CVE Database

46169+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8496
7.3 HIGH

A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 3, 2025
CVE-2025-8495
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. …

Aug 3, 2025
CVE-2025-54351
8.9 HIGH

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

Aug 3, 2025
CVE-2025-8494
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the …

Aug 3, 2025
CVE-2025-54955
8.1 HIGH

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. …

Aug 3, 2025
CVE-2025-8493
7.3 HIGH

A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_query.php. The manipulation …

Aug 2, 2025
CVE-2025-23284
7.8 HIGH

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack buffer overflow. A successful exploit of …

Aug 2, 2025
CVE-2025-23283
7.8 HIGH

NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause stack buffer overflow. A successful …

Aug 2, 2025
CVE-2025-23281
7.0 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race condition might be able …

Aug 2, 2025
CVE-2025-23279
7.0 HIGH

NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of …

Aug 2, 2025
CVE-2025-23278
7.1 HIGH

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index validation by issuing a call with crafted …

Aug 2, 2025
CVE-2025-23277
7.3 HIGH

NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under …

Aug 2, 2025
CVE-2025-23276
7.8 HIGH

NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful exploit of this vulnerability may lead to …

Aug 2, 2025
CVE-2025-8471
7.3 HIGH

A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file …

Aug 2, 2025
CVE-2025-8470
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/deleteroom.php. The manipulation …

Aug 2, 2025
CVE-2025-8469
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The …

Aug 2, 2025
CVE-2025-8468
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Aug 2, 2025
CVE-2025-8467
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 2, 2025
CVE-2025-8466
7.3 HIGH

A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. …

Aug 2, 2025
CVE-2025-6754
8.8 HIGH

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() …

Aug 2, 2025
CVE-2025-6076
8.8 HIGH

Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a …

Aug 2, 2025
CVE-2025-54796
7.5 HIGH

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is …

Aug 2, 2025
CVE-2025-54782
8.8 HIGH

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in …

Aug 2, 2025
CVE-2025-54136
7.2 HIGH

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying …

Aug 2, 2025
CVE-2025-54424
8.1 HIGH

1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, …

Aug 1, 2025
CVE-2013-10061
7.2 HIGH

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in …

Aug 1, 2025
CVE-2013-10060
7.2 HIGH

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A …

Aug 1, 2025
CVE-2013-10059
7.2 HIGH

An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface …

Aug 1, 2025
CVE-2013-10050
8.8 HIGH

An OS command injection vulnerability exists in multiple D-Link routers—confirmed on DIR-300 rev A (v1.05) and DIR-615 rev D (v4.13)—via the authenticated tools_vct.xgi CGI endpoint. …

Aug 1, 2025
CVE-2013-10044
8.8 HIGH

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. …

Aug 1, 2025
CVE-2025-8480
8.0 HIGH

Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is …

Aug 1, 2025
CVE-2025-8477
7.4 HIGH

Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Alpine iLX-507 devices. …

Aug 1, 2025
CVE-2025-8476
8.0 HIGH

Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is …

Aug 1, 2025
CVE-2025-8475
7.4 HIGH

Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 …

Aug 1, 2025
CVE-2025-8472
7.4 HIGH

Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine …

Aug 1, 2025
CVE-2025-5999
7.2 HIGH

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privileges to Vault’s root …

Aug 1, 2025
CVE-2025-54595
7.3 HIGH

Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the Pearcleaner application. It is …

Aug 1, 2025
CVE-2025-54593
7.2 HIGH

FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by …

Aug 1, 2025
CVE-2025-54564
7.8 HIGH

uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the nobody user.

Aug 1, 2025
CVE-2025-53012
7.5 HIGH

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, nested imports of MaterialX …

Aug 1, 2025
CVE-2025-53011
7.5 HIGH

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes …

Aug 1, 2025
CVE-2025-53010
7.5 HIGH

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes …

Aug 1, 2025
CVE-2025-53009
7.5 HIGH

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing …

Aug 1, 2025
CVE-2025-2824
7.4 HIGH

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By …

Aug 1, 2025
CVE-2023-32256
7.5 HIGH

A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in multichannel connections could result in …

Aug 1, 2025
CVE-2025-51504
7.6 HIGH

Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last name field.

Aug 1, 2025
CVE-2025-52361
7.8 HIGH

Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authenticated low-privilege user to execute arbitrary commands with root …

Aug 1, 2025
CVE-2025-52327
7.8 HIGH

SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file

Aug 1, 2025
CVE-2025-44139
7.2 HIGH

Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip

Aug 1, 2025
CVE-2025-45767
7.0 HIGH

jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security …

Aug 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.