CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54962
6.4 MEDIUM

/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then …

Aug 4, 2025
CVE-2025-20698
6.7 MEDIUM

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Aug 4, 2025
CVE-2025-20697
6.7 MEDIUM

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Aug 4, 2025
CVE-2025-20696
6.8 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Aug 4, 2025
CVE-2025-8513
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Caixin News App 8.0.1 on Android. Affected is an unknown function of the file AndroidManifest.xml …

Aug 3, 2025
CVE-2025-8512
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in TVB Big Big Shop App 2.9.0 on Android. This issue affects some unknown processing …

Aug 3, 2025
CVE-2024-51775
5.3 MEDIUM

Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal …

Aug 3, 2025
CVE-2024-52279
5.3 MEDIUM

Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects …

Aug 3, 2025
CVE-2024-41177
6.1 MEDIUM

Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which …

Aug 3, 2025
CVE-2025-8505
4.3 MEDIUM

A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site …

Aug 3, 2025
CVE-2025-8504
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation …

Aug 3, 2025
CVE-2025-8500
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Aug 3, 2025
CVE-2025-52133
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.

Aug 3, 2025
CVE-2025-52132
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.

Aug 3, 2025
CVE-2025-52131
6.4 MEDIUM

The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

Aug 3, 2025
CVE-2025-54349
6.5 MEDIUM

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

Aug 3, 2025
CVE-2025-23285
5.5 MEDIUM

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful exploit of this …

Aug 2, 2025
CVE-2023-32255
5.3 MEDIUM

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an …

Aug 2, 2025
CVE-2023-32253
5.9 MEDIUM

A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a …

Aug 2, 2025
CVE-2025-23286
4.4 MEDIUM

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit of this vulnerability might …

Aug 2, 2025
CVE-2025-7500
6.4 MEDIUM

The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 …

Aug 2, 2025
CVE-2025-8488
4.3 MEDIUM

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Aug 2, 2025
CVE-2025-6722
5.3 MEDIUM

The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Aug 2, 2025
CVE-2025-8400
6.1 MEDIUM

The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization …

Aug 2, 2025
CVE-2025-8399
6.4 MEDIUM

The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 …

Aug 2, 2025
CVE-2025-8391
6.4 MEDIUM

The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, …

Aug 2, 2025
CVE-2025-6832
6.1 MEDIUM

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via …

Aug 2, 2025
CVE-2025-8317
6.4 MEDIUM

The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all versions up to, and including, 0.3 …

Aug 2, 2025
CVE-2025-8212
6.4 MEDIUM

The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter widget in all versions up to, and …

Aug 2, 2025
CVE-2025-8152
5.3 MEDIUM

The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Aug 2, 2025
CVE-2025-6626
4.4 MEDIUM

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in …

Aug 2, 2025
CVE-2025-4588
6.4 MEDIUM

The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, …

Aug 2, 2025
CVE-2025-8146
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut Text widget in all versions up to, …

Aug 2, 2025
CVE-2025-7694
6.8 MEDIUM

The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versions …

Aug 2, 2025
CVE-2025-6078
5.4 MEDIUM

Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but …

Aug 2, 2025
CVE-2025-54790
6.5 MEDIUM

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the …

Aug 2, 2025
CVE-2025-54789
6.1 MEDIUM

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic …

Aug 2, 2025
CVE-2025-54792
6.8 MEDIUM

LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection. In versions 1.16.1 …

Aug 1, 2025
CVE-2025-54132
4.4 MEDIUM

Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams) allows embedding images which …

Aug 1, 2025
CVE-2025-54131
6.4 MEDIUM

Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with …

Aug 1, 2025
CVE-2025-8474
6.8 MEDIUM

Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 …

Aug 1, 2025
CVE-2025-8473
6.6 MEDIUM

Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is …

Aug 1, 2025
CVE-2025-6037
6.8 MEDIUM

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as [+trusted certificate+|https://developer.hashicorp.com/vault/api-docs/auth/cert#certificate]. In …

Aug 1, 2025
CVE-2025-6015
5.7 MEDIUM

Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and …

Aug 1, 2025
CVE-2025-6014
6.5 MEDIUM

Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition …

Aug 1, 2025
CVE-2025-6004
5.3 MEDIUM

Vault and Vault Enterprise’s (“Vault”) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault …

Aug 1, 2025
CVE-2025-50869
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of Institute-of-Current-Students 1.0, where the input fields for Query and Answer do not properly …

Aug 1, 2025
CVE-2025-50868
6.5 MEDIUM

A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP-Project 1.0. The Q4 POST parameter is not properly sanitized before being used in SQL …

Aug 1, 2025
CVE-2025-49832
6.5 MEDIUM

Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, between 20.00.0 and 20.15.0, 20.7-cert6, 21.00.0, 22.00.0 …

Aug 1, 2025
CVE-2025-33118
6.4 MEDIUM

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code …

Aug 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.