CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49973
4.3 MEDIUM

Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue …

Jun 20, 2025
CVE-2025-49972
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy tm-replace-howdy allows Cross Site Request Forgery.This issue affects TM Replace Howdy: from n/a through …

Jun 20, 2025
CVE-2025-49971
4.3 MEDIUM

Missing Authorization vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eDS Responsive Menu: from n/a …

Jun 20, 2025
CVE-2025-49970
4.3 MEDIUM

Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE Blog: from n/a through …

Jun 20, 2025
CVE-2025-49969
4.3 MEDIUM

Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression zara-4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zara 4 Image Compression: …

Jun 20, 2025
CVE-2025-49968
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Oganro XML Travel Portal Widget oganro-reservation-widget allows Cross Site Request Forgery.This issue affects XML Travel Portal Widget: from n/a …

Jun 20, 2025
CVE-2025-49967
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder live-sports-streamthunder allows Cross Site Request Forgery.This issue affects Live Sports Streamthunder: from n/a through <= …

Jun 20, 2025
CVE-2025-49966
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Oganro Oganro Travel Portal Search Widget for HotelBeds APITUDE API oganro-travel-portal-search-widget-for-hotelbeds-apitude-api allows Cross Site Request Forgery.This issue affects Oganro …

Jun 20, 2025
CVE-2025-49965
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Oganro PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-channel-manager-booking-engine allows Cross Site Request Forgery.This issue affects PixelBeds Channel Manager …

Jun 20, 2025
CVE-2025-49964
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in indgeek ClipLink cliplink allows Cross Site Request Forgery.This issue affects ClipLink: from n/a through <= 1.1.

Jun 20, 2025
CVE-2025-3228
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler …

Jun 20, 2025
CVE-2025-3227
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions …

Jun 20, 2025
CVE-2025-32876
6.8 MEDIUM

An issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE Secure Connections and …

Jun 20, 2025
CVE-2025-32875
5.7 MEDIUM

An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. …

Jun 20, 2025
CVE-2025-32753
5.3 MEDIUM

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged …

Jun 20, 2025
CVE-2024-7586
4.1 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from …

Jun 20, 2025
CVE-2025-6341
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request …

Jun 20, 2025
CVE-2025-38083
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: prio: fix a race in prio_tune() Gerrard Tai reported a race condition in PRIO, …

Jun 20, 2025
CVE-2025-6335
4.7 MEDIUM

A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of the file /include/dedetag.class.php of the …

Jun 20, 2025
CVE-2025-6333
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/admin-profile.php. The …

Jun 20, 2025
CVE-2025-6332
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of …

Jun 20, 2025
CVE-2025-6331
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-directory.php. …

Jun 20, 2025
CVE-2025-6329
5.4 MEDIUM

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 20, 2025
CVE-2025-6321
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 20, 2025
CVE-2025-6320
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System 1.0. Affected is an unknown function of the file /admin/add-class.php. The …

Jun 20, 2025
CVE-2025-6257
6.4 MEDIUM

The Euro FxRef Currency Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currency shortcode in all versions up to, and …

Jun 20, 2025
CVE-2025-6319
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. This issue affects some unknown processing of the file …

Jun 20, 2025
CVE-2025-50054
5.5 MEDIUM

Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control …

Jun 20, 2025
CVE-2025-5125
4.8 MEDIUM

The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using …

Jun 20, 2025
CVE-2025-6309
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 20, 2025
CVE-2025-6308
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/bwdates-request-report-details.php. The …

Jun 20, 2025
CVE-2025-6299
4.7 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the …

Jun 20, 2025
CVE-2025-6264
5.5 MEDIUM

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. …

Jun 20, 2025
CVE-2025-6285
4.3 MEDIUM

A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This issue affects some unknown processing of the …

Jun 19, 2025
CVE-2025-6284
4.3 MEDIUM

A vulnerability was found in PHPGurukul Car Rental Portal 3.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to …

Jun 19, 2025
CVE-2025-6282
5.5 MEDIUM

A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critical. Affected by this issue is the function create_upload_file of the file …

Jun 19, 2025
CVE-2025-6281
5.5 MEDIUM

A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 19, 2025
CVE-2025-6280
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function download_attachment of the file SuperAGI/superagi/helper/read_email.py of …

Jun 19, 2025
CVE-2025-6279
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool …

Jun 19, 2025
CVE-2025-6278
5.5 MEDIUM

A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the file markdown/server.py. The manipulation of …

Jun 19, 2025
CVE-2025-6277
6.3 MEDIUM

A vulnerability classified as critical has been found in Brilliance Golden Link Secondary System up to 20250609. This affects an unknown part of the file …

Jun 19, 2025
CVE-2025-6276
6.3 MEDIUM

A vulnerability was found in Brilliance Golden Link Secondary System up to 20250609. It has been rated as critical. Affected by this issue is some …

Jun 19, 2025
CVE-2025-36050
6.2 MEDIUM

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.

Jun 19, 2025
CVE-2025-6270
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5FS__sect_find_node of the …

Jun 19, 2025
CVE-2025-50200
5.5 MEDIUM

RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ …

Jun 19, 2025
CVE-2025-6269
5.3 MEDIUM

A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5C__reconstruct_cache_entry of the file H5Cimage.c. The …

Jun 19, 2025
CVE-2025-6268
4.3 MEDIUM

A vulnerability classified as problematic has been found in Luna Imaging up to 7.5.5.6. Affected is an unknown function of the file /luna/servlet/view/search. The manipulation …

Jun 19, 2025
CVE-2025-48886
4.8 MEDIUM

Hydra is a layer-two scalability solution for Cardano. Prior to version 0.22.0, the process assumes L1 event finality and does not consider failed transactions. Currently, …

Jun 19, 2025
CVE-2025-6267
6.3 MEDIUM

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated as critical. This issue affects some unknown processing …

Jun 19, 2025
CVE-2024-24916
6.5 MEDIUM

Untrusted DLLs in the installer's directory may be loaded and executed, leading to potentially arbitrary code execution with the installer's privileges (admin).

Jun 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.