CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8644
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8643
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8642
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8641
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8640
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8639
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected Kenwood DMX958XR devices. Authentication is not …

Aug 6, 2025
CVE-2025-8638
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8637
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8636
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8635
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8634
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8633
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8632
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8631
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8630
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8629
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-8628
6.8 MEDIUM

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication …

Aug 6, 2025
CVE-2025-7502
6.4 MEDIUM

The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, …

Aug 6, 2025
CVE-2025-6986
6.5 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions …

Aug 6, 2025
CVE-2025-6690
6.4 MEDIUM

The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 …

Aug 6, 2025
CVE-2025-6259
6.4 MEDIUM

The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view shortcode in all versions up to, and including, 1.2.3 due …

Aug 6, 2025
CVE-2025-6256
6.4 MEDIUM

The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ parameter in all versions up to, and including, 1.2.5 due …

Aug 6, 2025
CVE-2025-54623
6.3 MEDIUM

Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54621
5.3 MEDIUM

Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.

Aug 6, 2025
CVE-2025-54620
5.5 MEDIUM

Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54619
5.3 MEDIUM

Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.

Aug 6, 2025
CVE-2025-54618
5.7 MEDIUM

Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54617
6.8 MEDIUM

Stack-based buffer overflow vulnerability in the dms_fwk module. Impact: Successful exploitation of this vulnerability can cause RCE.

Aug 6, 2025
CVE-2025-54616
4.0 MEDIUM

Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54615
6.2 MEDIUM

Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 6, 2025
CVE-2025-54614
6.2 MEDIUM

Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54613
5.9 MEDIUM

Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

Aug 6, 2025
CVE-2025-54612
5.9 MEDIUM

Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

Aug 6, 2025
CVE-2025-54610
5.4 MEDIUM

Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54609
5.4 MEDIUM

Out-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.

Aug 6, 2025
CVE-2025-54608
6.2 MEDIUM

Vulnerability that allows setting screen rotation direction without permission verification in the screen management module. Impact: Successful exploitation of this vulnerability may cause device screen …

Aug 6, 2025
CVE-2025-54879
5.3 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through …

Aug 6, 2025
CVE-2025-54571
6.1 MEDIUM

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can …

Aug 6, 2025
CVE-2025-54125
6.5 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform …

Aug 6, 2025
CVE-2025-54124
6.5 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform …

Aug 6, 2025
CVE-2025-32430
6.1 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 …

Aug 6, 2025
CVE-2025-8573
4.8 MEDIUM

Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version 8 was not affected. A rogue …

Aug 5, 2025
CVE-2025-8571
4.8 MEDIUM

Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could …

Aug 5, 2025
CVE-2025-52237
6.5 MEDIUM

An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

Aug 5, 2025
CVE-2025-52078
6.5 MEDIUM

File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request …

Aug 5, 2025
CVE-2025-51541
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/database-configuration/. The c_database_schema field fails to properly sanitize user-supplied input before …

Aug 5, 2025
CVE-2025-50592
5.4 MEDIUM

Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.

Aug 5, 2025
CVE-2025-45512
6.5 MEDIUM

A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to …

Aug 5, 2025
CVE-2025-51857
6.1 MEDIUM

The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS attacks.

Aug 5, 2025
CVE-2025-51627
6.5 MEDIUM

Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator.

Aug 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.