CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23099
9.1 CRITICAL

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

Jun 2, 2025
CVE-2025-1051
8.8 HIGH

Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. …

Jun 2, 2025
CVE-2025-5086
9.0 CRITICAL KEV

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

Jun 2, 2025
CVE-2025-45387
5.4 MEDIUM

osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

Jun 2, 2025
CVE-2025-27956
7.5 HIGH

Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.

Jun 2, 2025
CVE-2025-27955
6.5 MEDIUM

Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive …

Jun 2, 2025
CVE-2025-27954
6.5 MEDIUM

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.

Jun 2, 2025
CVE-2025-27953
6.5 MEDIUM

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.

Jun 2, 2025
CVE-2025-23104
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privilege escalation.

Jun 2, 2025
CVE-2025-20298
8.0 HIGH

In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result …

Jun 2, 2025
CVE-2025-20297
4.3 MEDIUM

In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not …

Jun 2, 2025
CVE-2025-5036
7.8 HIGH

A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to …

Jun 2, 2025
CVE-2025-48995

SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret …

Jun 2, 2025
CVE-2025-48994

SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret …

Jun 2, 2025
CVE-2024-8008
5.2 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store …

Jun 2, 2025
CVE-2024-7074
6.8 MEDIUM

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with …

Jun 2, 2025
CVE-2024-7073
6.5 MEDIUM

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers …

Jun 2, 2025
CVE-2024-3509
4.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor …

Jun 2, 2025
CVE-2024-1440
5.4 MEDIUM

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is …

Jun 2, 2025
CVE-2025-48941
5.3 MEDIUM

MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine …

Jun 2, 2025
CVE-2025-48940
7.2 HIGH

MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to …

Jun 2, 2025
CVE-2025-48866
7.5 HIGH

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of …

Jun 2, 2025
CVE-2025-45542
7.3 HIGH

SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL …

Jun 2, 2025
CVE-2025-44115
5.4 MEDIUM

A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads …

Jun 2, 2025
CVE-2024-57459
7.3 HIGH

A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an …

Jun 2, 2025
CVE-2024-40114
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie …

Jun 2, 2025
CVE-2024-40113
6.5 MEDIUM

Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.

Jun 2, 2025
CVE-2024-40112
5.9 MEDIUM

A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the …

Jun 2, 2025
CVE-2025-44172
6.5 MEDIUM

Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

Jun 2, 2025
CVE-2025-37096
9.8 CRITICAL

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37095
9.8 CRITICAL

A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-20001
6.5 MEDIUM

An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trigger this vulnerability which can lead to disclosure of sensitive …

Jun 2, 2025
CVE-2024-54028
8.4 HIGH

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory …

Jun 2, 2025
CVE-2024-52035
8.4 HIGH

An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to …

Jun 2, 2025
CVE-2024-48877
8.4 HIGH

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead …

Jun 2, 2025
CVE-2025-5447
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function …

Jun 2, 2025
CVE-2025-37094
5.5 MEDIUM

A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37093
9.8 CRITICAL

An authentication bypass vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37092
9.8 CRITICAL

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37091
7.2 HIGH

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37090
9.8 CRITICAL

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37089
9.8 CRITICAL

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2024-57783
8.1 HIGH

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with …

Jun 2, 2025
CVE-2025-5446
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS …

Jun 2, 2025
CVE-2025-5445
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function …

Jun 2, 2025
CVE-2025-48745

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-49113. Reason: This candidate is a reservation duplicate of CVE-2025-49113. Notes: All CVE users should reference …

Jun 2, 2025
CVE-2025-46806

A Use of Out-of-range Pointer Offset vulnerability in sslh leads to denial of service on some architectures.This issue affects sslh before 2.2.4.

Jun 2, 2025
CVE-2025-26396
7.8 HIGH

The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a …

Jun 2, 2025
CVE-2024-12168
7.8 HIGH

Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.

Jun 2, 2025
CVE-2025-5444
6.3 MEDIUM

A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this vulnerability is the …

Jun 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.