CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49131
6.3 MEDIUM

FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-sandbox) is a …

Jun 9, 2025
CVE-2025-40669
6.5 MEDIUM

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including …

Jun 9, 2025
CVE-2025-40668
6.5 MEDIUM

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a …

Jun 9, 2025
CVE-2025-5876
5.3 MEDIUM

A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability is an unknown functionality. The …

Jun 9, 2025
CVE-2025-5874
4.6 MEDIUM

A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as problematic. This issue affects the function run_query of the file /query_runner/python.py …

Jun 9, 2025
CVE-2025-5873
6.3 MEDIUM

A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmware.php …

Jun 9, 2025
CVE-2025-41437
4.3 MEDIUM

Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.

Jun 9, 2025
CVE-2025-5872
5.3 MEDIUM

A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting …

Jun 9, 2025
CVE-2025-5871
5.3 MEDIUM

A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality of the component …

Jun 9, 2025
CVE-2025-40675
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser …

Jun 9, 2025
CVE-2025-4652
6.1 MEDIUM

The Broadstreet WordPress plugin before 1.51.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jun 9, 2025
CVE-2025-47712
6.5 MEDIUM

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status …

Jun 9, 2025
CVE-2025-47711
6.5 MEDIUM

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific …

Jun 9, 2025
CVE-2025-3582
4.8 MEDIUM

The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin …

Jun 9, 2025
CVE-2025-3581
4.8 MEDIUM

The Newsletter WordPress plugin before 8.8.5 does not validate and escape some of its Widget options before outputting them back in a page/post where the …

Jun 9, 2025
CVE-2025-25209
5.7 MEDIUM

The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes, however it assumes those secretes are already in the kuadrant-system instead …

Jun 9, 2025
CVE-2025-25208
5.7 MEDIUM

A Developer persona can bring down the Authorino service, preventing the evaluation of all AuthPolicies on the cluster

Jun 9, 2025
CVE-2025-25207
5.7 MEDIUM

The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona …

Jun 9, 2025
CVE-2025-5859
6.3 MEDIUM

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Jun 9, 2025
CVE-2025-5858
6.3 MEDIUM

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Jun 9, 2025
CVE-2025-5857
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /urinalysis_record.php. …

Jun 9, 2025
CVE-2025-27247
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

Jun 8, 2025
CVE-2025-27131
6.1 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

Jun 8, 2025
CVE-2025-26691
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

Jun 8, 2025
CVE-2025-24493
5.5 MEDIUM

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.

Jun 8, 2025
CVE-2025-38003
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is …

Jun 8, 2025
CVE-2025-5838
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file …

Jun 7, 2025
CVE-2025-5837
6.3 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The …

Jun 7, 2025
CVE-2025-5836
6.3 MEDIUM

A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of …

Jun 7, 2025
CVE-2025-5568
6.4 MEDIUM

The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient …

Jun 7, 2025
CVE-2025-5528
6.1 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up …

Jun 7, 2025
CVE-2024-9994
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2025
CVE-2024-9993
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jun 7, 2025
CVE-2025-5814
5.3 MEDIUM

The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jun 7, 2025
CVE-2025-49128
4.0 MEDIUM

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a …

Jun 6, 2025
CVE-2025-49599
4.1 MEDIUM

Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V5R021C00S184 allow the Epuser account to disable ONT firewall functionality, e.g., to …

Jun 6, 2025
CVE-2025-5784
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the file /myexp.php. …

Jun 6, 2025
CVE-2025-5783
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Employee Record Management System 1.3. This affects an unknown part of the file /editmyexp.php. …

Jun 6, 2025
CVE-2025-5751
6.8 MEDIUM

WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of …

Jun 6, 2025
CVE-2025-33035
6.5 MEDIUM

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the …

Jun 6, 2025
CVE-2025-29871
5.5 MEDIUM

An out-of-bounds read vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the …

Jun 6, 2025
CVE-2024-56805
5.4 MEDIUM

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Jun 6, 2025
CVE-2024-50406
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access …

Jun 6, 2025
CVE-2024-13087
6.7 MEDIUM

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they …

Jun 6, 2025
CVE-2025-5782
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. Affected by this issue is some unknown functionality …

Jun 6, 2025
CVE-2025-5780
6.3 MEDIUM

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jun 6, 2025
CVE-2025-5779
6.3 MEDIUM

A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jun 6, 2025
CVE-2025-38002
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo() Not everything requires locking in there, which is why the …

Jun 6, 2025
CVE-2025-38001
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice Savino says: "We are writing …

Jun 6, 2025
CVE-2025-0620
4.9 MEDIUM

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue …

Jun 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.