CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7405
7.3 HIGH

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the …

Sep 1, 2025
CVE-2025-9757
7.3 HIGH

A vulnerability was determined in Campcodes/SourceCodester Courier Management System 1.0. Affected is the function Login of the file /ajax.php. This manipulation of the argument email …

Sep 1, 2025
CVE-2025-9752
7.3 HIGH

A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. …

Sep 1, 2025
CVE-2025-9751
7.3 HIGH

A weakness has been identified in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /login.php. This manipulation of …

Sep 1, 2025
CVE-2025-9750
7.3 HIGH

A security flaw has been discovered in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of …

Aug 31, 2025
CVE-2025-9749
7.3 HIGH

A vulnerability was identified in HKritesh009 Grocery List Management Web App up to f491b681eb70d465f445c9a721415c965190f83b. This affects an unknown part of the file /src/update.php. The manipulation …

Aug 31, 2025
CVE-2025-9748
8.8 HIGH

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected by this issue is the function fromIpsecitem of the file /goform/IPSECsave of the component httpd. Executing …

Aug 31, 2025
CVE-2025-9744
7.3 HIGH

A weakness has been identified in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation …

Aug 31, 2025
CVE-2025-9743
7.3 HIGH

A security flaw has been discovered in code-projects Human Resource Integrated System 1.0. Impacted is an unknown function of the file login_attendance2.php. Performing manipulation of …

Aug 31, 2025
CVE-2025-9742
7.3 HIGH

A vulnerability was identified in code-projects Human Resource Integrated System 1.0. This issue affects some unknown processing of the file /login.php. Such manipulation of the …

Aug 31, 2025
CVE-2025-9741
7.3 HIGH

A vulnerability was determined in code-projects Human Resource Integrated System 1.0. This vulnerability affects unknown code of the file /login_query12.php. This manipulation of the argument …

Aug 31, 2025
CVE-2025-9740
7.3 HIGH

A vulnerability was found in code-projects Human Resource Integrated System 1.0. This affects an unknown part of the file /log_query.php. The manipulation of the argument …

Aug 31, 2025
CVE-2025-9739
7.3 HIGH

A vulnerability has been found in Campcodes Online Water Billing System 1.0. Affected by this issue is some unknown functionality of the file /process.php. The …

Aug 31, 2025
CVE-2025-9733
7.3 HIGH

A security flaw has been discovered in code-projects Human Resource Integrated System 1.0. This impacts an unknown function of the file /login_timeee.php. Performing manipulation of …

Aug 31, 2025
CVE-2025-9730
7.3 HIGH

A vulnerability was found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /ajax/updateProfile.php. The manipulation of the …

Aug 31, 2025
CVE-2025-9729
7.3 HIGH

A vulnerability was detected in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /admin/student-registration.php. Performing manipulation of the argument studentname …

Aug 31, 2025
CVE-2025-9726
7.3 HIGH

A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /review.php. The …

Aug 31, 2025
CVE-2025-47696
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer …

Aug 31, 2025
CVE-2024-32589
7.1 HIGH

Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & …

Aug 31, 2025
CVE-2025-9706
7.3 HIGH

A security vulnerability has been detected in SourceCodester Water Billing System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit.php. Such …

Aug 30, 2025
CVE-2025-9705
7.3 HIGH

A weakness has been identified in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument …

Aug 30, 2025
CVE-2025-9704
7.3 HIGH

A security flaw has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the …

Aug 30, 2025
CVE-2025-9702
7.3 HIGH

A vulnerability was identified in SourceCodester Simple Cafe Billing System 1.0. This affects an unknown function of the file /sales_report.php. The manipulation of the argument …

Aug 30, 2025
CVE-2025-9701
7.3 HIGH

A vulnerability was determined in SourceCodester Simple Cafe Billing System 1.0. The impacted element is an unknown function of the file /receipt.php. Executing manipulation of …

Aug 30, 2025
CVE-2025-9700
7.3 HIGH

A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the …

Aug 30, 2025
CVE-2025-9699
7.3 HIGH

A vulnerability was detected in SourceCodester Online Polling System Code 1.0. This vulnerability affects unknown code of the file /admin/checklogin.php. The manipulation of the argument …

Aug 30, 2025
CVE-2025-9694
7.3 HIGH

A vulnerability was determined in Campcodes Advanced Online Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. Executing manipulation …

Aug 30, 2025
CVE-2025-9692
7.3 HIGH

A vulnerability was found in Campcodes Online Shopping System 1.0. Affected is an unknown function of the file /product.php. Performing manipulation of the argument p …

Aug 30, 2025
CVE-2025-9691
7.3 HIGH

A vulnerability has been found in Campcodes Online Shopping System 1.0. This impacts an unknown function of the file /login.php. Such manipulation of the argument …

Aug 30, 2025
CVE-2005-10004
8.8 HIGH

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the …

Aug 30, 2025
CVE-2025-0165
7.6 HIGH

IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker could …

Aug 30, 2025
CVE-2025-38677
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in dnode page As Jiaming Zhang reported: <TASK> __dump_stack …

Aug 30, 2025
CVE-2025-9679
7.3 HIGH

A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the …

Aug 30, 2025
CVE-2025-9678
7.3 HIGH

A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_borrower. This manipulation …

Aug 29, 2025
CVE-2025-58157
7.5 HIGH

gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerability when computing scalar multiplication is using the …

Aug 29, 2025
CVE-2025-56577
8.4 HIGH

An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryptographic keys.

Aug 29, 2025
CVE-2025-9669
7.3 HIGH

A vulnerability has been found in Jinher OA 1.0. This issue affects some unknown processing of the file GetTreeDate.aspx. The manipulation of the argument ID …

Aug 29, 2025
CVE-2023-41471
7.8 HIGH

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: …

Aug 29, 2025
CVE-2025-9377
7.2 HIGH KEV

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer …

Aug 29, 2025
CVE-2025-58158
8.8 HIGH

Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact Registries. Prior to version 3.3.0, Open …

Aug 29, 2025
CVE-2025-44015
8.4 HIGH

A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerability to …

Aug 29, 2025
CVE-2025-30278
8.8 HIGH

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Aug 29, 2025
CVE-2025-30277
8.8 HIGH

An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Aug 29, 2025
CVE-2025-30273
8.1 HIGH

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then …

Aug 29, 2025
CVE-2025-30264
8.8 HIGH

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then …

Aug 29, 2025
CVE-2025-29894
8.8 HIGH

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Aug 29, 2025
CVE-2025-29893
8.8 HIGH

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Aug 29, 2025
CVE-2025-29887
7.2 HIGH

A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrator account, they can then exploit the vulnerability …

Aug 29, 2025
CVE-2025-9662
7.3 HIGH

A vulnerability was determined in code-projects Simple Grading System 1.0. This affects an unknown function of the file /login.php of the component Admin Panel. Executing …

Aug 29, 2025
CVE-2025-9660
7.3 HIGH

A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of …

Aug 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.