CVE Database

53006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4352
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Brilliance Golden Link Secondary System up to 20250424. This issue affects some unknown processing …

May 6, 2025
CVE-2025-3782
6.4 MEDIUM

The Cision Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.3.0 due …

May 6, 2025
CVE-2025-4341
6.3 MEDIUM

A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the file /htdocs/ssdpcgi …

May 6, 2025
CVE-2024-49830
6.6 MEDIUM

Memory corruption while processing an IOCTL call to set mixer controls.

May 6, 2025
CVE-2024-49829
6.7 MEDIUM

Memory corruption can occur during context user dumps due to inadequate checks on buffer length.

May 6, 2025
CVE-2024-45583
6.6 MEDIUM

Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.

May 6, 2025
CVE-2024-45581
6.6 MEDIUM

Memory corruption while sound model registration for voice activation with audio kernel driver.

May 6, 2025
CVE-2024-45570
6.6 MEDIUM

Memory corruption may occur during IO configuration processing when the IO port count is invalid.

May 6, 2025
CVE-2024-45568
6.7 MEDIUM

Memory corruption due to improper bounds check while command handling in camera-kernel driver.

May 6, 2025
CVE-2024-45563
6.6 MEDIUM

Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.

May 6, 2025
CVE-2024-45562
6.6 MEDIUM

Memory corruption during concurrent access to server info object due to unprotected critical field.

May 6, 2025
CVE-2025-4340
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. …

May 6, 2025
CVE-2025-4333
6.3 MEDIUM

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function uploadFile of the …

May 6, 2025
CVE-2025-46593
5.1 MEDIUM

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

May 6, 2025
CVE-2025-46592
4.4 MEDIUM

Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.

May 6, 2025
CVE-2025-46591
6.2 MEDIUM

Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 6, 2025
CVE-2025-46590
6.3 MEDIUM

Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search …

May 6, 2025
CVE-2025-46589
4.4 MEDIUM

Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

May 6, 2025
CVE-2025-46588
4.4 MEDIUM

Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

May 6, 2025
CVE-2025-46587
6.2 MEDIUM

Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 6, 2025
CVE-2025-3281
5.3 MEDIUM

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in …

May 6, 2025
CVE-2025-3020
5.4 MEDIUM

An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several fields of the configuration webpage with …

May 6, 2025
CVE-2024-58252
6.2 MEDIUM

Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 6, 2025
CVE-2025-4329
4.3 MEDIUM

A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the …

May 6, 2025
CVE-2025-4327
4.3 MEDIUM

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. …

May 6, 2025
CVE-2025-46586
5.1 MEDIUM

Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.

May 6, 2025
CVE-2025-4337
4.3 MEDIUM

The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing …

May 6, 2025
CVE-2025-4310
4.7 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/add_topic.php?category=BBS. The manipulation …

May 6, 2025
CVE-2025-3609
5.3 MEDIUM

The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to …

May 6, 2025
CVE-2025-4305
6.3 MEDIUM

A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file app/tools/controller/File.php. …

May 6, 2025
CVE-2024-39442
6.2 MEDIUM

In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

May 6, 2025
CVE-2025-4291
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. …

May 5, 2025
CVE-2025-1493
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of service …

May 5, 2025
CVE-2025-1000
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user to cause …

May 5, 2025
CVE-2025-0915
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations could allow an authenticated …

May 5, 2025
CVE-2025-46813
5.8 MEDIUM

Discourse is an open-source community platform. A data leak vulnerability affects sites deployed between commits 10df7fdee060d44accdee7679d66d778d1136510 and 82d84af6b0efbd9fa2aeec3e91ce7be1a768511b. On login-required sites, the leak meant that …

May 5, 2025
CVE-2025-46734
6.4 MEDIUM

league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote …

May 5, 2025
CVE-2025-46730
6.8 MEDIUM

MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools …

May 5, 2025
CVE-2025-45618
6.5 MEDIUM

Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.

May 5, 2025
CVE-2025-46719
5.4 MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, a vulnerability in the way certain html tags …

May 5, 2025
CVE-2025-46571
5.4 MEDIUM

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, low privileged users can upload HTML files which …

May 5, 2025
CVE-2025-46559
5.4 MEDIUM

Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, missing validation in `Mk:api` allows malicious AiScript …

May 5, 2025
CVE-2025-46553
6.1 MEDIUM

@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in …

May 5, 2025
CVE-2025-46335
5.4 MEDIUM

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A Stored Cross-Site Scripting (XSS) vulnerability has …

May 5, 2025
CVE-2025-29573
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.

May 5, 2025
CVE-2024-42213
5.3 MEDIUM

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing …

May 5, 2025
CVE-2024-42212
5.4 MEDIUM

HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request Forgery (CSRF) attacks, where a malicious site …

May 5, 2025
CVE-2025-4282
4.3 MEDIUM

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The …

May 5, 2025
CVE-2025-4051
6.3 MEDIUM

Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures …

May 5, 2025
CVE-2025-45239
5.3 MEDIUM

An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.

May 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.