CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8567
6.4 MEDIUM

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to …

Aug 19, 2025
CVE-2025-41685
6.5 MEDIUM

A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.

Aug 19, 2025
CVE-2025-8622
6.4 MEDIUM

The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortcode in all versions up to, and including, …

Aug 19, 2025
CVE-2025-38553
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: Restrict conditions for adding duplicating netems to qdisc tree netem_enqueue's duplication prevention logic breaks …

Aug 19, 2025
CVE-2025-8357
4.3 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user …

Aug 19, 2025
CVE-2025-5417
6.1 MEDIUM

An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has …

Aug 19, 2025
CVE-2025-7496
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements in all versions up to, and including, …

Aug 19, 2025
CVE-2025-54862
5.4 MEDIUM

Sante PACS Server web portal is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage …

Aug 18, 2025
CVE-2025-54759
6.1 MEDIUM

Sante PACS Server is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage and stealing …

Aug 18, 2025
CVE-2025-55590
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.

Aug 18, 2025
CVE-2025-55589
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.

Aug 18, 2025
CVE-2025-55585
6.5 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.

Aug 18, 2025
CVE-2025-55584
5.3 MEDIUM

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.

Aug 18, 2025
CVE-2025-4371
6.8 MEDIUM

A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write …

Aug 18, 2025
CVE-2025-43731
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, …

Aug 18, 2025
CVE-2025-55296
5.5 MEDIUM

librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. …

Aug 18, 2025
CVE-2025-55288
5.5 MEDIUM

Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Reflected Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could …

Aug 18, 2025
CVE-2025-55287
5.4 MEDIUM

Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could …

Aug 18, 2025
CVE-2025-54118
5.3 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker …

Aug 18, 2025
CVE-2025-33100
6.2 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound …

Aug 18, 2025
CVE-2025-27909
5.4 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name …

Aug 18, 2025
CVE-2025-1759
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Aug 18, 2025
CVE-2025-43733
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript …

Aug 18, 2025
CVE-2025-41242
5.9 MEDIUM

Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when …

Aug 18, 2025
CVE-2025-57703
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57702
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57701
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57700
6.1 MEDIUM

DIAEnergie - Stored Cross-site Scripting

Aug 18, 2025
CVE-2025-9108
4.3 MEDIUM

Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ui layers. It is possible to launch …

Aug 18, 2025
CVE-2025-9107
4.3 MEDIUM

A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/search_autocomplete. Executing manipulation of the argument q …

Aug 18, 2025
CVE-2025-9102
5.3 MEDIUM

A security vulnerability has been detected in 1&1 Mail & Media mail.com App 8.8.0 on Android. Affected is an unknown function of the file AndroidManifest.xml …

Aug 18, 2025
CVE-2025-9100
5.3 MEDIUM

A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article …

Aug 18, 2025
CVE-2025-9099
6.3 MEDIUM

A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of …

Aug 18, 2025
CVE-2025-9098
5.3 MEDIUM

A vulnerability was determined in Elseplus File Recovery App 4.4.21 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml. The …

Aug 18, 2025
CVE-2025-31714
6.8 MEDIUM

In Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

Aug 18, 2025
CVE-2025-9097
5.3 MEDIUM

A vulnerability was found in Euro Information CIC banque et compte en ligne App 12.56.0 on Android. Affected by this vulnerability is an unknown functionality …

Aug 18, 2025
CVE-2025-9094
4.3 MEDIUM

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of …

Aug 17, 2025
CVE-2025-9093
5.3 MEDIUM

A security vulnerability has been detected in BuzzFeed App 2024.9 on Android. This affects an unknown part of the file AndroidManifest.xml of the component com.buzzfeed.android. …

Aug 17, 2025
CVE-2025-9090
6.3 MEDIUM

A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads …

Aug 17, 2025
CVE-2023-4515
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate command request size In commit 2b9b8f3b68ed ("ksmbd: validate command payload size"), except for …

Aug 16, 2025
CVE-2023-4130
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea() There are multiple smb2_ea_info …

Aug 16, 2025
CVE-2023-3866
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in the compound request This patch validate session …

Aug 16, 2025
CVE-2023-32249
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is …

Aug 16, 2025
CVE-2023-32246
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: call rcu_barrier() in ksmbd_server_exit() racy issue is triggered the bug by racing between closing …

Aug 16, 2025
CVE-2025-8878
6.5 MEDIUM

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary …

Aug 16, 2025
CVE-2025-8143
6.4 MEDIUM

The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pcsml_smartlists_h’ parameter in all versions up to, and including, 8.6.7 due to …

Aug 16, 2025
CVE-2025-38551
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix recursived rtnl_lock() during probe() The deadlock appears in a stack trace like: virtnet_probe() …

Aug 16, 2025
CVE-2025-38549
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths When processing mount options, efivarfs …

Aug 16, 2025
CVE-2025-38547
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps The AXP717 ADC channel …

Aug 16, 2025
CVE-2025-38546
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix memory leak of struct clip_vcc. ioctl(ATMARP_MKIP) allocates struct clip_vcc and set it …

Aug 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.