CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-51660
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.

Jul 14, 2025
CVE-2025-51659
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.

Jul 14, 2025
CVE-2025-51658
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.

Jul 14, 2025
CVE-2025-51657
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.

Jul 14, 2025
CVE-2025-51656
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.

Jul 14, 2025
CVE-2025-51655
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.

Jul 14, 2025
CVE-2025-51654
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.

Jul 14, 2025
CVE-2025-51653
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.

Jul 14, 2025
CVE-2025-51652
5.4 MEDIUM

SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.

Jul 14, 2025
CVE-2025-51651
5.5 MEDIUM

An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.

Jul 14, 2025
CVE-2025-51650
5.6 MEDIUM

An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.

Jul 14, 2025
CVE-2024-42649
6.5 MEDIUM

NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

Jul 14, 2025
CVE-2024-42648
6.5 MEDIUM

NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

Jul 14, 2025
CVE-2025-7616
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of …

Jul 14, 2025
CVE-2025-7615
6.3 MEDIUM

A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file /cgi-bin/cstecgi.cgi of the …

Jul 14, 2025
CVE-2025-7614
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi of the component HTTP …

Jul 14, 2025
CVE-2025-7613
6.3 MEDIUM

A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file /cgi-bin/cstecgi.cgi of …

Jul 14, 2025
CVE-2025-7519
6.7 MEDIUM

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. …

Jul 14, 2025
CVE-2025-7600
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Online Library Management System 3.0. This affects an unknown part of the file /admin/student-history.php. …

Jul 14, 2025
CVE-2025-7599
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected by this issue is some unknown …

Jul 14, 2025
CVE-2025-7592
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality …

Jul 14, 2025
CVE-2025-7591
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected is an unknown function of the file …

Jul 14, 2025
CVE-2025-7590
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This issue affects some unknown processing of …

Jul 14, 2025
CVE-2025-7589
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Dairy Farm Shop Management System 1.3. This vulnerability affects unknown code of the file edit-company.php. The …

Jul 14, 2025
CVE-2025-7588
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This affects an unknown part of the file edit-product.php. …

Jul 14, 2025
CVE-2025-24391
5.3 MEDIUM

A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and …

Jul 14, 2025
CVE-2025-7585
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. Affected is an unknown function of the file …

Jul 14, 2025
CVE-2025-7584
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This issue affects some unknown processing of the file /admin/add-team.php. …

Jul 14, 2025
CVE-2025-7583
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This vulnerability affects unknown code of the file /admin/all-requests.php. …

Jul 14, 2025
CVE-2025-7582
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Online Fire Reporting System 1.2. This affects an unknown part of the file /admin/assigned-requests.php. …

Jul 14, 2025
CVE-2025-7581
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Voting System 1.0. Affected by this issue is some unknown functionality of the …

Jul 14, 2025
CVE-2025-7580
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/positions_row.php. The …

Jul 14, 2025
CVE-2025-7579
4.3 MEDIUM

A vulnerability was found in chinese-poetry 0.1. It has been rated as problematic. This issue affects some unknown processing of the file rank/server.js. The manipulation …

Jul 14, 2025
CVE-2025-7578
5.0 MEDIUM

A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been declared as critical. This vulnerability affects the function …

Jul 14, 2025
CVE-2025-7575
4.7 MEDIUM

A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerability is the function image_drop_upload_ajax/image_delete_ajax of the …

Jul 14, 2025
CVE-2025-7573
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This issue affects …

Jul 14, 2025
CVE-2025-7572
5.3 MEDIUM

A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This vulnerability affects the function bs_GetHostInfo …

Jul 14, 2025
CVE-2025-29606
4.3 MEDIUM

py-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key.

Jul 14, 2025
CVE-2025-7568
6.3 MEDIUM

A vulnerability was found in qianfox FoxCMS up to 1.2.5. It has been classified as critical. Affected is the function batchCope of the file app/admin/controller/Video.php. …

Jul 14, 2025
CVE-2025-7567
4.3 MEDIUM

A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processing of the file header.html. The manipulation …

Jul 14, 2025
CVE-2025-7566
4.7 MEDIUM

A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file /src/main/java/com/jsh/erp/controller/SystemConfigController.java. The …

Jul 14, 2025
CVE-2025-7565
5.3 MEDIUM

A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi-bin/lighttpd.cgi of …

Jul 14, 2025
CVE-2025-7563
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file …

Jul 14, 2025
CVE-2025-7562
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System 1.2. Affected is an unknown function of the file /admin/new-requests.php. The …

Jul 14, 2025
CVE-2025-7561
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been rated as critical. This issue affects some unknown processing of the …

Jul 14, 2025
CVE-2025-7560
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 14, 2025
CVE-2025-7559
6.3 MEDIUM

A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. This affects an unknown part of the file …

Jul 14, 2025
CVE-2025-7558
6.3 MEDIUM

A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/positions_add.php. …

Jul 14, 2025
CVE-2025-7557
6.3 MEDIUM

A vulnerability has been found in code-projects Voting System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jul 14, 2025
CVE-2025-7556
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Voting System 1.0. Affected is an unknown function of the file /admin/voters_edit.php. The manipulation …

Jul 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.