CVE Database

46169+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6117
7.3 HIGH

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jun 16, 2025
CVE-2025-6116
7.3 HIGH

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affects an unknown part of the file …

Jun 16, 2025
CVE-2025-6115
8.8 HIGH

A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function form_macfilter. The manipulation of the argument …

Jun 16, 2025
CVE-2025-6114
8.8 HIGH

A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is the function form_portforwarding of the file /goform/form_portforwarding. …

Jun 16, 2025
CVE-2025-40728
8.8 HIGH

SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter …

Jun 16, 2025
CVE-2025-6113
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of …

Jun 16, 2025
CVE-2025-6112
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The …

Jun 16, 2025
CVE-2025-4987
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to …

Jun 16, 2025
CVE-2025-6111
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the …

Jun 16, 2025
CVE-2025-6110
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the …

Jun 16, 2025
CVE-2025-6104
8.8 HIGH

A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/pms_check.php. …

Jun 16, 2025
CVE-2025-6103
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functionality …

Jun 16, 2025
CVE-2025-6102
8.8 HIGH

A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file …

Jun 16, 2025
CVE-2025-6095
7.3 HIGH

A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unknown function of the file /checklogin.php. The manipulation …

Jun 15, 2025
CVE-2025-5990
7.6 HIGH

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored …

Jun 15, 2025
CVE-2025-6091
8.8 HIGH

A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation …

Jun 15, 2025
CVE-2025-6090
8.8 HIGH

A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function UpdateWanparamsMulti/UpdateIpv6params of the file /routing/goform/aspForm. The manipulation of …

Jun 15, 2025
CVE-2025-1411
7.8 HIGH

IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges.

Jun 15, 2025
CVE-2025-4200
8.1 HIGH

The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Jun 14, 2025
CVE-2025-5487
7.2 HIGH

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the …

Jun 14, 2025
CVE-2025-3234
7.2 HIGH

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up …

Jun 14, 2025
CVE-2025-33108
8.5 HIGH

IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to …

Jun 14, 2025
CVE-2025-25215
8.8 HIGH

An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted …

Jun 13, 2025
CVE-2025-24919
8.1 HIGH

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially …

Jun 13, 2025
CVE-2025-25050
8.8 HIGH

An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially …

Jun 13, 2025
CVE-2025-24922
8.8 HIGH

A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially …

Jun 13, 2025
CVE-2025-24311
8.4 HIGH

An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted …

Jun 13, 2025
CVE-2025-49587
8.0 HIGH

XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits …

Jun 13, 2025
CVE-2025-49586
8.8 HIGH

XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all …

Jun 13, 2025
CVE-2025-49585
8.0 HIGH

XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right …

Jun 13, 2025
CVE-2025-49584
7.5 HIGH

XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.0-rc-1, the title of every single page whose …

Jun 13, 2025
CVE-2025-49582
8.0 HIGH

XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer …

Jun 13, 2025
CVE-2025-49581
8.8 HIGH

XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) …

Jun 13, 2025
CVE-2025-49580
8.0 HIGH

XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain …

Jun 13, 2025
CVE-2025-48920
7.3 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0.

Jun 13, 2025
CVE-2025-48918
8.8 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klaro allows Cross-Site Scripting (XSS).This issue affects Simple Klaro: from 0.0.0 …

Jun 13, 2025
CVE-2025-48915
8.6 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: …

Jun 13, 2025
CVE-2025-48914
8.6 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: …

Jun 13, 2025
CVE-2025-36633
8.8 HIGH

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with …

Jun 13, 2025
CVE-2025-36631
8.4 HIGH

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with …

Jun 13, 2025
CVE-2025-28382
7.5 HIGH

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

Jun 13, 2025
CVE-2025-28381
7.5 HIGH

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

Jun 13, 2025
CVE-2025-39240
7.2 HIGH

Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw …

Jun 13, 2025
CVE-2025-22239
8.1 HIGH

Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event …

Jun 13, 2025
CVE-2025-22236
8.1 HIGH

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job …

Jun 13, 2025
CVE-2025-5282
7.5 HIGH

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized loss of data due to a …

Jun 13, 2025
CVE-2025-5491
8.8 HIGH

Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this …

Jun 13, 2025
CVE-2025-47959
7.1 HIGH

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.

Jun 13, 2025
CVE-2025-30399
7.5 HIGH

Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

Jun 13, 2025
CVE-2025-4232
8.8 HIGH

An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to …

Jun 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.