CVE Database

52888+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23393
5.2 MEDIUM

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on users machines.This …

May 27, 2025
CVE-2024-47090
6.1 MEDIUM

Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS

May 27, 2025
CVE-2025-5232
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Student Study Center Management System 1.0. This issue affects some unknown processing of …

May 27, 2025
CVE-2025-48382
5.5 MEDIUM

Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fess.helper.SystemHelper creates temporary files without explicitly setting restrictive permissions. This …

May 27, 2025
CVE-2025-48742
5.4 MEDIUM

The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.

May 27, 2025
CVE-2025-4683
4.3 MEDIUM

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to …

May 27, 2025
CVE-2025-4682
6.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML attributes in Slider …

May 27, 2025
CVE-2025-48744
6.4 MEDIUM

In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.

May 27, 2025
CVE-2025-48743
5.3 MEDIUM

SIGB PMB before 8.0.1.2 allows SQL injection.

May 27, 2025
CVE-2025-33079
6.5 MEDIUM

IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.

May 27, 2025
CVE-2025-4783
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of the Countdown Timer Widget in all …

May 27, 2025
CVE-2025-5207
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. Affected by this issue is some unknown functionality …

May 26, 2025
CVE-2025-5206
4.7 MEDIUM

A vulnerability classified as critical was found in Pixelimity 1.0. Affected by this vulnerability is an unknown functionality of the file /install/index.php of the component …

May 26, 2025
CVE-2025-46802
6.0 MEDIUM

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

May 26, 2025
CVE-2025-23392
5.2 MEDIUM

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on target systems.This …

May 26, 2025
CVE-2025-46803
5.0 MEDIUM

The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs …

May 26, 2025
CVE-2025-37992
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change() Previously, when reducing a qdisc's limit via the …

May 26, 2025
CVE-2025-5196
6.6 MEDIUM

A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of …

May 26, 2025
CVE-2025-46805
5.5 MEDIUM

Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.

May 26, 2025
CVE-2025-39498
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Spotlight Spotlight - Social Media Feeds (Premium) allows Retrieve Embedded Sensitive Data.This issue affects Spotlight - …

May 26, 2025
CVE-2025-5186
6.3 MEDIUM

A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of …

May 26, 2025
CVE-2025-5185
4.3 MEDIUM

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been declared as problematic. Affected by this vulnerability …

May 26, 2025
CVE-2025-40667
6.5 MEDIUM

Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionality of the application even when they are not available …

May 26, 2025
CVE-2025-5184
4.3 MEDIUM

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been classified as problematic. Affected is an unknown …

May 26, 2025
CVE-2025-5182
4.3 MEDIUM

A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability affects unknown code …

May 26, 2025
CVE-2025-5178
6.3 MEDIUM

A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected is an unknown function of the file …

May 26, 2025
CVE-2025-5177
4.3 MEDIUM

A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This issue affects some unknown processing …

May 26, 2025
CVE-2025-4057
5.5 MEDIUM

A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between separated CR dependencies.

May 26, 2025
CVE-2025-1985
6.1 MEDIUM

Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected …

May 26, 2025
CVE-2025-5175
5.3 MEDIUM

A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the function Save of the file pypickle/pypickle.py. …

May 26, 2025
CVE-2025-5174
5.3 MEDIUM

A vulnerability was found in erdogant pypickle up to 1.1.5 and classified as problematic. Affected by this issue is the function load of the file …

May 26, 2025
CVE-2025-5173
5.3 MEDIUM

A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability is the function load of the …

May 26, 2025
CVE-2025-41441
5.3 MEDIUM

Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability …

May 26, 2025
CVE-2025-5171
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in llisoft MTA Maita Training System 4.5. This issue affects the function this.fileService.download of the …

May 26, 2025
CVE-2025-5170
6.3 MEDIUM

A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The …

May 26, 2025
CVE-2025-5163
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper …

May 26, 2025
CVE-2025-5162
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this issue is some unknown functionality …

May 26, 2025
CVE-2025-5161
4.3 MEDIUM

A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function operationDailyOut of the file …

May 26, 2025
CVE-2025-5160
4.3 MEDIUM

A vulnerability classified as problematic has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected is the function Download of the file /packetCaptureStrategy/download. The …

May 26, 2025
CVE-2025-5159
4.3 MEDIUM

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been rated as problematic. This issue affects the function Download of the …

May 26, 2025
CVE-2025-5158
4.3 MEDIUM

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been declared as problematic. This vulnerability affects the function downloadSoftware of the …

May 25, 2025
CVE-2025-5157
4.3 MEDIUM

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of the file …

May 25, 2025
CVE-2025-5155
6.3 MEDIUM

A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the function batchCope of the file app/admin/controller/Article.php. …

May 25, 2025
CVE-2025-5152
6.3 MEDIUM

A vulnerability classified as critical was found in Chanjet CRM up to 20250510. This vulnerability affects unknown code of the file /activity/newActivityedit.php?DontCheckLogin=1&id=null&ret=mod1. The manipulation of …

May 25, 2025
CVE-2025-5151
5.3 MEDIUM

A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This affects the function execute_analysis_code_safely of the file introspect/backend/tools/analysis_tools.py. The manipulation …

May 25, 2025
CVE-2025-5150
6.3 MEDIUM

A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the …

May 25, 2025
CVE-2025-5149
5.6 MEDIUM

A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the …

May 25, 2025
CVE-2025-5148
5.3 MEDIUM

A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is the function load_state_dict of the file inspiremusic/cli/model.py …

May 25, 2025
CVE-2025-5147
6.3 MEDIUM

A vulnerability was found in Netcore NBR1005GPEV2, NBR200V2 and B6V2 up to 20250508 and classified as critical. This issue affects the function tools_ping of the …

May 25, 2025
CVE-2025-5146
6.3 MEDIUM

A vulnerability has been found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2 and NBR200V2 up to 20250508 and classified as critical. This vulnerability affects …

May 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.