CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7908
8.8 HIGH

A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file …

Jul 20, 2025
CVE-2025-54317
8.4 HIGH

An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template, which …

Jul 20, 2025
CVE-2025-47917
8.9 HIGH

Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a …

Jul 20, 2025
CVE-2025-7897
7.3 HIGH

A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file …

Jul 20, 2025
CVE-2025-46385
8.6 HIGH

CWE-918 Server-Side Request Forgery (SSRF)

Jul 20, 2025
CVE-2025-46384
8.8 HIGH

CWE-434 Unrestricted Upload of File with Dangerous Type

Jul 20, 2025
CVE-2025-7886
7.3 HIGH

A vulnerability, which was classified as critical, was found in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. This affects the function getUserLanguage of the file classes/class.database.php. The …

Jul 20, 2025
CVE-2025-7883
7.8 HIGH

A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component …

Jul 20, 2025
CVE-2025-7875
7.3 HIGH

A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part of the file /debug.jsp. The …

Jul 20, 2025
CVE-2025-7862
7.3 HIGH

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi …

Jul 20, 2025
CVE-2025-7861
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an unknown function of the file /members/search.php. The …

Jul 20, 2025
CVE-2025-7860
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file …

Jul 20, 2025
CVE-2025-7859
7.3 HIGH

A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/update_password_admin.php. The manipulation of …

Jul 20, 2025
CVE-2025-7855
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromqossetting of the file /goform/qossetting. The manipulation …

Jul 19, 2025
CVE-2025-7854
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the …

Jul 19, 2025
CVE-2025-7853
8.8 HIGH

A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function fromSetIpBind of the file /goform/SetIpBind. The …

Jul 19, 2025
CVE-2025-7838
7.3 HIGH

A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Jul 19, 2025
CVE-2025-7837
8.8 HIGH

A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the component MQTT Service. …

Jul 19, 2025
CVE-2025-54313
7.5 HIGH KEV

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches …

Jul 19, 2025
CVE-2025-7833
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file …

Jul 19, 2025
CVE-2025-7832
7.3 HIGH

A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/offering.php. The manipulation of …

Jul 19, 2025
CVE-2025-7831
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unknown part of the file /members/Tithes.php. The manipulation …

Jul 19, 2025
CVE-2025-7830
7.3 HIGH

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 19, 2025
CVE-2025-7829
7.3 HIGH

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 19, 2025
CVE-2025-7824
7.3 HIGH

A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The …

Jul 19, 2025
CVE-2025-7823
7.3 HIGH

A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation …

Jul 19, 2025
CVE-2015-10139
8.8 HIGH

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for …

Jul 19, 2025
CVE-2015-10136
7.5 HIGH

The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read …

Jul 19, 2025
CVE-2015-10134
7.5 HIGH

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is …

Jul 19, 2025
CVE-2015-10133
7.2 HIGH

The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. …

Jul 19, 2025
CVE-2025-38350
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain classful qdiscs may invoke their …

Jul 19, 2025
CVE-2025-27210
7.5 HIGH

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users …

Jul 18, 2025
CVE-2025-27209
7.5 HIGH

The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker …

Jul 18, 2025
CVE-2025-7814
7.3 HIGH

A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability affects unknown code of the file /pages/signup_function.php. The manipulation …

Jul 18, 2025
CVE-2025-7807
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. This issue affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. The …

Jul 18, 2025
CVE-2025-7806
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. The manipulation of the …

Jul 18, 2025
CVE-2025-7805
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the …

Jul 18, 2025
CVE-2025-50708
7.5 HIGH

An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL

Jul 18, 2025
CVE-2025-7801
7.3 HIGH

A vulnerability has been found in BossSoft CRM 6.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /crm/module/HNDCBas_customPrmSearchDtl.jsp. …

Jul 18, 2025
CVE-2025-52169
7.1 HIGH

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

Jul 18, 2025
CVE-2025-50585
8.8 HIGH

StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.

Jul 18, 2025
CVE-2025-7796
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserAdd of the file /goform/PPTPDClient. The manipulation of …

Jul 18, 2025
CVE-2025-7795
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file …

Jul 18, 2025
CVE-2025-52164
8.2 HIGH

Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.

Jul 18, 2025
CVE-2025-7794
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation …

Jul 18, 2025
CVE-2025-7793
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary. The manipulation of the …

Jul 18, 2025
CVE-2025-7792
8.8 HIGH

A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. The …

Jul 18, 2025
CVE-2025-53762
8.7 HIGH

Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.

Jul 18, 2025
CVE-2025-7790
8.8 HIGH

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part of the file /menu_nat.asp of the …

Jul 18, 2025
CVE-2025-54079
8.8 HIGH

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions …

Jul 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.