CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-3357
9.8 CRITICAL

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index …

May 28, 2025
CVE-2025-5277
9.6 CRITICAL

aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands …

May 28, 2025
CVE-2025-4134
7.3 HIGH

Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update …

May 28, 2025
CVE-2025-48734
8.8 HIGH

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using …

May 28, 2025
CVE-2025-45997
8.6 HIGH

Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying …

May 28, 2025
CVE-2025-40651

Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the …

May 28, 2025
CVE-2025-4493
6.5 MEDIUM

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting …

May 28, 2025
CVE-2025-5299
7.3 HIGH

A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

May 28, 2025
CVE-2025-5298
7.3 HIGH

A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/betweendates-detailsreports.php. …

May 28, 2025
CVE-2025-5297
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file …

May 28, 2025
CVE-2025-3864

Hackney fails to properly release HTTP connections to the pool after handling 307 Temporary Redirect responses. Remote attackers can exploit this to exhaust connection pools, …

May 28, 2025
CVE-2025-5295
7.3 HIGH

A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code of the component PORT Command Handler. The manipulation …

May 28, 2025
CVE-2025-40673

A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because …

May 28, 2025
CVE-2025-4963
6.4 MEDIUM

The WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.15 due …

May 28, 2025
CVE-2025-1753
7.8 HIGH

LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files` argument, which is directly passed …

May 28, 2025
CVE-2025-5287
7.5 HIGH

The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.0.0 …

May 28, 2025
CVE-2025-5082
6.1 MEDIUM

The WP Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘attachment_id’ parameter in all versions up to, and including, 5.0.12 due …

May 28, 2025
CVE-2025-47295
3.7 LOW

A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker …

May 28, 2025
CVE-2025-47294
5.3 MEDIUM

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the …

May 28, 2025
CVE-2025-46777
2.3 LOW

A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an …

May 28, 2025
CVE-2025-27528
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability allows attackers to bypass the security …

May 28, 2025
CVE-2025-27526
6.5 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability …

May 28, 2025
CVE-2025-27522
6.5 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability is a secondary mining bypass for …

May 28, 2025
CVE-2025-25251
7.8 HIGH

An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a local attacker to escalate privileges …

May 28, 2025
CVE-2025-24473
3.7 LOW

A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an …

May 28, 2025
CVE-2025-22252
9.8 CRITICAL

A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS versions 7.4.4 through 7.4.6 and version 7.6.0 …

May 28, 2025
CVE-2024-54020
2.3 LOW

A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds …

May 28, 2025
CVE-2025-5025
4.8 MEDIUM

libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC …

May 28, 2025
CVE-2025-4947
6.5 MEDIUM

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does …

May 28, 2025
CVE-2025-4009

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This …

May 28, 2025
CVE-2025-4800
8.8 HIGH

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attachment function in …

May 28, 2025
CVE-2025-48848

Rejected reason: Not used

May 28, 2025
CVE-2025-48847

Rejected reason: Not used

May 28, 2025
CVE-2025-48846

Rejected reason: Not used

May 28, 2025
CVE-2025-48845

Rejected reason: Not used

May 28, 2025
CVE-2025-48844

Rejected reason: Not used

May 28, 2025
CVE-2025-48843

Rejected reason: Not used

May 28, 2025
CVE-2025-48842

Rejected reason: Not used

May 28, 2025
CVE-2025-48841

Rejected reason: Not used

May 28, 2025
CVE-2023-41839

Rejected reason: Not used

May 28, 2025
CVE-2025-25029
4.9 MEDIUM

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

May 28, 2025
CVE-2025-25026
4.3 MEDIUM

IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.

May 28, 2025
CVE-2025-25025
4.3 MEDIUM

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This …

May 28, 2025
CVE-2025-2826
2.6 LOW

n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on …

May 27, 2025
CVE-2025-2796
5.3 MEDIUM

On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. …

May 27, 2025
CVE-2024-45094
5.5 MEDIUM

IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code …

May 27, 2025
CVE-2024-11185
6.5 MEDIUM

On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, …

May 27, 2025
CVE-2022-21200

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 27, 2025
CVE-2022-21150

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

May 27, 2025
CVE-2025-40911
6.5 MEDIUM

Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass …

May 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.