CVE Database

46169+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6265
7.2 HIGH

A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and earlier could allow an authenticated attacker with administrator …

Jul 15, 2025
CVE-2025-53823
8.8 HIGH

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection …

Jul 14, 2025
CVE-2025-53819
7.9 HIGH

Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of …

Jul 14, 2025
CVE-2025-53643
7.5 HIGH

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability …

Jul 14, 2025
CVE-2025-53101
7.4 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, …

Jul 14, 2025
CVE-2025-53015
7.5 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a …

Jul 14, 2025
CVE-2024-42646
7.5 HIGH

A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.

Jul 14, 2025
CVE-2025-7612
7.3 HIGH

A vulnerability was found in code-projects Mobile Shop 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /login.php. The …

Jul 14, 2025
CVE-2025-7611
7.3 HIGH

A vulnerability was found in code-projects Wedding Reservation 1.0. It has been classified as critical. This affects an unknown part of the file /global.php. The …

Jul 14, 2025
CVE-2025-7610
7.3 HIGH

A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jul 14, 2025
CVE-2025-7609
7.3 HIGH

A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 14, 2025
CVE-2025-7608
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The …

Jul 14, 2025
CVE-2025-7607
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file …

Jul 14, 2025
CVE-2025-7606
7.3 HIGH

A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of the file /city.php. The manipulation of …

Jul 14, 2025
CVE-2025-7605
7.3 HIGH

A vulnerability was found in code-projects AVL Rooms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 14, 2025
CVE-2025-7604
7.3 HIGH

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 14, 2025
CVE-2025-7603
7.2 HIGH

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown function of the file /jingx.asp of the …

Jul 14, 2025
CVE-2025-27582
7.6 HIGH

The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within …

Jul 14, 2025
CVE-2025-7602
7.2 HIGH

A vulnerability was found in D-Link DI-8100 16.07.26A1 and classified as critical. This issue affects some unknown processing of the file /arp_sys.asp of the component …

Jul 14, 2025
CVE-2025-7598
8.8 HIGH

A vulnerability classified as critical was found in Tenda AX1803 1.0.0.1. Affected by this vulnerability is the function formSetWifiMacFilterCfg of the file /goform/setWifiFilterCfg. The manipulation …

Jul 14, 2025
CVE-2025-7597
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AX1803 1.0.0.1. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the …

Jul 14, 2025
CVE-2025-7596
8.8 HIGH

A vulnerability was found in Tenda FH1205 2.0.0.7(775). It has been rated as critical. This issue affects the function formWifiExtraSet of the file /goform/WifiExtraSet. The …

Jul 14, 2025
CVE-2025-7595
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view-cad.php. The …

Jul 14, 2025
CVE-2024-51770
7.5 HIGH

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Jul 14, 2025
CVE-2024-51769
7.5 HIGH

An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Jul 14, 2025
CVE-2024-51768
8.0 HIGH

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Jul 14, 2025
CVE-2024-51767
7.3 HIGH

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

Jul 14, 2025
CVE-2025-7594
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0. It has been classified as critical. This affects an unknown part of the file /view-emp.php. The …

Jul 14, 2025
CVE-2025-7593
7.3 HIGH

A vulnerability was found in code-projects Job Diary 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-all.php. …

Jul 14, 2025
CVE-2025-53689
8.8 HIGH

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are …

Jul 14, 2025
CVE-2025-7587
7.3 HIGH

A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 14, 2025
CVE-2025-7586
8.8 HIGH

A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. Affected by this vulnerability is the function formSetAPCfg of the file …

Jul 14, 2025
CVE-2025-7576
7.3 HIGH

A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16 and classified as critical. Affected by this issue is some unknown …

Jul 14, 2025
CVE-2025-7571
8.8 HIGH

A vulnerability classified as critical has been found in UTT HiPER 840G up to 3.1.1-190328. This affects an unknown part of the file /goform/aspApBasicConfigUrcp. The …

Jul 14, 2025
CVE-2025-7620
8.8 HIGH

The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while …

Jul 14, 2025
CVE-2025-7619
8.8 HIGH

BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is …

Jul 14, 2025
CVE-2025-7570
8.8 HIGH

A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 14, 2025
CVE-2025-7564
7.8 HIGH

A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality of the file …

Jul 14, 2025
CVE-2025-25180
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. …

Jul 14, 2025
CVE-2025-7551
8.8 HIGH

A vulnerability was found in Tenda FH1201 1.2.0.14(408). It has been declared as critical. Affected by this vulnerability is the function fromPptpUserAdd of the file …

Jul 14, 2025
CVE-2025-1384
7.0 HIGH

Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use …

Jul 14, 2025
CVE-2025-7550
8.8 HIGH

A vulnerability was found in Tenda FH1201 1.2.0.14(408). It has been classified as critical. Affected is the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation …

Jul 13, 2025
CVE-2025-7549
8.8 HIGH

A vulnerability was found in Tenda FH1201 1.2.0.14(408) and classified as critical. This issue affects the function frmL7ProtForm of the file /goform/L7Prot. The manipulation of …

Jul 13, 2025
CVE-2025-7548
8.8 HIGH

A vulnerability has been found in Tenda FH1201 1.2.0.14(408) and classified as critical. This vulnerability affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation …

Jul 13, 2025
CVE-2025-7547
7.3 HIGH

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects the function save_movie of the …

Jul 13, 2025
CVE-2025-7544
8.8 HIGH

A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The …

Jul 13, 2025
CVE-2024-58258
7.2 HIGH

SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.

Jul 13, 2025
CVE-2025-7542
7.3 HIGH

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. Affected by this issue is some …

Jul 13, 2025
CVE-2025-7541
7.3 HIGH

A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 13, 2025
CVE-2025-7540
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. …

Jul 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.