CVE Database

52406+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-51488
4.9 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to store and execute arbitrary JavaScript by including a malicious …

Aug 19, 2025
CVE-2025-51487
4.5 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary JavaScript by using "javascript:" payload, instead of the expected …

Aug 19, 2025
CVE-2025-50897
4.3 MEDIUM

A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly …

Aug 19, 2025
CVE-2025-50579
5.3 MEDIUM

A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin …

Aug 19, 2025
CVE-2025-9140
6.3 MEDIUM

A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this issue is some unknown functionality of the file …

Aug 19, 2025
CVE-2025-50461
6.5 MEDIUM

A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script when using the "fsdp" backend. The script calls torch.load() with weights_only=False on …

Aug 19, 2025
CVE-2025-4690
4.3 MEDIUM

A regular expression used by AngularJS' linky https://docs.angularjs.org/api/ngSanitize/filter/linky filter to detect URLs in input text is vulnerable to super-linear runtime due to backtracking. With a …

Aug 19, 2025
CVE-2025-43739
4.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 …

Aug 19, 2025
CVE-2024-45062
6.4 MEDIUM

A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer that supports IPP-over-USB can cause a buffer overflow which …

Aug 19, 2025
CVE-2025-9139
4.3 MEDIUM

A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information …

Aug 19, 2025
CVE-2025-43740
5.4 MEDIUM

A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 …

Aug 19, 2025
CVE-2025-9136
5.3 MEDIUM

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack …

Aug 19, 2025
CVE-2025-9135
5.3 MEDIUM

A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 12.1.1(258) on Android. The impacted element is an unknown function …

Aug 19, 2025
CVE-2025-9134
5.3 MEDIUM

A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected element is an unknown function of the …

Aug 19, 2025
CVE-2025-8783
4.4 MEDIUM

The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all versions up to, and including, 8.6.5 due …

Aug 19, 2025
CVE-2025-8567
6.4 MEDIUM

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to …

Aug 19, 2025
CVE-2025-41685
6.5 MEDIUM

A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.

Aug 19, 2025
CVE-2025-8622
6.4 MEDIUM

The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortcode in all versions up to, and including, …

Aug 19, 2025
CVE-2025-38553
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: Restrict conditions for adding duplicating netems to qdisc tree netem_enqueue's duplication prevention logic breaks …

Aug 19, 2025
CVE-2025-8357
4.3 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user …

Aug 19, 2025
CVE-2025-5417
6.1 MEDIUM

An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has …

Aug 19, 2025
CVE-2025-7496
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements in all versions up to, and including, …

Aug 19, 2025
CVE-2025-54862
5.4 MEDIUM

Sante PACS Server web portal is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage …

Aug 18, 2025
CVE-2025-54759
6.1 MEDIUM

Sante PACS Server is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage and stealing …

Aug 18, 2025
CVE-2025-55590
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.

Aug 18, 2025
CVE-2025-55589
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.

Aug 18, 2025
CVE-2025-55585
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.

Aug 18, 2025
CVE-2025-55584
5.3 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.

Aug 18, 2025
CVE-2025-4371
6.8 MEDIUM

A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write …

Aug 18, 2025
CVE-2025-43731
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, …

Aug 18, 2025
CVE-2025-55296
5.5 MEDIUM

librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. …

Aug 18, 2025
CVE-2025-55288
5.5 MEDIUM

Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Reflected Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could …

Aug 18, 2025
CVE-2025-55287
5.4 MEDIUM

Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could …

Aug 18, 2025
CVE-2025-54118
5.3 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker …

Aug 18, 2025
CVE-2025-33100
6.2 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound …

Aug 18, 2025
CVE-2025-27909
5.4 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name …

Aug 18, 2025
CVE-2025-1759
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Aug 18, 2025
CVE-2025-43733
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript …

Aug 18, 2025
CVE-2025-41242
5.9 MEDIUM

Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when …

Aug 18, 2025
CVE-2025-57703
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57702
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57701
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57700
6.1 MEDIUM

DIAEnergie - Stored Cross-site Scripting

Aug 18, 2025
CVE-2025-9108
4.3 MEDIUM

Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ui layers. It is possible to launch …

Aug 18, 2025
CVE-2025-9107
4.3 MEDIUM

A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/search_autocomplete. Executing manipulation of the argument q …

Aug 18, 2025
CVE-2025-9102
5.3 MEDIUM

A security vulnerability has been detected in 1&1 Mail & Media mail.com App 8.8.0 on Android. Affected is an unknown function of the file AndroidManifest.xml …

Aug 18, 2025
CVE-2025-9100
5.3 MEDIUM

A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article …

Aug 18, 2025
CVE-2025-9099
6.3 MEDIUM

A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of …

Aug 18, 2025
CVE-2025-9098
5.3 MEDIUM

A vulnerability was determined in Elseplus File Recovery App 4.4.21 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml. The …

Aug 18, 2025
CVE-2025-31714
6.8 MEDIUM

In Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

Aug 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.