CVE-2025-5914
7.8 HIGH

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to …

Jun 9, 2025
CVE-2025-5895
4.3 MEDIUM

A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads …

Jun 9, 2025
CVE-2025-5892
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. …

Jun 9, 2025
CVE-2025-5891
4.3 MEDIUM

A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code of the file /lib/tools/Config.js. The manipulation leads …

Jun 9, 2025
CVE-2025-5890
4.3 MEDIUM

A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. …

Jun 9, 2025
CVE-2025-5889
3.1 LOW

A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of …

Jun 9, 2025
CVE-2025-5888
4.3 MEDIUM

A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads …

Jun 9, 2025
CVE-2025-49653
8.0 HIGH

Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.

Jun 9, 2025
CVE-2025-49652
9.8 CRITICAL

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is …

Jun 9, 2025
CVE-2025-49651
8.1 HIGH

Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists …

Jun 9, 2025
CVE-2024-47081
5.3 MEDIUM

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific …

Jun 9, 2025
CVE-2025-5887
3.5 LOW

A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been classified as problematic. Affected is an unknown function of the file UserMgrController.java of the …

Jun 9, 2025
CVE-2025-49136
9.0 CRITICAL

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions …

Jun 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.