CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-35009
7.1 HIGH

Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MNNETSP command that can lead to privilege …

Jun 8, 2025
CVE-2025-35008
7.1 HIGH

Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MMNAME command that can lead to privilege …

Jun 8, 2025
CVE-2025-35007
7.1 HIGH

Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFRULE command that can lead to privilege …

Jun 8, 2025
CVE-2025-35006
7.1 HIGH

Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFPORTFWD command that can lead to privilege …

Jun 8, 2025
CVE-2025-35005
7.1 HIGH

Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFMAC command that can lead to privilege …

Jun 8, 2025
CVE-2025-35004
7.1 HIGH

Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFIP command that can lead to privilege …

Jun 8, 2025
CVE-2025-32459
7.7 HIGH

The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance …

Jun 8, 2025
CVE-2025-32458
7.7 HIGH

The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), that is vulnerable to command injection. This is an instance …

Jun 8, 2025
CVE-2025-32457
7.7 HIGH

The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), that is vulnerable to command injection. This is an instance …

Jun 8, 2025
CVE-2025-32456
7.7 HIGH

The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance …

Jun 8, 2025
CVE-2025-32455
7.7 HIGH

The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance …

Jun 8, 2025
CVE-2025-5847
8.8 HIGH

A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg …

Jun 8, 2025
CVE-2025-27563
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

Jun 8, 2025
CVE-2025-27247
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

Jun 8, 2025
CVE-2025-27242
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

Jun 8, 2025
CVE-2025-27131
6.1 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

Jun 8, 2025
CVE-2025-26693
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

Jun 8, 2025
CVE-2025-26691
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

Jun 8, 2025
CVE-2025-25217
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

Jun 8, 2025
CVE-2025-24493
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.

Jun 8, 2025
CVE-2025-23235
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Jun 8, 2025
CVE-2025-21082
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

Jun 8, 2025
CVE-2025-20063
3.3 LOW

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause apps crash through type confusion.

Jun 8, 2025
CVE-2025-38004
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: can: bcm: add locking for bcm_op runtime updates The CAN broadcast manager (CAN BCM) can …

Jun 8, 2025
CVE-2025-38003
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is …

Jun 8, 2025
CVE-2025-5242

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2025
CVE-2025-5223

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2025
CVE-2025-5097

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2025
CVE-2025-5026

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 7, 2025
CVE-2024-55585

In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated …

Jun 7, 2025
CVE-2025-5840
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. …

Jun 7, 2025
CVE-2025-5839
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file …

Jun 7, 2025
CVE-2025-5838
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file …

Jun 7, 2025
CVE-2025-5837
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The …

Jun 7, 2025
CVE-2025-5836
6.3 MEDIUM

A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of …

Jun 7, 2025
CVE-2025-49619
8.5 HIGH

Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization …

Jun 7, 2025
CVE-2025-5568
6.4 MEDIUM

The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient …

Jun 7, 2025
CVE-2025-5528
6.1 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up …

Jun 7, 2025
CVE-2024-9994
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2025
CVE-2024-9993
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2025
CVE-2025-5303
7.2 HIGH

The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress …

Jun 7, 2025
CVE-2025-5399
7.5 HIGH

Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless …

Jun 7, 2025
CVE-2025-5814
5.3 MEDIUM

The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 7, 2025
CVE-2025-47601
8.8 HIGH

Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <= 2.1.0.

Jun 7, 2025
CVE-2025-49128
4.0 MEDIUM

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a …

Jun 6, 2025
CVE-2025-49127

Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute …

Jun 6, 2025
CVE-2025-5799
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.09. It has been declared as critical. Affected by this vulnerability is the function fromSetWirelessRepeat of the file …

Jun 6, 2025
CVE-2025-5798
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.09. It has been classified as critical. Affected is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation …

Jun 6, 2025
CVE-2025-5797
3.5 LOW

A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unknown processing of the file /data/insert_type.php. The manipulation …

Jun 6, 2025
CVE-2025-5796
3.5 LOW

A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /data/edit_type.php. The manipulation …

Jun 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.