CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4292
2.4 LOW

A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/user/edit.do of …

May 5, 2025
CVE-2025-4291
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. …

May 5, 2025
CVE-2025-4290
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SMNT …

May 5, 2025
CVE-2025-44074
9.8 CRITICAL

SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_topic.php.

May 5, 2025
CVE-2025-44072
9.8 CRITICAL

SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.

May 5, 2025
CVE-2025-44071
9.8 CRITICAL

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allows attackers to execute arbitrary code via …

May 5, 2025
CVE-2025-4289
7.3 HIGH

A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component RNTO Command Handler. The manipulation …

May 5, 2025
CVE-2025-4288
7.3 HIGH

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RNFR Command Handler. The …

May 5, 2025
CVE-2025-1493
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service …

May 5, 2025
CVE-2025-1000
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user to cause …

May 5, 2025
CVE-2025-0915
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations could allow an authenticated …

May 5, 2025
CVE-2025-4287
3.3 LOW

A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function torch.cuda.nccl.reduce of the file torch/cuda/nccl.py. …

May 5, 2025
CVE-2025-4286
2.7 LOW

A vulnerability was found in Intelbras InControl up to 2.21.59. It has been classified as problematic. Affected is an unknown function of the component Dispositivos …

May 5, 2025
CVE-2025-46813
5.8 MEDIUM

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that …

May 5, 2025
CVE-2025-46734
6.4 MEDIUM

league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote …

May 5, 2025
CVE-2025-46731
7.2 HIGH

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 …

May 5, 2025
CVE-2025-46730
6.8 MEDIUM

MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools …

May 5, 2025
CVE-2025-46726
9.1 CRITICAL

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input …

May 5, 2025
CVE-2025-45618
6.5 MEDIUM

Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.

May 5, 2025
CVE-2025-45617
7.5 HIGH

Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

May 5, 2025
CVE-2025-45616
9.8 CRITICAL

Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.

May 5, 2025
CVE-2025-45615
9.8 CRITICAL

Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.

May 5, 2025
CVE-2025-45614
7.5 HIGH

Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.

May 5, 2025
CVE-2025-45613
7.5 HIGH

Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.

May 5, 2025
CVE-2025-45612
9.8 CRITICAL

Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.

May 5, 2025
CVE-2025-45611
9.8 CRITICAL

Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.

May 5, 2025
CVE-2025-45610
7.5 HIGH

Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a crafted payload.

May 5, 2025
CVE-2025-45609
7.5 HIGH

Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

May 5, 2025
CVE-2025-45608
7.5 HIGH

Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

May 5, 2025
CVE-2025-45607
9.8 CRITICAL

An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.

May 5, 2025
CVE-2025-1909
9.8 CRITICAL

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification …

May 5, 2025
CVE-2025-4318

The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access …

May 5, 2025
CVE-2025-4283
7.3 HIGH

A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The …

May 5, 2025
CVE-2025-4279
8.8 HIGH

The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_replace_get_posts::replace_post' function in all …

May 5, 2025
CVE-2025-46720
3.1 LOW

Keystone is a content management system for Node.js. Prior to version 6.5.0, `{field}.isFilterable` access control can be bypassed in `update` and `delete` mutations by adding …

May 5, 2025
CVE-2025-46719
5.4 MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, a vulnerability in the way certain html tags …

May 5, 2025
CVE-2025-46571
5.4 MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, low privileged users can upload HTML files which …

May 5, 2025
CVE-2025-46559
5.4 MEDIUM

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript …

May 5, 2025
CVE-2025-46553
6.1 MEDIUM

@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in …

May 5, 2025
CVE-2025-46340
7.2 HIGH

Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation …

May 5, 2025
CVE-2025-46335
5.4 MEDIUM

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has …

May 5, 2025
CVE-2025-43852
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. …

May 5, 2025
CVE-2025-43851
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. …

May 5, 2025
CVE-2025-43850
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. …

May 5, 2025
CVE-2025-43849
9.8 CRITICAL

Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b variables take user …

May 5, 2025
CVE-2025-29573
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.

May 5, 2025
CVE-2024-42213
5.3 MEDIUM

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing …

May 5, 2025
CVE-2024-42212
5.4 MEDIUM

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site …

May 5, 2025
CVE-2025-4282
4.3 MEDIUM

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The …

May 5, 2025
CVE-2025-4096
8.8 HIGH

Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.