CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-51060
6.5 MEDIUM

An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR …

Aug 5, 2025
CVE-2025-50688
6.5 MEDIUM

A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability …

Aug 5, 2025
CVE-2025-50454
6.5 MEDIUM

An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an unauthorized attacker to log into the application as an administrator without valid …

Aug 5, 2025
CVE-2025-8585
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the …

Aug 5, 2025
CVE-2025-43980
6.5 MEDIUM

An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the credentials of root/admin. The GUI doesn't …

Aug 5, 2025
CVE-2025-47152
6.5 MEDIUM

An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.6.0.396. By using a specially crafted EMF file, an attacker …

Aug 5, 2025
CVE-2025-46958
5.4 MEDIUM

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Aug 5, 2025
CVE-2025-27931
6.5 MEDIUM

An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit …

Aug 5, 2025
CVE-2024-52890
6.1 MEDIUM

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

Aug 5, 2025
CVE-2025-8295
6.4 MEDIUM

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due …

Aug 5, 2025
CVE-2025-8294
6.4 MEDIUM

The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3 due …

Aug 5, 2025
CVE-2025-2810
5.5 MEDIUM

A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.

Aug 5, 2025
CVE-2025-8315
6.4 MEDIUM

The WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.0.1 …

Aug 5, 2025
CVE-2025-8313
6.4 MEDIUM

The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due …

Aug 5, 2025
CVE-2025-8547
5.3 MEDIUM

A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email Verification …

Aug 5, 2025
CVE-2025-8546
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code …

Aug 5, 2025
CVE-2025-54871
5.5 MEDIUM

Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass …

Aug 5, 2025
CVE-2025-54804
6.5 MEDIUM

Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used …

Aug 5, 2025
CVE-2025-52892
4.5 MEDIUM

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and …

Aug 5, 2025
CVE-2025-8530
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of …

Aug 4, 2025
CVE-2025-8529
6.3 MEDIUM

A vulnerability classified as critical was found in cloudfavorites favorites-web up to 1.3.0. Affected by this vulnerability is the function getCollectLogoUrl of the file app/src/main/java/com/favorites/web/CollectController.java. …

Aug 4, 2025
CVE-2025-8527
6.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file …

Aug 4, 2025
CVE-2025-54554
5.3 MEDIUM

tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.

Aug 4, 2025
CVE-2025-4604
6.1 MEDIUM

The vulnerable code can bypass the Captcha check in Liferay Portal 7.4.3.80 through 7.4.3.132, and Liferay DXP 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through …

Aug 4, 2025
CVE-2025-4599
6.1 MEDIUM

The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 …

Aug 4, 2025
CVE-2025-8526
6.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file …

Aug 4, 2025
CVE-2025-8525
5.3 MEDIUM

A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring …

Aug 4, 2025
CVE-2025-8524
5.3 MEDIUM

A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the …

Aug 4, 2025
CVE-2025-8523
5.3 MEDIUM

A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality …

Aug 4, 2025
CVE-2025-55014
4.7 MEDIUM

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers …

Aug 4, 2025
CVE-2025-50340
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other …

Aug 4, 2025
CVE-2025-8522
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of …

Aug 4, 2025
CVE-2025-8520
4.7 MEDIUM

A vulnerability classified as critical was found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin123/?module=editor/editor of the component …

Aug 4, 2025
CVE-2025-46206
6.5 MEDIUM

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` …

Aug 4, 2025
CVE-2024-45183
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads …

Aug 4, 2025
CVE-2025-8518
4.7 MEDIUM

A vulnerability was found in givanz Vvveb 1.0.5. It has been rated as critical. Affected by this issue is the function Save of the file …

Aug 4, 2025
CVE-2025-50420
6.5 MEDIUM

An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can …

Aug 4, 2025
CVE-2025-44962
5.0 MEDIUM

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.

Aug 4, 2025
CVE-2025-44958
5.3 MEDIUM

RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.

Aug 4, 2025
CVE-2025-8517
6.3 MEDIUM

A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. …

Aug 4, 2025
CVE-2025-8516
5.3 MEDIUM

A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file K3Cloud\BBCMallSite\WEB-INF\lib\Kingdee.K3.O2O.Base.WebApp.jar!\kingdee\k3\o2o\base\webapp\action\FileUploadAction.class of …

Aug 4, 2025
CVE-2025-5988
5.3 MEDIUM

A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, …

Aug 4, 2025
CVE-2025-30098
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-30097
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-30096
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS …

Aug 4, 2025
CVE-2025-36605
6.1 MEDIUM

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the CWE-79: Improper Neutralization of …

Aug 4, 2025
CVE-2025-0932
4.3 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace …

Aug 4, 2025
CVE-2025-8341
5.0 MEDIUM

Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, …

Aug 4, 2025
CVE-2025-41658
5.5 MEDIUM

CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.

Aug 4, 2025
CVE-2025-48499
5.3 MEDIUM

Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially crafted IPP (Internet Printing Protocol) or LPD (Line Printer Daemon) packet may cause a …

Aug 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.