CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-41657
4.3 MEDIUM

Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.

Jun 10, 2025
CVE-2025-5743
5.5 MEDIUM

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote control over the charging station …

Jun 10, 2025
CVE-2025-5742
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated user modifies configuration parameters on the web server

Jun 10, 2025
CVE-2025-5741
4.9 MEDIUM

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file reads from the charging station. The …

Jun 10, 2025
CVE-2025-3905
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting PLC system variables that could cause an unvalidated data injected by …

Jun 10, 2025
CVE-2025-3899
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Certificates page on Webserver that could cause an unvalidated data injected …

Jun 10, 2025
CVE-2025-3898
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request containing invalid data type to …

Jun 10, 2025
CVE-2025-3117
5.4 MEDIUM

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting configuration file paths that could cause an unvalidated data injected by …

Jun 10, 2025
CVE-2025-3116
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted …

Jun 10, 2025
CVE-2025-3112
6.5 MEDIUM

CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated malicious user sends manipulated HTTPS Content-Length header to the webserver.

Jun 10, 2025
CVE-2025-5935
5.3 MEDIUM

A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the …

Jun 10, 2025
CVE-2025-3076
6.4 MEDIUM

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions up to, and including, …

Jun 10, 2025
CVE-2025-5925
4.3 MEDIUM

The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.95. This is due to …

Jun 10, 2025
CVE-2025-42998
5.3 MEDIUM

The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted …

Jun 10, 2025
CVE-2025-42996
5.6 MEDIUM

SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to …

Jun 10, 2025
CVE-2025-42993
6.7 MEDIUM

Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an …

Jun 10, 2025
CVE-2025-42991
4.3 MEDIUM

SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'approver' user to delete attachment from bank account application of …

Jun 10, 2025
CVE-2025-42987
4.3 MEDIUM

SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. …

Jun 10, 2025
CVE-2025-42984
5.4 MEDIUM

SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function …

Jun 10, 2025
CVE-2025-31325
5.8 MEDIUM

Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an …

Jun 10, 2025
CVE-2025-0037
6.6 MEDIUM

In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated …

Jun 10, 2025
CVE-2025-30507
5.3 MEDIUM

CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.

Jun 9, 2025
CVE-2025-5900
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. …

Jun 9, 2025
CVE-2025-5899
5.3 MEDIUM

A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation …

Jun 9, 2025
CVE-2025-5898
5.3 MEDIUM

A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to …

Jun 9, 2025
CVE-2025-5897
4.3 MEDIUM

A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file …

Jun 9, 2025
CVE-2025-5896
4.3 MEDIUM

A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. …

Jun 9, 2025
CVE-2025-49139
5.3 MEDIUM

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can …

Jun 9, 2025
CVE-2025-49138
6.5 MEDIUM

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability …

Jun 9, 2025
CVE-2025-5915
6.6 MEDIUM

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter …

Jun 9, 2025
CVE-2025-5895
4.3 MEDIUM

A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads …

Jun 9, 2025
CVE-2025-5892
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. …

Jun 9, 2025
CVE-2025-5891
4.3 MEDIUM

A vulnerability classified as problematic was found in Unitech pm2 up to 6.0.6. This vulnerability affects unknown code of the file /lib/tools/Config.js. The manipulation leads …

Jun 9, 2025
CVE-2025-5890
4.3 MEDIUM

A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. …

Jun 9, 2025
CVE-2025-5888
4.3 MEDIUM

A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads …

Jun 9, 2025
CVE-2024-47081
5.3 MEDIUM

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific …

Jun 9, 2025
CVE-2025-46041
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation …

Jun 9, 2025
CVE-2025-45002
5.4 MEDIUM

Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my profile.

Jun 9, 2025
CVE-2025-29627
6.8 MEDIUM

An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module

Jun 9, 2025
CVE-2024-46452
6.1 MEDIUM

A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b allows attackers to redirect victim users to …

Jun 9, 2025
CVE-2025-48147
6.5 MEDIUM

Missing Authorization vulnerability in Crypto Cloud CryptoCloud - Crypto Payment Gateway cryptocloud-crypto-payment-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CryptoCloud - Crypto …

Jun 9, 2025
CVE-2025-48139
6.5 MEDIUM

Missing Authorization vulnerability in relentlo StyleAI relentlosoftware allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects StyleAI: from n/a through <= 1.0.4.

Jun 9, 2025
CVE-2025-47598
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in click5 History Log by click5 history-log-by-click5 allows Stored XSS.This issue affects History Log …

Jun 9, 2025
CVE-2025-47511
6.8 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Path Traversal.This issue affects Welcart e-Commerce: from …

Jun 9, 2025
CVE-2025-46178
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in …

Jun 9, 2025
CVE-2025-45055
5.4 MEDIUM

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an …

Jun 9, 2025
CVE-2025-5885
4.3 MEDIUM

A vulnerability has been found in Konica Minolta bizhub up to 20250202 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to …

Jun 9, 2025
CVE-2025-5881
6.3 MEDIUM

A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. …

Jun 9, 2025
CVE-2025-5880
4.3 MEDIUM

A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the …

Jun 9, 2025
CVE-2025-5877
6.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the …

Jun 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.