CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31220
5.5 MEDIUM

A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. …

May 12, 2025
CVE-2025-31218
6.2 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to observe the …

May 12, 2025
CVE-2025-31217
6.5 MEDIUM

The issue was addressed with improved input validation. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, …

May 12, 2025
CVE-2025-31215
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS …

May 12, 2025
CVE-2025-31212
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, …

May 12, 2025
CVE-2025-31210
6.5 MEDIUM

The issue was addressed with improved UI. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing web content may lead to …

May 12, 2025
CVE-2025-31209
6.3 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS …

May 12, 2025
CVE-2025-31206
4.3 MEDIUM

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS …

May 12, 2025
CVE-2025-31205
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS …

May 12, 2025
CVE-2025-31196
5.5 MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS …

May 12, 2025
CVE-2025-31195
6.3 MEDIUM

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of …

May 12, 2025
CVE-2025-30440
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be …

May 12, 2025
CVE-2025-24225
6.5 MEDIUM

An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing an email may …

May 12, 2025
CVE-2025-24222
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5. Processing maliciously crafted web content may lead to an …

May 12, 2025
CVE-2025-24220
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may be able …

May 12, 2025
CVE-2025-24155
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may …

May 12, 2025
CVE-2025-24144
5.5 MEDIUM

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia …

May 12, 2025
CVE-2025-24142
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS …

May 12, 2025
CVE-2025-24111
5.5 MEDIUM

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, …

May 12, 2025
CVE-2024-55466
6.5 MEDIUM

An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via …

May 12, 2025
CVE-2025-44176
6.5 MEDIUM

Tenda FH451 V1.0.0.9 is vulnerable to Remote Code Execution in the formSafeEmailFilter function.

May 12, 2025
CVE-2025-44175
5.4 MEDIUM

Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.

May 12, 2025
CVE-2023-34732
5.4 MEDIUM

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user …

May 12, 2025
CVE-2025-46750
4.4 MEDIUM

SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and change password-protected BIOS settings by importing a BIOS …

May 12, 2025
CVE-2025-46749
4.3 MEDIUM

An authenticated user could submit scripting to fields that lack proper input and output sanitization leading to subsequent client-side script execution.

May 12, 2025
CVE-2025-46747
5.7 MEDIUM

An authenticated user without user-management permissions could identify other user accounts.

May 12, 2025
CVE-2025-46746
5.8 MEDIUM

An administrator could discover another account's credentials.

May 12, 2025
CVE-2025-46745
6.5 MEDIUM

An authenticated user without user-management permissions could view other users account information.

May 12, 2025
CVE-2025-46743
6.3 MEDIUM

An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.

May 12, 2025
CVE-2025-46742
4.3 MEDIUM

Users who were required to change their password could still access system information before changing their password

May 12, 2025
CVE-2025-46741
5.7 MEDIUM

A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.

May 12, 2025
CVE-2025-47578
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button bns-twitter-follow-button allows DOM-Based XSS.This issue affects BNS …

May 12, 2025
CVE-2025-46738
6.6 MEDIUM

An authenticated attacker can maliciously modify layout data files in the SEL-5033 installation directory to execute arbitrary code.

May 12, 2025
CVE-2025-46611
6.1 MEDIUM

Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.

May 12, 2025
CVE-2025-26841
6.1 MEDIUM

Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.

May 12, 2025
CVE-2025-40627
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim …

May 12, 2025
CVE-2025-40626
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in AbanteCart v1.4.0, that could allow an attacker to execute JavaScript code in a victim's browser by sending the victim …

May 12, 2025
CVE-2025-22247
6.1 MEDIUM

VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger …

May 12, 2025
CVE-2025-41393
6.1 MEDIUM

Reflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor. If exploited, an arbitrary script may …

May 12, 2025
CVE-2025-4560
6.5 MEDIUM

The ISOinsight from Netvision has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access certain system functions. These functions include viewing the administrator list, …

May 12, 2025
CVE-2025-3649
6.8 MEDIUM

The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role …

May 12, 2025
CVE-2025-3597
5.9 MEDIUM

The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is …

May 12, 2025
CVE-2025-4552
5.4 MEDIUM

A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

May 12, 2025
CVE-2025-4546
4.7 MEDIUM

A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 11, 2025
CVE-2025-4545
5.4 MEDIUM

A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\controllers\admin\Tpl.php …

May 11, 2025
CVE-2025-4544
6.6 MEDIUM

A vulnerability was found in D-Link DI-8100 up to 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /ddos.asp of …

May 11, 2025
CVE-2025-4541
6.3 MEDIUM

A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\admin\ZtAction.class.php of the component POST Request …

May 11, 2025
CVE-2025-4538
6.3 MEDIUM

A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of …

May 11, 2025
CVE-2025-4536
5.3 MEDIUM

A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classified as critical. Affected by this vulnerability is an unknown …

May 11, 2025
CVE-2025-4535
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0. Affected is an unknown function of the …

May 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.