CVE Database

46169+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6937
7.3 HIGH

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 1, 2025
CVE-2025-6936
7.3 HIGH

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jul 1, 2025
CVE-2025-6935
7.3 HIGH

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 1, 2025
CVE-2025-6554
8.1 HIGH KEV

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security …

Jun 30, 2025
CVE-2025-49521
8.8 HIGH

A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. …

Jun 30, 2025
CVE-2025-49520
8.8 HIGH

A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows …

Jun 30, 2025
CVE-2025-52995
8.0 HIGH

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior …

Jun 30, 2025
CVE-2025-36593
8.8 HIGH

Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access …

Jun 30, 2025
CVE-2025-6917
7.3 HIGH

A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/registration.php. The …

Jun 30, 2025
CVE-2025-52898
8.8 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access …

Jun 30, 2025
CVE-2025-6916
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of …

Jun 30, 2025
CVE-2025-52895
7.5 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could …

Jun 30, 2025
CVE-2025-45143
7.0 HIGH

string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.

Jun 30, 2025
CVE-2024-53621
7.5 HIGH

A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to cause a Denial of Service (DoS) via a crafted …

Jun 30, 2025
CVE-2025-6907
7.3 HIGH

A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unknown code of the file /book_car.php. The manipulation of …

Jun 30, 2025
CVE-2025-6906
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Car Rental System 1.0. This affects an unknown part of the file /login.php. The manipulation …

Jun 30, 2025
CVE-2025-6905
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue affects some unknown processing of the file …

Jun 30, 2025
CVE-2025-6904
7.3 HIGH

A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jun 30, 2025
CVE-2025-6903
7.3 HIGH

A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 30, 2025
CVE-2025-6902
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /php_action/editUser.php. …

Jun 30, 2025
CVE-2025-6901
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/removeUser.php. The …

Jun 30, 2025
CVE-2025-53416
7.8 HIGH

Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Jun 30, 2025
CVE-2024-8419
7.5 HIGH

The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing …

Jun 30, 2025
CVE-2025-53415
7.8 HIGH

Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Jun 30, 2025
CVE-2025-40732
7.5 HIGH

user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a POST request must be sent using the name parameter in /check.php

Jun 30, 2025
CVE-2025-38088
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mmap issue has an out …

Jun 30, 2025
CVE-2025-38087
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix use-after-free in taprio_dev_notifier Since taprio’s taprio_dev_notifier() isn’t protected by an RCU read-side critical …

Jun 30, 2025
CVE-2025-6891
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Inventory Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation …

Jun 30, 2025
CVE-2025-6889
7.3 HIGH

A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /logIn.php. …

Jun 30, 2025
CVE-2025-6888
7.3 HIGH

A vulnerability was found in PHPGurukul Teachers Record Management System 2.1. It has been classified as critical. This affects an unknown part of the file …

Jun 30, 2025
CVE-2025-6887
8.8 HIGH

A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetSysTimeCfg. The …

Jun 30, 2025
CVE-2025-6886
8.8 HIGH

A vulnerability has been found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. …

Jun 30, 2025
CVE-2025-6885
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of the file /admin/edit-teacher-detail.php. …

Jun 30, 2025
CVE-2025-6882
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-513 1.0. This affects an unknown part of the file /goform/formSetWanPPTP. The manipulation of the …

Jun 30, 2025
CVE-2025-6881
8.8 HIGH

A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Jun 30, 2025
CVE-2025-46014
8.8 HIGH

Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly …

Jun 30, 2025
CVE-2025-6871
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Simple Company Website 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation …

Jun 29, 2025
CVE-2025-24289
7.5 HIGH

A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if …

Jun 29, 2025
CVE-2025-6863
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of …

Jun 29, 2025
CVE-2025-5878
7.3 HIGH

A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack leads …

Jun 29, 2025
CVE-2025-6846
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Forum 1.0. This affects an unknown part of the file /forum_viewfile.php. The manipulation of …

Jun 29, 2025
CVE-2025-6845
7.3 HIGH

A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jun 29, 2025
CVE-2025-6844
7.3 HIGH

A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 29, 2025
CVE-2025-6843
7.3 HIGH

A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file /upload-photo.php. …

Jun 29, 2025
CVE-2025-6840
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Product Inventory System 1.0. This affects an unknown part of the file /index.php of …

Jun 29, 2025
CVE-2025-6836
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Library System 1.0. Affected is an unknown function of the file /profile.php. The manipulation of …

Jun 29, 2025
CVE-2025-6835
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student-issue-book.php. …

Jun 29, 2025
CVE-2025-6834
7.3 HIGH

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/editPayment.php. …

Jun 29, 2025
CVE-2025-6828
7.3 HIGH

A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /orders.php. The …

Jun 28, 2025
CVE-2025-6827
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affects an unknown part of the file /php_action/editOrder.php. The …

Jun 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.