CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7517
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the …

Jul 13, 2025
CVE-2025-7516
7.3 HIGH

A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. This vulnerability affects unknown code of the file /cancelbookingpatient.php. The manipulation …

Jul 13, 2025
CVE-2025-7515
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. This affects an unknown part of the file /ulocateus.php. The …

Jul 13, 2025
CVE-2025-7514
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 13, 2025
CVE-2025-7513
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 13, 2025
CVE-2025-7512
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0. It has been classified as critical. Affected is an unknown function of the file /contact-back.php. The …

Jul 13, 2025
CVE-2025-7510
7.3 HIGH

A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/productadd_back.php. The manipulation …

Jul 13, 2025
CVE-2025-7509
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /admin/slide.php. The manipulation …

Jul 13, 2025
CVE-2025-7508
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Modern Bag 1.0. Affected by this issue is some unknown functionality of the …

Jul 13, 2025
CVE-2025-7506
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromNatlimit of the file /goform/Natlimit of the …

Jul 12, 2025
CVE-2025-7505
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function frmL7ProtForm of the file /goform/L7Prot of the component HTTP …

Jul 12, 2025
CVE-2025-7483
7.3 HIGH

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been rated as critical. This issue affects some unknown processing of the …

Jul 12, 2025
CVE-2024-41169
7.5 HIGH

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue …

Jul 12, 2025
CVE-2025-7480
7.3 HIGH

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 12, 2025
CVE-2025-7478
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. Affected is an unknown function of the file /admin/category-list.php. The manipulation …

Jul 12, 2025
CVE-2025-7476
7.3 HIGH

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /admin/approve.php. The manipulation …

Jul 12, 2025
CVE-2025-7475
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part of the file /pay.php. The …

Jul 12, 2025
CVE-2025-7474
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 12, 2025
CVE-2025-7471
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 12, 2025
CVE-2020-36848
7.5 HIGH

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Jul 12, 2025
CVE-2025-7470
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jul 12, 2025
CVE-2025-7469
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/product_add.php. …

Jul 12, 2025
CVE-2025-7504
7.5 HIGH

The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes …

Jul 12, 2025
CVE-2025-7468
8.8 HIGH

A vulnerability has been found in Tenda FH1201 1.2.0.14 and classified as critical. This vulnerability affects the function fromSafeUrlFilter of the file /goform/fromSafeUrlFilter of the …

Jul 12, 2025
CVE-2025-7467
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /product-detail.php. The manipulation …

Jul 12, 2025
CVE-2025-7466
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000projects ABC Courier Management 1.0. Affected by this issue is some unknown functionality of …

Jul 12, 2025
CVE-2025-6423
8.8 HIGH

The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_upload_file() function in all versions …

Jul 12, 2025
CVE-2025-7465
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH1201 1.2.0.14. Affected by this vulnerability is the function fromRouteStatic of the file /goform/fromRouteStatic of the …

Jul 12, 2025
CVE-2025-7463
8.8 HIGH

A vulnerability was found in Tenda FH1201 1.2.0.14. It has been declared as critical. This vulnerability affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of …

Jul 12, 2025
CVE-2025-1313
8.8 HIGH

The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, …

Jul 12, 2025
CVE-2025-7461
7.3 HIGH

A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. …

Jul 12, 2025
CVE-2025-6057
8.8 HIGH

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up …

Jul 12, 2025
CVE-2025-24294
7.5 HIGH

The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain …

Jul 12, 2025
CVE-2025-5199
7.3 HIGH

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed …

Jul 12, 2025
CVE-2025-7460
8.8 HIGH

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi …

Jul 11, 2025
CVE-2025-7459
7.3 HIGH

A vulnerability classified as critical was found in code-projects Mobile Shop 1.0. This vulnerability affects unknown code of the file /EditMobile.php. The manipulation of the …

Jul 11, 2025
CVE-2025-7457
7.3 HIGH

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects an unknown part of the …

Jul 11, 2025
CVE-2025-7456
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this issue is some …

Jul 11, 2025
CVE-2025-7455
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of …

Jul 11, 2025
CVE-2025-7454
7.3 HIGH

A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected is an unknown function of the file …

Jul 11, 2025
CVE-2025-30403
8.1 HIGH

A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.

Jul 11, 2025
CVE-2013-3307
8.3 HIGH

Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in the apply.cgi ping_ip …

Jul 11, 2025
CVE-2025-53641
8.2 HIGH

Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into …

Jul 11, 2025
CVE-2025-30402
8.1 HIGH

A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially result in code execution or other undesirable effects. …

Jul 11, 2025
CVE-2025-7029
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHeader, …

Jul 11, 2025
CVE-2025-7028
7.8 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0x20) allows a local attacker to supply a crafted pointer (FuncBlock) through RBX and RCX register values. …

Jul 11, 2025
CVE-2025-7027
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and write addresses used by the CommandRcx1 …

Jul 11, 2025
CVE-2025-7026
8.2 HIGH

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used as an unchecked pointer …

Jul 11, 2025
CVE-2025-52983
7.2 HIGH

A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to …

Jul 11, 2025
CVE-2025-52981
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX1600, SRX2300, SRX 4000 …

Jul 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.