CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-36056
5.4 MEDIUM

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable …

Jul 1, 2025
CVE-2025-2141
6.1 MEDIUM

IBM System Storage Virtualization Engine TS7700 3957 VED R5.4 8.54.2.17, R6.0 8.60.0.115, 3948 VED R5.4 8.54.2.17, R6.0 8.60.0.115, and 3948 VEF R6.0 8.60.0.115 is vulnerable …

Jul 1, 2025
CVE-2025-6930
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/manage-foreigners-ticket.php. The manipulation …

Jun 30, 2025
CVE-2025-6929
6.3 MEDIUM

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-52997
5.9 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52901
4.5 MEDIUM

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-52491
5.8 MEDIUM

Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

Jun 30, 2025
CVE-2025-49493
5.8 MEDIUM

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

Jun 30, 2025
CVE-2025-6925
5.3 MEDIUM

A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java …

Jun 30, 2025
CVE-2025-6915
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by this issue is some unknown functionality of …

Jun 30, 2025
CVE-2025-52896
5.4 MEDIUM

Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading …

Jun 30, 2025
CVE-2025-47871
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving …

Jun 30, 2025
CVE-2025-46702
5.4 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions …

Jun 30, 2025
CVE-2025-6914
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability is an unknown functionality of the file /edit-student.php. …

Jun 30, 2025
CVE-2025-6913
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation …

Jun 30, 2025
CVE-2024-12915
4.6 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS.This issue affects Library Software: …

Jun 30, 2025
CVE-2025-6912
6.3 MEDIUM

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-6911
6.3 MEDIUM

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /manage-subjects.php. …

Jun 30, 2025
CVE-2025-2895
5.4 MEDIUM

IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote attacker could inject …

Jun 30, 2025
CVE-2023-47310
6.5 MEDIUM

A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.

Jun 30, 2025
CVE-2025-6910
6.3 MEDIUM

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been classified as critical. This affects an unknown part of the file /session.php. …

Jun 30, 2025
CVE-2025-6909
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Jun 30, 2025
CVE-2025-6908
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file …

Jun 30, 2025
CVE-2025-4407
6.7 MEDIUM

Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.

Jun 30, 2025
CVE-2025-41439
6.1 MEDIUM

A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary …

Jun 30, 2025
CVE-2025-6900
6.3 MEDIUM

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-book.php. The manipulation …

Jun 30, 2025
CVE-2025-6899
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file msp_info.htm. The …

Jun 30, 2025
CVE-2025-40734
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through …

Jun 30, 2025
CVE-2025-40733
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through …

Jun 30, 2025
CVE-2025-6898
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionality of the file …

Jun 30, 2025
CVE-2025-6897
5.5 MEDIUM

A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the file httpd_debug.asp. The manipulation …

Jun 30, 2025
CVE-2025-38090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drivers/rapidio/rio_cm.c: prevent possible heap overwrite In riocm_cdev_ioctl(RIO_CM_CHAN_SEND) -> cm_chan_msg_send() -> riocm_ch_send() cm_chan_msg_send() checks that userspace …

Jun 30, 2025
CVE-2025-38089
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error tianshuo han reported a remotely-triggerable …

Jun 30, 2025
CVE-2025-6896
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The manipulation of the …

Jun 30, 2025
CVE-2025-6890
6.3 MEDIUM

A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-5730
4.3 MEDIUM

The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jun 30, 2025
CVE-2025-3745
6.3 MEDIUM

The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may …

Jun 30, 2025
CVE-2025-6884
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-6883
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Staff Audit System 1.0. This vulnerability affects unknown code of the file /update_index.php. The manipulation of …

Jun 30, 2025
CVE-2025-6880
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-tax.php. The …

Jun 30, 2025
CVE-2025-6879
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 30, 2025
CVE-2025-6878
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 30, 2025
CVE-2025-6877
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jun 30, 2025
CVE-2025-6876
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jun 29, 2025
CVE-2025-6875
6.3 MEDIUM

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jun 29, 2025
CVE-2025-6874
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/add_subscribe.php. …

Jun 29, 2025
CVE-2025-6873
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file …

Jun 29, 2025
CVE-2025-6872
4.7 MEDIUM

A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of …

Jun 29, 2025
CVE-2025-6870
4.7 MEDIUM

A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jun 29, 2025
CVE-2025-6869
4.7 MEDIUM

A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.