CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29744
5.4 MEDIUM

pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.

Jun 12, 2025
CVE-2024-44906
6.5 MEDIUM

uptrace pgdriver v1.2.1 was discovered to contain a SQL injection vulnerability via the appendArg function in /pgdriver/format.go. The maintainer has stated that the issue is …

Jun 12, 2025
CVE-2024-44905
6.5 MEDIUM

go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.

Jun 12, 2025
CVE-2025-49200
6.5 MEDIUM

The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.

Jun 12, 2025
CVE-2025-49197
6.5 MEDIUM

The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.

Jun 12, 2025
CVE-2025-49196
6.5 MEDIUM

A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways …

Jun 12, 2025
CVE-2025-49195
5.3 MEDIUM

The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.

Jun 12, 2025
CVE-2025-49193
4.2 MEDIUM

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application …

Jun 12, 2025
CVE-2025-49192
4.3 MEDIUM

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking …

Jun 12, 2025
CVE-2025-49191
4.8 MEDIUM

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible …

Jun 12, 2025
CVE-2025-49190
4.3 MEDIUM

The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.

Jun 12, 2025
CVE-2025-49189
5.3 MEDIUM

The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag …

Jun 12, 2025
CVE-2025-49188
5.3 MEDIUM

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

Jun 12, 2025
CVE-2025-49187
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Jun 12, 2025
CVE-2025-49186
5.3 MEDIUM

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

Jun 12, 2025
CVE-2025-49185
5.5 MEDIUM

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function …

Jun 12, 2025
CVE-2024-9512
5.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may …

Jun 12, 2025
CVE-2025-5195
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible …

Jun 12, 2025
CVE-2025-5996
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of …

Jun 12, 2025
CVE-2025-1516
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation …

Jun 12, 2025
CVE-2025-1478
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of …

Jun 12, 2025
CVE-2025-6003
5.3 MEDIUM

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions …

Jun 12, 2025
CVE-2025-5301
6.1 MEDIUM

ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. …

Jun 12, 2025
CVE-2025-40592
6.1 MEDIUM

A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All versions < V10.12.17), Mendix Studio Pro …

Jun 12, 2025
CVE-2025-6009
4.7 MEDIUM

A vulnerability was found in kiCode111 like-girl 5.2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ipAddPost.php. The …

Jun 12, 2025
CVE-2025-6008
4.7 MEDIUM

A vulnerability has been found in kiCode111 like-girl 5.2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ImgAddPost.php. …

Jun 12, 2025
CVE-2025-6007
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in kiCode111 like-girl 5.2.0. Affected is an unknown function of the file /admin/CopyadminPost.php. The manipulation of …

Jun 12, 2025
CVE-2025-6006
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in kiCode111 like-girl 5.2.0. This issue affects some unknown processing of the file /admin/ImgUpdaPost.php. The …

Jun 12, 2025
CVE-2025-6005
4.7 MEDIUM

A vulnerability classified as critical was found in kiCode111 like-girl 5.2.0. This vulnerability affects unknown code of the file /admin/aboutPost.php. The manipulation of the argument …

Jun 12, 2025
CVE-2025-49150
5.9 MEDIUM

Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enable was set to True. This means that …

Jun 11, 2025
CVE-2025-0923
5.3 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in …

Jun 11, 2025
CVE-2025-0917
5.5 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged …

Jun 11, 2025
CVE-2025-0913
5.5 MEDIUM

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL …

Jun 11, 2025
CVE-2025-4673
6.8 MEDIUM

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Jun 11, 2025
CVE-2025-48448
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.

Jun 11, 2025
CVE-2025-48444
5.3 MEDIUM

Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.

Jun 11, 2025
CVE-2025-48013
5.3 MEDIUM

Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0.

Jun 11, 2025
CVE-2025-3473
6.7 MEDIUM

IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.

Jun 11, 2025
CVE-2025-0163
5.3 MEDIUM

IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of …

Jun 11, 2025
CVE-2025-4605
6.6 MEDIUM

A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to …

Jun 11, 2025
CVE-2025-35941
5.5 MEDIUM

A password is exposed locally.

Jun 11, 2025
CVE-2025-5144
6.4 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 …

Jun 11, 2025
CVE-2025-5986
6.5 MEDIUM

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even …

Jun 11, 2025
CVE-2025-4573
4.1 MEDIUM

Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated …

Jun 11, 2025
CVE-2025-26412
6.8 MEDIUM

The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker …

Jun 11, 2025
CVE-2024-35295
6.1 MEDIUM

A vulnerability has been identified in Perfect Harmony GH180 (All versions >= V8.0 < V8.3.3 with NXGPro+ controller manufactured between April 2020 to April 2025). …

Jun 11, 2025
CVE-2025-4798
4.9 MEDIUM

The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack …

Jun 11, 2025
CVE-2025-4666
6.4 MEDIUM

The Zotpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nickname’ parameter in all versions up to, and including, 7.3.15 due to …

Jun 11, 2025
CVE-2025-30675
4.7 MEDIUM

In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A malicious Domain Admin or Resource Admin can exploit this issue …

Jun 11, 2025
CVE-2025-1055
5.6 MEDIUM

A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate …

Jun 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.