CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-52964
6.5 MEDIUM

A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to …

Jul 11, 2025
CVE-2025-52963
5.5 MEDIUM

An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, …

Jul 11, 2025
CVE-2025-52958
5.3 MEDIUM

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to …

Jul 11, 2025
CVE-2025-52955
6.5 MEDIUM

An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent …

Jul 11, 2025
CVE-2025-52953
6.5 MEDIUM

An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker …

Jul 11, 2025
CVE-2025-52952
6.5 MEDIUM

An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line …

Jul 11, 2025
CVE-2025-52951
5.8 MEDIUM

A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to …

Jul 11, 2025
CVE-2025-52949
6.5 MEDIUM

An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a …

Jul 11, 2025
CVE-2025-52948
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker, in rare cases, sending …

Jul 11, 2025
CVE-2025-52947
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker …

Jul 11, 2025
CVE-2025-48924
5.3 MEDIUM

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. …

Jul 11, 2025
CVE-2023-38329
6.1 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web …

Jul 11, 2025
CVE-2023-38327
5.3 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web …

Jul 11, 2025
CVE-2025-3933
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability …

Jul 11, 2025
CVE-2025-6838
4.1 MEDIUM

The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are …

Jul 11, 2025
CVE-2025-6745
5.3 MEDIUM

The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_query() function due to insufficient …

Jul 11, 2025
CVE-2025-6068
6.4 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & …

Jul 11, 2025
CVE-2025-5530
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shortcode_btn' shortcode in all versions up to, …

Jul 11, 2025
CVE-2025-4593
6.5 MEDIUM

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the …

Jul 11, 2025
CVE-2025-6716
6.4 MEDIUM

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress …

Jul 11, 2025
CVE-2025-6200
5.9 MEDIUM

The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Jul 11, 2025
CVE-2025-30024
6.8 MEDIUM

The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

Jul 11, 2025
CVE-2025-2942
4.3 MEDIUM

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing …

Jul 11, 2025
CVE-2025-53864
5.8 MEDIUM

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply …

Jul 11, 2025
CVE-2025-5241
5.3 MEDIUM

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain …

Jul 11, 2025
CVE-2025-53519
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, …

Jul 11, 2025
CVE-2025-53509
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. …

Jul 11, 2025
CVE-2025-53471
5.1 MEDIUM

Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to …

Jul 11, 2025
CVE-2025-53397
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, …

Jul 11, 2025
CVE-2025-52459
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain …

Jul 11, 2025
CVE-2025-48496
5.1 MEDIUM

Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the …

Jul 11, 2025
CVE-2025-46704
4.3 MEDIUM

A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least …

Jul 11, 2025
CVE-2025-41442
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input …

Jul 11, 2025
CVE-2025-31267
4.6 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an …

Jul 10, 2025
CVE-2025-6392
4.4 MEDIUM

Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec …

Jul 10, 2025
CVE-2025-53637
4.1 MEDIUM

Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be …

Jul 10, 2025
CVE-2025-24798
4.3 MEDIUM

Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. …

Jul 10, 2025
CVE-2025-7415
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of …

Jul 10, 2025
CVE-2025-7414
6.3 MEDIUM

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. …

Jul 10, 2025
CVE-2025-6390
4.4 MEDIUM

Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit …

Jul 10, 2025
CVE-2025-4662
4.4 MEDIUM

Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the …

Jul 10, 2025
CVE-2025-2522
6.5 MEDIUM

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit …

Jul 10, 2025
CVE-2025-7413
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/profile.php. The manipulation of …

Jul 10, 2025
CVE-2025-7412
6.3 MEDIUM

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 10, 2025
CVE-2025-7021
6.5 MEDIUM

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker …

Jul 10, 2025
CVE-2025-45662
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's …

Jul 10, 2025
CVE-2025-53709
5.4 MEDIUM

Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The service only installed on a small number of environments. …

Jul 10, 2025
CVE-2025-53626
6.1 MEDIUM

pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading …

Jul 10, 2025
CVE-2025-52473
5.9 MEDIUM

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Multiple secret-dependent branches have been identified in the reference implementation of the …

Jul 10, 2025
CVE-2025-28245
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web script or HTML via the notification body.

Jul 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.