CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60730
7.6 HIGH

PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function

Oct 24, 2025
CVE-2025-60801
8.2 HIGH

jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.

Oct 24, 2025
CVE-2025-60566
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.

Oct 24, 2025
CVE-2025-60565
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.

Oct 24, 2025
CVE-2025-60564
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.

Oct 24, 2025
CVE-2025-60563
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.

Oct 24, 2025
CVE-2025-60562
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.

Oct 24, 2025
CVE-2025-60561
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEmail.

Oct 24, 2025
CVE-2025-60559
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.

Oct 24, 2025
CVE-2025-60558
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formVirtualServ.

Oct 24, 2025
CVE-2025-60557
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEasy_Wizard.

Oct 24, 2025
CVE-2025-60556
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizard1.

Oct 24, 2025
CVE-2025-60555
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.

Oct 24, 2025
CVE-2025-60552
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formTcpipSetup.

Oct 24, 2025
CVE-2025-60551
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the next_page parameter in the function formDeviceReboot.

Oct 24, 2025
CVE-2025-60550
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formEasySetTimezone.

Oct 24, 2025
CVE-2025-60549
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4.

Oct 24, 2025
CVE-2025-60547
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7.

Oct 24, 2025
CVE-2025-60938
7.5 HIGH

Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. …

Oct 24, 2025
CVE-2025-60572
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvNetwork.

Oct 24, 2025
CVE-2025-60571
7.5 HIGH

D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetQoS.

Oct 24, 2025
CVE-2025-60570
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLogDnsquery.

Oct 24, 2025
CVE-2025-60569
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.

Oct 24, 2025
CVE-2025-60568
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.

Oct 24, 2025
CVE-2025-43994
8.6 HIGH

Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could …

Oct 24, 2025
CVE-2025-11145
7.5 HIGH

Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware …

Oct 24, 2025
CVE-2025-46183
8.2 HIGH

The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in …

Oct 24, 2025
CVE-2025-10861
7.5 HIGH

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Oct 24, 2025
CVE-2025-10680
8.8 HIGH

OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use

Oct 24, 2025
CVE-2025-12028
8.8 HIGH

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce …

Oct 24, 2025
CVE-2025-11889
7.2 HIGH

The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Oct 24, 2025
CVE-2025-11504
7.5 HIGH

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This …

Oct 24, 2025
CVE-2025-62868
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local File Inclusion.This issue …

Oct 24, 2025
CVE-2025-62254
7.5 HIGH

The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update …

Oct 23, 2025
CVE-2025-58429
7.5 HIGH

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-62688
7.1 HIGH

An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials …

Oct 23, 2025
CVE-2025-62498
8.8 HIGH

A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity …

Oct 23, 2025
CVE-2025-61977
7.0 HIGH

A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an …

Oct 23, 2025
CVE-2025-59500
7.7 HIGH

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Oct 23, 2025
CVE-2025-59273
7.3 HIGH

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

Oct 23, 2025
CVE-2025-58078
7.5 HIGH

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-12100
7.8 HIGH

Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6.

Oct 23, 2025
CVE-2025-55067
7.1 HIGH

The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January …

Oct 23, 2025
CVE-2025-54964
8.4 HIGH

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary …

Oct 23, 2025
CVE-2025-12044
7.5 HIGH

Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a …

Oct 23, 2025
CVE-2025-6980
7.5 HIGH

Captive Portal can expose sensitive information

Oct 23, 2025
CVE-2025-6979
8.8 HIGH

Captive Portal can allow authentication bypass

Oct 23, 2025
CVE-2025-6978
7.2 HIGH

Diagnostics command injection vulnerability

Oct 23, 2025
CVE-2025-54808
7.8 HIGH

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on …

Oct 23, 2025
CVE-2025-23352
7.8 HIGH

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitialized pointer access. A successful exploit of this …

Oct 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.