CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48427

Rejected reason: Not used

May 21, 2025
CVE-2025-48426

Rejected reason: Not used

May 21, 2025
CVE-2025-48425

Rejected reason: Not used

May 21, 2025
CVE-2025-48424

Rejected reason: Not used

May 21, 2025
CVE-2025-48423

Rejected reason: Not used

May 21, 2025
CVE-2025-48422

Rejected reason: Not used

May 21, 2025
CVE-2025-48421

Rejected reason: Not used

May 21, 2025
CVE-2025-48420

Rejected reason: Not used

May 21, 2025
CVE-2025-48419

Rejected reason: Not used

May 21, 2025
CVE-2025-5011
2.4 LOW

A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List …

May 21, 2025
CVE-2025-5010
2.4 LOW

A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog …

May 21, 2025
CVE-2025-5008
7.3 HIGH

A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

May 20, 2025
CVE-2025-5007
3.5 LOW

A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the …

May 20, 2025
CVE-2025-5006
7.3 HIGH

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/category.php. …

May 20, 2025
CVE-2025-5004
7.3 HIGH

A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add_course.php. …

May 20, 2025
CVE-2025-4436

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 20, 2025
CVE-2025-5003
7.3 HIGH

A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /semester_ajax.php. …

May 20, 2025
CVE-2025-5002
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. …

May 20, 2025
CVE-2025-5001
3.3 LOW

A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The …

May 20, 2025
CVE-2025-5000
6.3 MEDIUM

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the …

May 20, 2025
CVE-2025-4999
6.3 MEDIUM

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function sub_4153FC of …

May 20, 2025
CVE-2025-4998
6.5 MEDIUM

A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of …

May 20, 2025
CVE-2025-44898
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.

May 20, 2025
CVE-2025-44897
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.

May 20, 2025
CVE-2025-44896
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.

May 20, 2025
CVE-2025-44894
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.

May 20, 2025
CVE-2025-44891
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.

May 20, 2025
CVE-2025-44883
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.

May 20, 2025
CVE-2025-44882
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

May 20, 2025
CVE-2025-44880
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

May 20, 2025
CVE-2025-4997
6.5 MEDIUM

A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function UpdateWanParams/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList/Edit_BasicSSID/Edit_GuestSSIDFor2P4G/Edit_BasicSSID_5G/SetAPInfoById of the file /goform/aspForm of …

May 20, 2025
CVE-2025-48056
5.3 MEDIUM

Hubble is a fully distributed networking and security observability platform for cloud native workloads. Prior to version 1.17.2, a network attacker could inject malicious control …

May 20, 2025
CVE-2025-44893
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.

May 20, 2025
CVE-2025-44890
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.

May 20, 2025
CVE-2025-44888
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.

May 20, 2025
CVE-2025-44887
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

May 20, 2025
CVE-2025-44886
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.

May 20, 2025
CVE-2025-44885
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.

May 20, 2025
CVE-2025-44884
9.8 CRITICAL

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.

May 20, 2025
CVE-2025-44881
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

May 20, 2025
CVE-2025-4996
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add …

May 20, 2025
CVE-2025-47290
5.9 MEDIUM

containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially …

May 20, 2025
CVE-2025-4364

The affected products could allow an unauthenticated attacker to access system information that could enable further access to sensitive files and obtain administrative credentials.

May 20, 2025
CVE-2025-48391
7.7 HIGH

In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

May 20, 2025
CVE-2025-47854
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page

May 20, 2025
CVE-2025-47853
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible

May 20, 2025
CVE-2025-47852
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible

May 20, 2025
CVE-2025-47851
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible

May 20, 2025
CVE-2025-47850
4.3 MEDIUM

In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

May 20, 2025
CVE-2025-47277
9.8 CRITICAL

vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the …

May 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.