CVE Database

46169+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4231
7.2 HIGH

A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have …

Jun 13, 2025
CVE-2025-27689
7.8 HIGH

Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, …

Jun 12, 2025
CVE-2025-6031
7.5 HIGH

Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. …

Jun 12, 2025
CVE-2025-5485
8.6 HIGH

User names used to access the web management interface are limited to the device identifier, which is a numerical identifier no more than 10 digits. …

Jun 12, 2025
CVE-2025-5484
8.3 HIGH

A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on …

Jun 12, 2025
CVE-2025-44019
7.1 HIGH

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI …

Jun 12, 2025
CVE-2025-43866
7.5 HIGH

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The …

Jun 12, 2025
CVE-2025-49080
7.5 HIGH

There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a …

Jun 12, 2025
CVE-2024-55567
7.5 HIGH

Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.01, 5.6 before 05.62.01, and 5.7 before 05.71.01. The …

Jun 12, 2025
CVE-2025-46035
7.5 HIGH

Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in …

Jun 12, 2025
CVE-2025-36573
7.1 HIGH

Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially …

Jun 12, 2025
CVE-2025-49199
8.8 HIGH

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. …

Jun 12, 2025
CVE-2025-49194
7.5 HIGH

The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept traffic between a client …

Jun 12, 2025
CVE-2025-49184
7.5 HIGH

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.

Jun 12, 2025
CVE-2025-49183
7.5 HIGH

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the …

Jun 12, 2025
CVE-2025-49182
7.5 HIGH

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to …

Jun 12, 2025
CVE-2025-49181
8.6 HIGH

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP …

Jun 12, 2025
CVE-2025-6021
7.5 HIGH

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can …

Jun 12, 2025
CVE-2025-0673
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker …

Jun 12, 2025
CVE-2025-4278
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page …

Jun 12, 2025
CVE-2025-2254
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding …

Jun 12, 2025
CVE-2025-4613
8.8 HIGH

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into …

Jun 12, 2025
CVE-2025-5012
8.8 HIGH

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type …

Jun 12, 2025
CVE-2025-35978
7.1 HIGH

Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local …

Jun 12, 2025
CVE-2025-25032
7.5 HIGH

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service …

Jun 11, 2025
CVE-2025-6002
7.2 HIGH

An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable …

Jun 11, 2025
CVE-2025-6001
8.3 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able …

Jun 11, 2025
CVE-2025-40915
7.0 HIGH

Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of …

Jun 11, 2025
CVE-2025-22874
7.5 HIGH

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

Jun 11, 2025
CVE-2025-49148
7.3 HIGH

ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL search order and …

Jun 11, 2025
CVE-2025-49146
8.2 HIGH

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to …

Jun 11, 2025
CVE-2025-48447
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Lightgallery allows Cross-Site Scripting (XSS).This issue affects Lightgallery: from 0.0.0 before 1.6.0.

Jun 11, 2025
CVE-2025-48446
8.8 HIGH

Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.0.0 before 1.0.3.

Jun 11, 2025
CVE-2025-48445
8.8 HIGH

Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redirect): from 0.0.0 before 2.1.1.

Jun 11, 2025
CVE-2025-4922
8.1 HIGH

Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed …

Jun 11, 2025
CVE-2025-5687
7.8 HIGH

A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other …

Jun 11, 2025
CVE-2025-3302
7.2 HIGH

The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, …

Jun 11, 2025
CVE-2025-4315
8.8 HIGH

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is …

Jun 11, 2025
CVE-2025-41661
8.8 HIGH

An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection.

Jun 11, 2025
CVE-2025-5395
8.8 HIGH

The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php' file in all …

Jun 11, 2025
CVE-2025-4799
7.2 HIGH

The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from …

Jun 11, 2025
CVE-2024-1243
7.2 HIGH

Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key …

Jun 11, 2025
CVE-2025-5959
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Jun 11, 2025
CVE-2025-5958
8.8 HIGH

Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2025
CVE-2025-4275
7.8 HIGH

A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a …

Jun 11, 2025
CVE-2025-49091
8.2 HIGH

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or …

Jun 11, 2025
CVE-2025-32717
8.4 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jun 11, 2025
CVE-2024-9062
7.8 HIGH

The Archify application contains a local privilege escalation vulnerability due to insufficient client validation in its privileged helper tool, com.oct4pie.archifyhelper, which is exposed via XPC. …

Jun 11, 2025
CVE-2024-7457
7.8 HIGH

The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the client's authorization reference, the helper invokes …

Jun 11, 2025
CVE-2025-5985
7.3 HIGH

A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation …

Jun 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.