CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7789
3.7 LOW

A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file …

Jul 18, 2025
CVE-2025-7786
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file …

Jul 18, 2025
CVE-2025-6227
2.2 LOW

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both …

Jul 18, 2025
CVE-2025-7767
3.5 LOW

A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Affected by this issue is some unknown functionality …

Jul 18, 2025
CVE-2025-2818
3.5 LOW

A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby …

Jul 17, 2025
CVE-2024-42209
3.5 LOW

HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user to obtain sensitive information they are not entitled to, which is …

Jul 17, 2025
CVE-2025-7748
3.5 LOW

A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the component Create Article Page. The manipulation of the …

Jul 17, 2025
CVE-2025-7339
3.4 LOW

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being …

Jul 17, 2025
CVE-2025-7729
3.5 LOW

A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The …

Jul 17, 2025
CVE-2025-7728
3.5 LOW

A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of the file users.shtm. The manipulation of …

Jul 17, 2025
CVE-2025-53840
2.4 LOW

Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency …

Jul 16, 2025
CVE-2025-7703
3.1 LOW

Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.

Jul 16, 2025
CVE-2025-52687
2.4 LOW

Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web …

Jul 16, 2025
CVE-2025-53029
2.3 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high …

Jul 15, 2025
CVE-2025-50104
2.7 LOW

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability …

Jul 15, 2025
CVE-2025-50100
2.2 LOW

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Difficult to …

Jul 15, 2025
CVE-2025-50098
2.7 LOW

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Easily exploitable vulnerability …

Jul 15, 2025
CVE-2025-50081
3.1 LOW

Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and 9.0.0-9.3.0. Difficult to exploit …

Jul 15, 2025
CVE-2025-50066
2.7 LOW

Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability …

Jul 15, 2025
CVE-2025-50065
3.7 LOW

Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version that is affected is Oracle GraalVM for …

Jul 15, 2025
CVE-2025-30752
3.7 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle …

Jul 15, 2025
CVE-2025-30750
2.4 LOW

Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high …

Jul 15, 2025
CVE-2025-53019
3.7 LOW

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, …

Jul 14, 2025
CVE-2025-53014
3.7 LOW

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in …

Jul 14, 2025
CVE-2025-7601
3.5 LOW

A vulnerability has been found in PHPGurukul Online Library Management System 3.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/student-history.php. …

Jul 14, 2025
CVE-2025-7577
3.7 LOW

A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problematic. This affects an unknown part. …

Jul 14, 2025
CVE-2025-7569
3.5 LOW

A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerability is the function parse_args of …

Jul 14, 2025
CVE-2025-7554
2.4 LOW

A vulnerability classified as problematic was found in Sapido RB-1802 1.0.32. This vulnerability affects unknown code of the file urlfilter.asp of the component URL Filtering …

Jul 14, 2025
CVE-2025-1220
3.7 LOW

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does …

Jul 13, 2025
CVE-2025-7485
3.3 LOW

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler of the component SCTP Partial …

Jul 12, 2025
CVE-2025-7464
3.7 LOW

A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR of the file pkg/packet/rtr/rtr.go. The manipulation …

Jul 12, 2025
CVE-2025-7453
3.7 LOW

A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file …

Jul 11, 2025
CVE-2025-51591
3.7 LOW

A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. …

Jul 11, 2025
CVE-2025-53862
3.5 LOW

A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data …

Jul 11, 2025
CVE-2025-53861
3.1 LOW

A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing …

Jul 11, 2025
CVE-2025-7435
3.5 LOW

A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file …

Jul 11, 2025
CVE-2025-49462
3.5 LOW

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.

Jul 10, 2025
CVE-2025-27889
3.4 LOW

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If …

Jul 10, 2025
CVE-2025-7408
3.5 LOW

A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/templates/animal_form_template.php. The …

Jul 10, 2025
CVE-2025-27613
3.6 LOW

Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, …

Jul 10, 2025
CVE-2025-6168
2.7 LOW

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers …

Jul 10, 2025
CVE-2025-4972
2.7 LOW

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users …

Jul 10, 2025
CVE-2023-50458
3.5 LOW

In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

Jul 10, 2025
CVE-2025-7215
1.6 LOW

A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of …

Jul 9, 2025
CVE-2025-7214
1.6 LOW

A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is an unknown functionality of the file /etc/shadow …

Jul 9, 2025
CVE-2025-7209
3.3 LOW

A vulnerability has been found in 9fans plan9port up to 9da5b44 and classified as problematic. Affected by this vulnerability is the function value_decode in the …

Jul 9, 2025
CVE-2025-7207
3.3 LOW

A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the …

Jul 9, 2025
CVE-2025-49546
2.4 LOW

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged …

Jul 8, 2025
CVE-2025-49760
3.5 LOW

External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.

Jul 8, 2025
CVE-2025-49756
3.3 LOW

Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.