CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48948
6.5 MEDIUM

Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any authenticated regular user …

May 30, 2025
CVE-2025-1479
5.3 MEDIUM

An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary …

May 30, 2025
CVE-2025-48944
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with …

May 30, 2025
CVE-2025-48943
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) …

May 30, 2025
CVE-2025-48942
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). In versions 0.8.0 up to but excluding 0.9.0, hitting the /v1/completions API with …

May 30, 2025
CVE-2025-5054
4.7 MEDIUM

Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling …

May 30, 2025
CVE-2025-48887
6.5 MEDIUM

vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file `vllm/entrypoints/openai/tool_parsers/pythonic_tool_parser.py` of …

May 30, 2025
CVE-2024-42191
6.5 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with …

May 30, 2025
CVE-2024-42190
6.5 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with …

May 30, 2025
CVE-2024-23589
6.8 MEDIUM

Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware …

May 30, 2025
CVE-2025-3230
5.4 MEDIUM

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing …

May 30, 2025
CVE-2025-2571
4.2 MEDIUM

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to …

May 30, 2025
CVE-2024-7097
4.3 MEDIUM

An incorrect authorization vulnerability exists in multiple WSO2 products due to a flaw in the SOAP admin service, which allows user account creation regardless of …

May 30, 2025
CVE-2024-7096
4.2 MEDIUM

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can create a …

May 30, 2025
CVE-2025-4598
4.7 MEDIUM

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary …

May 30, 2025
CVE-2025-40909
5.9 MEDIUM

Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the …

May 30, 2025
CVE-2025-1484
6.5 MEDIUM

A vulnerability exists in the media upload component of the Asset Suite versions listed below. If successfully exploited an attacker could impact the confidentiality or …

May 30, 2025
CVE-2025-4944
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in …

May 30, 2025
CVE-2025-4597
6.5 MEDIUM

The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

May 30, 2025
CVE-2025-5235
6.4 MEDIUM

The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.4.0 due to …

May 30, 2025
CVE-2025-5142
6.5 MEDIUM

The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due …

May 30, 2025
CVE-2025-4635
6.6 MEDIUM

A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to obtain remote code execution on the …

May 30, 2025
CVE-2025-4634
4.1 MEDIUM

The web portal on airpointer 2.4.107-2 was vulnerable local file inclusion. A malicious user with administrative privileges in the web portal would be able to …

May 30, 2025
CVE-2025-4633
6.5 MEDIUM

Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor to log in via the web portal

May 30, 2025
CVE-2025-48912
6.5 MEDIUM

An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of …

May 30, 2025
CVE-2025-48334
6.5 MEDIUM

Missing Authorization vulnerability in BinaryCarpenter Woo Slider Pro woo-slider-pro-drag-drop-slider-builder-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Slider Pro: from n/a through …

May 30, 2025
CVE-2025-5236
6.4 MEDIUM

The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, …

May 30, 2025
CVE-2025-4431
4.3 MEDIUM

The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

May 30, 2025
CVE-2025-4943
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and …

May 30, 2025
CVE-2025-48880
6.6 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is …

May 30, 2025
CVE-2025-48875
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data …

May 30, 2025
CVE-2025-48489
4.8 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to …

May 30, 2025
CVE-2025-48488
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML …

May 30, 2025
CVE-2025-48487
4.8 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a …

May 30, 2025
CVE-2025-48486
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerability is caused by the lack of …

May 30, 2025
CVE-2025-48485
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to …

May 30, 2025
CVE-2025-41406
6.1 MEDIUM

Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user connects to the affected device with a specific operation, an arbitrary …

May 30, 2025
CVE-2025-5259
6.4 MEDIUM

The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.7.3 …

May 30, 2025
CVE-2025-4659
5.3 MEDIUM

The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions …

May 30, 2025
CVE-2025-4429
6.1 MEDIUM

The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

May 30, 2025
CVE-2025-48889
5.3 MEDIUM

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. …

May 30, 2025
CVE-2025-48484
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to …

May 30, 2025
CVE-2025-48483
5.4 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to …

May 30, 2025
CVE-2025-48482
4.3 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated …

May 30, 2025
CVE-2025-48478
4.9 MEDIUM

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation during user creation has resulted in a mass …

May 30, 2025
CVE-2025-48381
4.3 MEDIUM

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. In versions starting from 2.4.0 to before 2.38.0, an …

May 30, 2025
CVE-2025-48068
4.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may …

May 30, 2025
CVE-2025-44612
5.9 MEDIUM

Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept …

May 30, 2025
CVE-2025-31264
4.6 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker …

May 29, 2025
CVE-2025-31261
5.5 MEDIUM

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app …

May 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.