CVE Database

52406+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-33023
4.1 MEDIUM

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (All versions), RUGGEDCOM ROX RX1500 (All …

Aug 12, 2025
CVE-2025-30034
6.2 MEDIUM

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected devices do not properly validate input sent to its listening …

Aug 12, 2025
CVE-2024-41986
6.4 MEDIUM

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < …

Aug 12, 2025
CVE-2024-41982
4.8 MEDIUM

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < …

Aug 12, 2025
CVE-2025-43736
4.3 MEDIUM

A Denial Of Service via File Upload (DOS) vulnerability in the Liferay Portal 7.4.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, …

Aug 12, 2025
CVE-2025-26398
5.6 MEDIUM

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. …

Aug 12, 2025
CVE-2025-8874
6.4 MEDIUM

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Aug 12, 2025
CVE-2025-8767
4.8 MEDIUM

The AnWP Football Leagues plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 0.16.17 via the 'download_csv_players' and 'download_csv_games' …

Aug 12, 2025
CVE-2025-8482
4.3 MEDIUM

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check …

Aug 12, 2025
CVE-2025-47444
5.3 MEDIUM

Missing Authorization vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FiboSearch: from n/a through <= 1.32.1.

Aug 12, 2025
CVE-2025-8081
4.9 MEDIUM

The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to …

Aug 12, 2025
CVE-2025-3892
6.7 MEDIUM

ACAP applications can be executed with elevated privileges, potentially leading to privilege escalation. This vulnerability can only be exploited if the Axis device is configured …

Aug 12, 2025
CVE-2025-30027
6.7 MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vulnerability can only be exploited if the Axis device …

Aug 12, 2025
CVE-2025-8314
6.4 MEDIUM

The Software Issue Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg parameter in all versions up to, and including, 5.0.1 …

Aug 12, 2025
CVE-2025-7622
5.7 MEDIUM

During an internal security assessment, a Server-Side Request Forgery (SSRF) vulnerability that allowed an authenticated attacker to access internal resources on the server was discovered.

Aug 12, 2025
CVE-2025-8690
6.4 MEDIUM

The Simple Responsive Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0 due to insufficient input …

Aug 12, 2025
CVE-2025-8688
6.4 MEDIUM

The Inline Stock Quotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock shortcode in all versions up to, and including, …

Aug 12, 2025
CVE-2025-8685
6.4 MEDIUM

The Wp chart generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpchart shortcode in all versions up to, and including, …

Aug 12, 2025
CVE-2025-8621
6.4 MEDIUM

The Mosaic Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘c’ parameter in all versions up to, and including, 1.0.5 due …

Aug 12, 2025
CVE-2025-8568
6.4 MEDIUM

The GMap Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘h’ parameter in all versions up to, and including, 1.1 due …

Aug 12, 2025
CVE-2025-8462
6.4 MEDIUM

The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the social URL parameter in all …

Aug 12, 2025
CVE-2025-4390
5.3 MEDIUM

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' …

Aug 12, 2025
CVE-2025-42975
6.1 MEDIUM

SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds …

Aug 12, 2025
CVE-2025-42949
4.9 MEDIUM

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging …

Aug 12, 2025
CVE-2025-42948
6.1 MEDIUM

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. …

Aug 12, 2025
CVE-2025-42946
6.9 MEDIUM

Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in …

Aug 12, 2025
CVE-2025-42945
6.1 MEDIUM

SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick …

Aug 12, 2025
CVE-2025-42943
4.5 MEDIUM

SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, …

Aug 12, 2025
CVE-2025-42942
6.1 MEDIUM

SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and …

Aug 12, 2025
CVE-2025-42936
5.4 MEDIUM

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users …

Aug 12, 2025
CVE-2025-42935
4.1 MEDIUM

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files …

Aug 12, 2025
CVE-2025-42934
4.3 MEDIUM

SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted …

Aug 12, 2025
CVE-2025-8285
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper …

Aug 11, 2025
CVE-2025-7677
5.9 MEDIUM

A denial-of-service (DoS) attack is possible if access to the local network is provided to unauthorized users. This is due to a buffer copy issue …

Aug 11, 2025
CVE-2025-54463
5.9 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint …

Aug 11, 2025
CVE-2025-54458
5.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to create a subscription for …

Aug 11, 2025
CVE-2025-53910
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without …

Aug 11, 2025
CVE-2025-53514
5.9 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint …

Aug 11, 2025
CVE-2025-51824
6.5 MEDIUM

libcsp 2.0 is vulnerable to Buffer Overflow in the csp_usart_open() function at drivers/usart/zephyr.c.

Aug 11, 2025
CVE-2025-51823
6.5 MEDIUM

libcsp 2.0 is vulnerable to Buffer Overflow in the csp_eth_init() function due to improper handling of the ifname parameter. The function uses strcpy to copy …

Aug 11, 2025
CVE-2025-48731
6.4 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the Confluence space which allows attackers to edit a subscription for …

Aug 11, 2025
CVE-2025-44001
4.0 MEDIUM

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without …

Aug 11, 2025
CVE-2025-25229
5.4 MEDIUM

Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system …

Aug 11, 2025
CVE-2025-38499
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is …

Aug 11, 2025
CVE-2025-8859
6.3 MEDIUM

A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File …

Aug 11, 2025
CVE-2025-8852
4.3 MEDIUM

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation …

Aug 11, 2025
CVE-2025-8851
5.3 MEDIUM

A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. …

Aug 11, 2025
CVE-2025-8846
5.3 MEDIUM

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected is the function parse_line of the file parser.c. The manipulation leads to stack-based buffer …

Aug 11, 2025
CVE-2025-8845
5.3 MEDIUM

A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer …

Aug 11, 2025
CVE-2025-8843
5.3 MEDIUM

A vulnerability was found in NASM Netwide Assember 2.17rc0. This affects the function macho_no_dead_strip of the file outmacho.c. The manipulation leads to heap-based buffer overflow. …

Aug 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.