CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4733
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file …

May 16, 2025
CVE-2025-4732
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formFilter of the component …

May 16, 2025
CVE-2025-47809
8.2 HIGH

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation …

May 16, 2025
CVE-2024-51475
5.4 MEDIUM

IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

May 16, 2025
CVE-2025-4731
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formPortFw of the …

May 16, 2025
CVE-2025-4730
8.8 HIGH

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is some unknown functionality of …

May 16, 2025
CVE-2025-4729
6.3 MEDIUM

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 16, 2025
CVE-2025-47930
5.3 MEDIUM

Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism …

May 16, 2025
CVE-2025-4728
7.3 HIGH

A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file …

May 15, 2025
CVE-2025-4727
3.7 LOW

A vulnerability was found in Meteor up to 3.2.1 and classified as problematic. This issue affects the function Object.assign of the file packages/ddp-server/livedata_server.js. The manipulation …

May 15, 2025
CVE-2025-4726
7.3 HIGH

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view_student.php. The …

May 15, 2025
CVE-2025-4209

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 15, 2025
CVE-2025-0921
6.5 MEDIUM

Execution with Unnecessary Privileges vulnerability in multiple services of Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi …

May 15, 2025
CVE-2025-4725
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. This affects an unknown part of the file /view_drive.php. The …

May 15, 2025
CVE-2025-4724
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Placement Management System 1.0. Affected by this issue is some unknown functionality of …

May 15, 2025
CVE-2025-4723
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /all_student.php. …

May 15, 2025
CVE-2025-4722
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /edit_profile.php. The manipulation …

May 15, 2025
CVE-2025-47287
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to …

May 15, 2025
CVE-2025-47275
9.1 CRITICAL

Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session cookies of applications using …

May 15, 2025
CVE-2025-4721
7.3 HIGH

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

May 15, 2025
CVE-2025-4720
5.4 MEDIUM

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

May 15, 2025
CVE-2025-4719
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

May 15, 2025
CVE-2025-4718
7.3 HIGH

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

May 15, 2025
CVE-2025-47929

DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scripting vulnerability in the upload functionality prior …

May 15, 2025
CVE-2025-1138
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory …

May 15, 2025
CVE-2025-4717
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /visitors-form.php. …

May 15, 2025
CVE-2025-4716
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

May 15, 2025
CVE-2025-4715
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 15, 2025
CVE-2025-47928
9.1 CRITICAL

Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_request_target` on `.github/workflows/integration_tests.yml` followed by the checking out the head.sha …

May 15, 2025
CVE-2025-47789
6.1 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla …

May 15, 2025
CVE-2025-47788

Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow …

May 15, 2025
CVE-2025-47787
9.8 CRITICAL

Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical …

May 15, 2025
CVE-2025-47786
4.8 MEDIUM

Emlog is an open source website building system. Version 2.5.13 has a stored cross-site scripting vulnerability that allows any registered user to construct malicious JavaScript, …

May 15, 2025
CVE-2025-47785
8.3 HIGH

Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the $origContent parameter in admin/article_save.php is …

May 15, 2025
CVE-2025-47784
9.8 CRITICAL

Emlog is an open source website building system. Versions 2.5.13 and prior have a deserialization vulnerability. A user who creates a carefully crafted nickname can …

May 15, 2025
CVE-2025-47161
7.8 HIGH

Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

May 15, 2025
CVE-2025-46834

Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e6f540d249afcaeaf76ab95517d0359fde883b0, …

May 15, 2025
CVE-2025-2248
5.4 MEDIUM

The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL …

May 15, 2025
CVE-2025-2247
5.4 MEDIUM

The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

May 15, 2025
CVE-2025-2203
6.1 MEDIUM

The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL …

May 15, 2025
CVE-2025-1454
5.4 MEDIUM

The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2025-1303
6.1 MEDIUM

The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

May 15, 2025
CVE-2025-1289
4.8 MEDIUM

The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 15, 2025
CVE-2025-1288
6.1 MEDIUM

The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

May 15, 2025
CVE-2025-1286
6.1 MEDIUM

The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to …

May 15, 2025
CVE-2025-1033
4.8 MEDIUM

The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 15, 2025
CVE-2025-0688
6.1 MEDIUM

The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the …

May 15, 2025
CVE-2025-0687
6.1 MEDIUM

The Spiritual Gifts Survey (and optional S.H.A.P.E survey) WordPress plugin through 0.9.10 does not sanitise and escape a parameter before outputting it back in the …

May 15, 2025
CVE-2025-0329
4.8 MEDIUM

The AI ChatBot for WordPress WordPress plugin before 6.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

May 15, 2025
CVE-2024-9882
4.8 MEDIUM

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, …

May 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.