CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2533
5.3 MEDIUM

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a denial of service as the server may crash under certain conditions with a …

Jul 29, 2025
CVE-2025-27514
4.5 MEDIUM

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In versions 9.5.0 through …

Jul 29, 2025
CVE-2025-28171
6.5 MEDIUM

An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.

Jul 29, 2025
CVE-2025-28172
6.5 MEDIUM

Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts …

Jul 29, 2025
CVE-2025-52358
6.3 MEDIUM

A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject …

Jul 29, 2025
CVE-2025-6060
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Software Geodi allows Cross-Site Scripting (XSS).This issue affects Geodi: before …

Jul 29, 2025
CVE-2025-54422
5.5 MEDIUM

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in …

Jul 29, 2025
CVE-2025-41241
4.4 MEDIUM

VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation …

Jul 29, 2025
CVE-2025-40686
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser …

Jul 29, 2025
CVE-2025-40685
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser …

Jul 29, 2025
CVE-2025-40684
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser …

Jul 29, 2025
CVE-2025-40683
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser …

Jul 29, 2025
CVE-2025-5587
6.4 MEDIUM

The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.2.6 due to …

Jul 29, 2025
CVE-2025-8216
6.4 MEDIUM

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in all versions up to, and including, 3.1.4 …

Jul 29, 2025
CVE-2025-8196
6.4 MEDIUM

The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes in all versions up to, and …

Jul 29, 2025
CVE-2025-6730
4.3 MEDIUM

The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jul 29, 2025
CVE-2025-6692
6.4 MEDIUM

The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all versions up to, and including, 10.3 due …

Jul 29, 2025
CVE-2025-6681
6.4 MEDIUM

The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.0.1 due …

Jul 29, 2025
CVE-2025-26400
5.3 MEDIUM

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, …

Jul 29, 2025
CVE-2025-53082
6.1 MEDIUM

An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to …

Jul 29, 2025
CVE-2025-53081
6.4 MEDIUM

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to …

Jul 29, 2025
CVE-2025-53649
5.1 MEDIUM

"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive …

Jul 29, 2025
CVE-2025-53079
4.9 MEDIUM

Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

Jul 29, 2025
CVE-2025-53077
6.5 MEDIUM

An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the …

Jul 29, 2025
CVE-2025-4566
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element …

Jul 29, 2025
CVE-2025-4370
5.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing …

Jul 29, 2025
CVE-2025-3075
6.4 MEDIUM

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode …

Jul 29, 2025
CVE-2025-7811
6.4 MEDIUM

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-7810
5.4 MEDIUM

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-7809
6.4 MEDIUM

The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, …

Jul 29, 2025
CVE-2025-54768
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54767
6.5 MEDIUM

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

Jul 29, 2025
CVE-2025-54766
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54765
5.3 MEDIUM

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint …

Jul 29, 2025
CVE-2025-54423
5.4 MEDIUM

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in …

Jul 28, 2025
CVE-2025-54538
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

Jul 28, 2025
CVE-2025-54537
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

Jul 28, 2025
CVE-2025-54536
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint

Jul 28, 2025
CVE-2025-54535
5.8 MEDIUM

In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

Jul 28, 2025
CVE-2025-54534
4.8 MEDIUM

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

Jul 28, 2025
CVE-2025-54533
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

Jul 28, 2025
CVE-2025-54532
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

Jul 28, 2025
CVE-2025-54528
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

Jul 28, 2025
CVE-2025-54527
6.1 MEDIUM

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

Jul 28, 2025
CVE-2025-6250
6.7 MEDIUM

Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service …

Jul 28, 2025
CVE-2024-49343
5.4 MEDIUM

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Jul 28, 2025
CVE-2025-32731
6.1 MEDIUM

A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream MedDream PACS Premium 7.3.5.860. A specially crafted malicious url can lead to …

Jul 28, 2025
CVE-2025-30126
5.3 MEDIUM

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a …

Jul 28, 2025
CVE-2025-24485
5.8 MEDIUM

A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP request can lead to SSRF. An …

Jul 28, 2025
CVE-2025-8275
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown …

Jul 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.