CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6566
5.3 MEDIUM

A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the function deserializeArray of the file …

Jun 24, 2025
CVE-2025-6434
4.3 MEDIUM

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick …

Jun 24, 2025
CVE-2025-6431
6.5 MEDIUM

When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could …

Jun 24, 2025
CVE-2025-6430
6.1 MEDIUM

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` …

Jun 24, 2025
CVE-2025-6429
6.5 MEDIUM

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could …

Jun 24, 2025
CVE-2025-6428
4.3 MEDIUM

When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to …

Jun 24, 2025
CVE-2025-6425
4.3 MEDIUM

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private …

Jun 24, 2025
CVE-2025-39205
6.5 MEDIUM

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to …

Jun 24, 2025
CVE-2025-39204
6.5 MEDIUM

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning …

Jun 24, 2025
CVE-2025-39203
6.5 MEDIUM

A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can …

Jun 24, 2025
CVE-2025-39201
6.1 MEDIUM

A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of …

Jun 24, 2025
CVE-2025-1718
6.5 MEDIUM

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk …

Jun 24, 2025
CVE-2025-5258
6.4 MEDIUM

The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due …

Jun 24, 2025
CVE-2025-43877
5.4 MEDIUM

WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be executed on the web browser of the user who …

Jun 24, 2025
CVE-2025-36519
4.3 MEDIUM

Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially …

Jun 24, 2025
CVE-2025-47943
6.3 MEDIUM

Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, …

Jun 24, 2025
CVE-2025-6552
4.3 MEDIUM

A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the …

Jun 24, 2025
CVE-2025-48470
4.1 MEDIUM

Successful exploitation of the stored cross-site scripting vulnerability could allow an attacker to inject malicious scripts into device fields and executed in other users’ browser, …

Jun 24, 2025
CVE-2025-48468
6.4 MEDIUM

Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.

Jun 24, 2025
CVE-2025-48467
6.5 MEDIUM

Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to remote denial-of-service and system unavailability.

Jun 24, 2025
CVE-2025-48462
4.2 MEDIUM

Successful exploitation of the vulnerability could allow an attacker to consume all available session slots and block other users from logging in, thereby preventing legitimate …

Jun 24, 2025
CVE-2025-48461
5.0 MEDIUM

Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially …

Jun 24, 2025
CVE-2025-6535
6.3 MEDIUM

A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file novel-admin/src/main/resources/mybatis/system/UserMapper.xml …

Jun 24, 2025
CVE-2025-6534
4.2 MEDIUM

A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/controller/FileController.java of …

Jun 24, 2025
CVE-2025-34032
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application …

Jun 24, 2025
CVE-2025-6533
5.6 MEDIUM

A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of …

Jun 24, 2025
CVE-2025-6532
4.3 MEDIUM

A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerability is an unknown functionality of the component …

Jun 24, 2025
CVE-2025-6531
4.3 MEDIUM

A vulnerability was found in SIFUSM/MZZYG BD S1 up to 20250611. It has been declared as problematic. This vulnerability affects unknown code of the component …

Jun 24, 2025
CVE-2025-6530
4.8 MEDIUM

A vulnerability was found in 70mai M300 up to 20250611. It has been classified as problematic. This affects an unknown part of the file demo.sh …

Jun 23, 2025
CVE-2025-6528
4.3 MEDIUM

A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jun 23, 2025
CVE-2025-6525
4.3 MEDIUM

A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code of the file /cgi-bin/Config.cgi?action=set of the component …

Jun 23, 2025
CVE-2025-49574
6.4 MEDIUM

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. In versions prior to 3.24.1, 3.20.2, and 3.15.6, there is a potential …

Jun 23, 2025
CVE-2021-47688
5.7 MEDIUM

In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be …

Jun 23, 2025
CVE-2025-6518
6.3 MEDIUM

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py …

Jun 23, 2025
CVE-2025-6517
6.3 MEDIUM

A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.java of …

Jun 23, 2025
CVE-2025-6516
5.3 MEDIUM

A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5F_addr_decode_len of the file /hdf5/src/H5Fint.c. The …

Jun 23, 2025
CVE-2025-52967
5.8 MEDIUM

gateway_proxy_handler in MLflow before 3.1.0 lacks gateway_path validation.

Jun 23, 2025
CVE-2025-52879
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible

Jun 23, 2025
CVE-2025-52878
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions

Jun 23, 2025
CVE-2025-52877
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

Jun 23, 2025
CVE-2025-52876
5.4 MEDIUM

In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

Jun 23, 2025
CVE-2025-52875
5.4 MEDIUM

In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible

Jun 23, 2025
CVE-2025-48700
6.1 MEDIUM KEV

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI …

Jun 23, 2025
CVE-2023-47298
4.3 MEDIUM

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of …

Jun 23, 2025
CVE-2025-52920
6.4 MEDIUM

Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit …

Jun 23, 2025
CVE-2024-3511
4.3 MEDIUM

An incorrect authorization vulnerability exists in multiple WSO2 products that allows unauthorized access to versioned files stored in the registry. Due to flawed authorization logic, …

Jun 23, 2025
CVE-2025-6493
5.3 MEDIUM

A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/markdown.js of the component Markdown Mode. This …

Jun 22, 2025
CVE-2025-6492
5.3 MEDIUM

A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is the function getRecommendTitleFromMarkdownString of the file …

Jun 22, 2025
CVE-2025-6485
6.3 MEDIUM

A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation …

Jun 22, 2025
CVE-2025-6484
4.7 MEDIUM

A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.