CVE Database

52406+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54608
6.2 MEDIUM

Vulnerability that allows setting screen rotation direction without permission verification in the screen management module. Impact: Successful exploitation of this vulnerability may cause device screen …

Aug 6, 2025
CVE-2025-54879
5.3 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through …

Aug 6, 2025
CVE-2025-54571
6.1 MEDIUM

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can …

Aug 6, 2025
CVE-2025-54125
6.5 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform …

Aug 6, 2025
CVE-2025-54124
6.5 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform …

Aug 6, 2025
CVE-2025-32430
6.1 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 …

Aug 6, 2025
CVE-2025-8573
4.8 MEDIUM

Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version 8 was not affected. A rogue …

Aug 5, 2025
CVE-2025-8571
4.8 MEDIUM

Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could …

Aug 5, 2025
CVE-2025-52237
6.5 MEDIUM

An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

Aug 5, 2025
CVE-2025-52078
6.5 MEDIUM

File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request …

Aug 5, 2025
CVE-2025-51541
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before …

Aug 5, 2025
CVE-2025-50592
5.4 MEDIUM

Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.

Aug 5, 2025
CVE-2025-45512
6.5 MEDIUM

A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to …

Aug 5, 2025
CVE-2025-51857
6.1 MEDIUM

The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS attacks.

Aug 5, 2025
CVE-2025-51627
6.5 MEDIUM

Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator.

Aug 5, 2025
CVE-2025-51060
6.5 MEDIUM

An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR …

Aug 5, 2025
CVE-2025-50688
6.5 MEDIUM

A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability …

Aug 5, 2025
CVE-2025-50454
6.5 MEDIUM

An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log into the application as an administrator without valid …

Aug 5, 2025
CVE-2025-8585
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the …

Aug 5, 2025
CVE-2025-43980
6.5 MEDIUM

An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the credentials of root/admin. The GUI doesn't …

Aug 5, 2025
CVE-2025-47152
6.5 MEDIUM

An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396. By using a specially crafted EMF file, an attacker …

Aug 5, 2025
CVE-2025-46958
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Aug 5, 2025
CVE-2025-27931
6.5 MEDIUM

An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit …

Aug 5, 2025
CVE-2024-52890
6.1 MEDIUM

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

Aug 5, 2025
CVE-2025-8295
6.4 MEDIUM

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due …

Aug 5, 2025
CVE-2025-8294
6.4 MEDIUM

The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3 due …

Aug 5, 2025
CVE-2025-2810
5.5 MEDIUM

A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.

Aug 5, 2025
CVE-2025-8315
6.4 MEDIUM

The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.0.1 …

Aug 5, 2025
CVE-2025-8313
6.4 MEDIUM

The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due …

Aug 5, 2025
CVE-2025-8547
5.3 MEDIUM

A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email Verification …

Aug 5, 2025
CVE-2025-8546
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code …

Aug 5, 2025
CVE-2025-54871
5.5 MEDIUM

Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass …

Aug 5, 2025
CVE-2025-54804
6.5 MEDIUM

Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used …

Aug 5, 2025
CVE-2025-52892
4.5 MEDIUM

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and …

Aug 5, 2025
CVE-2025-8530
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of …

Aug 4, 2025
CVE-2025-8529
6.3 MEDIUM

A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerability is the function getCollectLogoUrl of the file app/src/main/java/com/favorites/web/CollectController.java. …

Aug 4, 2025
CVE-2025-8527
6.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file …

Aug 4, 2025
CVE-2025-54554
5.3 MEDIUM

tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.

Aug 4, 2025
CVE-2025-4604
6.1 MEDIUM

The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through …

Aug 4, 2025
CVE-2025-4599
6.1 MEDIUM

The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 …

Aug 4, 2025
CVE-2025-8526
6.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file …

Aug 4, 2025
CVE-2025-8525
5.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring …

Aug 4, 2025
CVE-2025-8524
5.3 MEDIUM

A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the …

Aug 4, 2025
CVE-2025-8523
5.3 MEDIUM

A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality …

Aug 4, 2025
CVE-2025-55014
4.7 MEDIUM

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers …

Aug 4, 2025
CVE-2025-50340
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other …

Aug 4, 2025
CVE-2025-8522
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of …

Aug 4, 2025
CVE-2025-8520
4.7 MEDIUM

A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/?module=editor/editor of the component …

Aug 4, 2025
CVE-2025-46206
6.5 MEDIUM

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` …

Aug 4, 2025
CVE-2024-45183
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads …

Aug 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.