CVE Database

52547+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-33114
5.3 MEDIUM

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to denial of service with a specially crafted query under certain non-default conditions.

Jul 29, 2025
CVE-2024-52894
4.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is …

Jul 29, 2025
CVE-2024-51473
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is …

Jul 29, 2025
CVE-2024-49828
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5.0.0 through 10.5.0.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.2 is …

Jul 29, 2025
CVE-2025-52284
6.5 MEDIUM

Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to …

Jul 29, 2025
CVE-2025-36010
6.5 MEDIUM

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 could allow an unauthenticated user to cause a denial of service due to executable segments that are …

Jul 29, 2025
CVE-2025-2533
5.3 MEDIUM

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a …

Jul 29, 2025
CVE-2025-27514
4.5 MEDIUM

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through …

Jul 29, 2025
CVE-2025-28171
6.5 MEDIUM

An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.

Jul 29, 2025
CVE-2025-28172
6.5 MEDIUM

Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts …

Jul 29, 2025
CVE-2025-52358
6.3 MEDIUM

A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject …

Jul 29, 2025
CVE-2025-6060
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Software Geodi allows Cross-Site Scripting (XSS).This issue affects Geodi: before …

Jul 29, 2025
CVE-2025-54422
5.5 MEDIUM

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in …

Jul 29, 2025
CVE-2025-41241
4.4 MEDIUM

VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation …

Jul 29, 2025
CVE-2025-40686
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser …

Jul 29, 2025
CVE-2025-40685
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser …

Jul 29, 2025
CVE-2025-40684
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser …

Jul 29, 2025
CVE-2025-40683
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser …

Jul 29, 2025
CVE-2025-5587
6.4 MEDIUM

The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.2.6 due to …

Jul 29, 2025
CVE-2025-8216
6.4 MEDIUM

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in all versions up to, and including, 3.1.4 …

Jul 29, 2025
CVE-2025-8196
6.4 MEDIUM

The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes in all versions up to, and …

Jul 29, 2025
CVE-2025-6730
4.3 MEDIUM

The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jul 29, 2025
CVE-2025-6692
6.4 MEDIUM

The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all versions up to, and including, 10.3 due …

Jul 29, 2025
CVE-2025-6681
6.4 MEDIUM

The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.0.1 due …

Jul 29, 2025
CVE-2025-26400
5.3 MEDIUM

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, …

Jul 29, 2025
CVE-2025-53082
6.1 MEDIUM

An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to …

Jul 29, 2025
CVE-2025-53081
6.4 MEDIUM

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to …

Jul 29, 2025
CVE-2025-53649
5.1 MEDIUM

"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive …

Jul 29, 2025
CVE-2025-53079
4.9 MEDIUM

Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

Jul 29, 2025
CVE-2025-53077
6.5 MEDIUM

An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the …

Jul 29, 2025
CVE-2025-4566
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element …

Jul 29, 2025
CVE-2025-4370
5.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing …

Jul 29, 2025
CVE-2025-3075
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode …

Jul 29, 2025
CVE-2025-7811
6.4 MEDIUM

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-7810
5.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-7809
6.4 MEDIUM

The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-54768
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54767
6.5 MEDIUM

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

Jul 29, 2025
CVE-2025-54766
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54765
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54423
5.4 MEDIUM

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in …

Jul 28, 2025
CVE-2025-54538
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

Jul 28, 2025
CVE-2025-54537
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

Jul 28, 2025
CVE-2025-54536
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint

Jul 28, 2025
CVE-2025-54535
5.8 MEDIUM

In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

Jul 28, 2025
CVE-2025-54534
4.8 MEDIUM

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

Jul 28, 2025
CVE-2025-54533
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

Jul 28, 2025
CVE-2025-54532
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

Jul 28, 2025
CVE-2025-54528
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

Jul 28, 2025
CVE-2025-54527
6.1 MEDIUM

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

Jul 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.