CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24292
6.8 MEDIUM

A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a …

Jun 29, 2025
CVE-2025-6868
4.7 MEDIUM

A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. …

Jun 29, 2025
CVE-2025-6867
4.7 MEDIUM

A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The …

Jun 29, 2025
CVE-2025-6866
4.3 MEDIUM

A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation …

Jun 29, 2025
CVE-2025-6865
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation …

Jun 29, 2025
CVE-2025-6864
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the …

Jun 29, 2025
CVE-2025-6862
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit_plan.php. The …

Jun 29, 2025
CVE-2025-6861
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 29, 2025
CVE-2025-6860
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 29, 2025
CVE-2025-6859
6.3 MEDIUM

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jun 29, 2025
CVE-2024-24915
6.1 MEDIUM

Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

Jun 29, 2025
CVE-2025-6855
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file …

Jun 29, 2025
CVE-2025-6854
4.3 MEDIUM

A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads …

Jun 29, 2025
CVE-2025-6853
6.3 MEDIUM

A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the …

Jun 29, 2025
CVE-2025-6850
6.3 MEDIUM

A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jun 29, 2025
CVE-2025-6848
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. …

Jun 29, 2025
CVE-2025-6847
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Forum 1.0. This vulnerability affects unknown code of the file /forum_edit.php. The manipulation of the …

Jun 29, 2025
CVE-2025-6462
6.4 MEDIUM

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all …

Jun 29, 2025
CVE-2025-6842
4.7 MEDIUM

A vulnerability was found in code-projects Product Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit_user.php. The …

Jun 29, 2025
CVE-2025-6841
4.7 MEDIUM

A vulnerability has been found in code-projects Product Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit_product.php. The …

Jun 29, 2025
CVE-2025-6839
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue …

Jun 29, 2025
CVE-2025-6837
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of the file /profile.php. The …

Jun 29, 2025
CVE-2025-6829
6.3 MEDIUM

A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function outAddress of the component External Address …

Jun 28, 2025
CVE-2025-53393
6.0 MEDIUM

In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.

Jun 28, 2025
CVE-2025-53392
5.0 MEDIUM

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is …

Jun 28, 2025
CVE-2023-29113
6.3 MEDIUM

The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with …

Jun 28, 2025
CVE-2023-28912
5.7 MEDIUM

The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access …

Jun 28, 2025
CVE-2023-28911
6.5 MEDIUM

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28908
5.4 MEDIUM

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which …

Jun 28, 2025
CVE-2023-28907
6.7 MEDIUM

There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to …

Jun 28, 2025
CVE-2023-28904
5.2 MEDIUM

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to …

Jun 28, 2025
CVE-2025-5937
4.3 MEDIUM

The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jun 28, 2025
CVE-2025-38086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nway_restart In mii_nway_restart() the code attempts to call mii->mdio_read …

Jun 28, 2025
CVE-2025-38085
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that …

Jun 28, 2025
CVE-2025-38084
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table …

Jun 28, 2025
CVE-2025-6252
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 1.9.1 …

Jun 28, 2025
CVE-2025-6350
6.4 MEDIUM

The WP VR – 360 Panorama and Free Virtual Tour Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hotspot-hover’ …

Jun 28, 2025
CVE-2025-36027
5.4 MEDIUM

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Jun 28, 2025
CVE-2025-36026
4.3 MEDIUM

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the …

Jun 28, 2025
CVE-2024-52900
6.4 MEDIUM

IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to …

Jun 28, 2025
CVE-2024-39730
5.4 MEDIUM

IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to …

Jun 28, 2025
CVE-2024-36347
6.4 MEDIUM

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in …

Jun 27, 2025
CVE-2025-53097
5.9 MEDIUM

Roo Code is an AI-powered autonomous coding agent. Prior to version 3.20.3, there was an issue where the Roo Code agent's `search_files` tool did not …

Jun 27, 2025
CVE-2025-6775
6.3 MEDIUM

A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file /app/api/v1/openvpn.py of the …

Jun 27, 2025
CVE-2025-6774
6.3 MEDIUM

A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is the function AddTemp of …

Jun 27, 2025
CVE-2025-6773
5.3 MEDIUM

A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_input_dir of …

Jun 27, 2025
CVE-2025-6522
5.4 MEDIUM

Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on …

Jun 27, 2025
CVE-2025-46708
4.3 MEDIUM

Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.

Jun 27, 2025
CVE-2025-46707
5.2 MEDIUM

Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.

Jun 27, 2025
CVE-2025-44559
6.5 MEDIUM

An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a Denial of …

Jun 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.