CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20677
5.5 MEDIUM

In Bluetooth driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution …

Jun 2, 2025
CVE-2025-20676
5.5 MEDIUM

In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User …

Jun 2, 2025
CVE-2025-20675
5.5 MEDIUM

In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User …

Jun 2, 2025
CVE-2025-20674
9.8 CRITICAL

In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation …

Jun 2, 2025
CVE-2025-20673
5.5 MEDIUM

In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User …

Jun 2, 2025
CVE-2025-20672
9.8 CRITICAL

In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Jun 2, 2025
CVE-2025-5423
6.3 MEDIUM

A vulnerability has been found in juzaweb CMS up to 3.4.2 and classified as critical. This vulnerability affects unknown code of the file /admin-cp/setting/system/general of …

Jun 2, 2025
CVE-2025-5422
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/logs/email of …

Jun 2, 2025
CVE-2025-5421
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in juzaweb CMS up to 3.4.2. Affected by this issue is some unknown functionality of …

Jun 2, 2025
CVE-2025-5420
3.5 LOW

A vulnerability classified as problematic was found in juzaweb CMS up to 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/file-manager/upload …

Jun 2, 2025
CVE-2025-5412
3.5 LOW

A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1. Affected is the function Login of the file src/mist/api/views.py of …

Jun 2, 2025
CVE-2025-5411
3.5 LOW

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been rated as problematic. This issue affects the function tag_resources of the …

Jun 1, 2025
CVE-2025-5410
4.3 MEDIUM

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability affects the function session_start_response of the …

Jun 1, 2025
CVE-2025-5409
7.3 HIGH

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file …

Jun 1, 2025
CVE-2025-5408
9.8 CRITICAL

A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this …

Jun 1, 2025
CVE-2025-5407
2.4 LOW

A vulnerability has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jun 1, 2025
CVE-2025-5406
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an unknown function of the file /admin/posts.php?source=add_post. The …

Jun 1, 2025
CVE-2025-5405
3.5 LOW

A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This issue affects some unknown processing of the file …

Jun 1, 2025
CVE-2025-5404
4.3 MEDIUM

A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This vulnerability affects unknown code of the file /search.php of the component …

Jun 1, 2025
CVE-2025-5403
6.3 MEDIUM

A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This affects an unknown part of the file /admin/view_all_posts.php of the …

Jun 1, 2025
CVE-2025-5402
7.3 HIGH

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jun 1, 2025
CVE-2025-40908
9.1 CRITICAL

YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

Jun 1, 2025
CVE-2025-5401
7.3 HIGH

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 1, 2025
CVE-2025-33005
6.3 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on …

Jun 1, 2025
CVE-2025-33004
6.5 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.

Jun 1, 2025
CVE-2025-2896
4.8 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Jun 1, 2025
CVE-2025-25044
5.4 MEDIUM

IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the …

Jun 1, 2025
CVE-2025-1499
6.5 MEDIUM

IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.

Jun 1, 2025
CVE-2025-5400
7.3 HIGH

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been classified as critical. Affected is an unknown function of the file /user.php …

Jun 1, 2025
CVE-2025-5390
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the …

May 31, 2025
CVE-2025-5389
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the …

May 31, 2025
CVE-2025-5388
6.3 MEDIUM

A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The …

May 31, 2025
CVE-2025-5387
6.3 MEDIUM

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component …

May 31, 2025
CVE-2025-5386
6.3 MEDIUM

A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function transEditor of the file /cgformTransController.do?transEditor. …

May 31, 2025
CVE-2025-5385
6.3 MEDIUM

A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. …

May 31, 2025
CVE-2025-5384
6.3 MEDIUM

A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAutoListController of the file /cgAutoListController.do?datagrid. The …

May 31, 2025
CVE-2025-5383
2.4 LOW

A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component …

May 31, 2025
CVE-2025-5381
2.7 LOW

A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/File/downloadFile of …

May 31, 2025
CVE-2025-5380
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f5615e5a3d8bcbfbb. This issue affects some unknown processing of …

May 31, 2025
CVE-2025-5379
4.3 MEDIUM

A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The manipulation …

May 31, 2025
CVE-2025-5378
4.3 MEDIUM

A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown part of the file mycouncil2.aspx. The manipulation …

May 31, 2025
CVE-2025-5377
4.3 MEDIUM

A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

May 31, 2025
CVE-2025-5376
7.3 HIGH

A vulnerability was found in SourceCodester Health Center Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an …

May 31, 2025
CVE-2025-4857
7.2 HIGH

The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9 via the 'file' parameter. This makes …

May 31, 2025
CVE-2025-4691
5.3 MEDIUM

The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

May 31, 2025
CVE-2025-5375
6.3 MEDIUM

A vulnerability was found in PHPGurukul HPGurukul Online Birth Certificate System 2.0. It has been classified as critical. Affected is an unknown function of the …

May 31, 2025
CVE-2025-5374
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This issue affects some unknown processing of the file /admin/all-applications.php. …

May 31, 2025
CVE-2025-5373
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Online Birth Certificate System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/users-applications.php. …

May 31, 2025
CVE-2025-5371
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Health Center Patient Record Management System 1.0. Affected by this issue is some …

May 31, 2025
CVE-2025-5290
6.4 MEDIUM

The Borderless – Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, …

May 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.