CVE Database

58391+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-52985
5.3 MEDIUM

A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security …

Jul 11, 2025
CVE-2025-52984
5.9 MEDIUM

A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker …

Jul 11, 2025
CVE-2025-52982
5.9 MEDIUM

An Improper Resource Shutdown or Release vulnerability in the SIP ALG of Juniper Networks Junos OS on MX Series with MS-MPC allows an unauthenticated, network-based …

Jul 11, 2025
CVE-2025-52994
4.9 MEDIUM

gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.

Jul 11, 2025
CVE-2025-52964
6.5 MEDIUM

A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to …

Jul 11, 2025
CVE-2025-52963
5.5 MEDIUM

An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, …

Jul 11, 2025
CVE-2025-52958
5.3 MEDIUM

A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to …

Jul 11, 2025
CVE-2025-52955
6.5 MEDIUM

An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent …

Jul 11, 2025
CVE-2025-52953
6.5 MEDIUM

An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker …

Jul 11, 2025
CVE-2025-52952
6.5 MEDIUM

An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line …

Jul 11, 2025
CVE-2025-52951
5.8 MEDIUM

A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to …

Jul 11, 2025
CVE-2025-52949
6.5 MEDIUM

An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a …

Jul 11, 2025
CVE-2025-52948
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker, in rare cases, sending …

Jul 11, 2025
CVE-2025-52947
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper Networks Junos OS on specific end-of-life (EOL) ACX Series platforms allows an attacker …

Jul 11, 2025
CVE-2025-48924
5.3 MEDIUM

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. …

Jul 11, 2025
CVE-2023-38329
6.1 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A cross-site scripting Reflected (XSS) vulnerability exists in calendar/freebusy.php, which allows unauthenticated remote attackers to inject arbitrary web …

Jul 11, 2025
CVE-2023-38327
5.3 MEDIUM

An issue was discovered in eGroupWare 17.1.20190111. A User Enumeration vulnerability exists under calendar/freebusy.php, which allows unauthenticated remote attackers to enumerate the users of web …

Jul 11, 2025
CVE-2025-3933
5.3 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the DonutProcessor class's `token2json()` method. This vulnerability …

Jul 11, 2025
CVE-2025-6838
4.1 MEDIUM

The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are …

Jul 11, 2025
CVE-2025-6745
5.3 MEDIUM

The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.2.5 via the woodmart_get_posts_by_query() function due to insufficient …

Jul 11, 2025
CVE-2025-6068
6.4 MEDIUM

The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption-title` & …

Jul 11, 2025
CVE-2025-5530
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shortcode_btn' shortcode in all versions up to, …

Jul 11, 2025
CVE-2025-4593
6.5 MEDIUM

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the …

Jul 11, 2025
CVE-2025-6716
6.4 MEDIUM

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress …

Jul 11, 2025
CVE-2025-6200
5.9 MEDIUM

The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Jul 11, 2025
CVE-2025-30024
6.8 MEDIUM

The communication protocol used between client and server had a flaw that could be leveraged to execute a man in the middle attack.

Jul 11, 2025
CVE-2025-2942
4.3 MEDIUM

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing …

Jul 11, 2025
CVE-2025-53864
5.8 MEDIUM

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply …

Jul 11, 2025
CVE-2025-5241
5.3 MEDIUM

Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series allows a remote unauthenticated attacker to lockout legitimate users for a certain …

Jul 11, 2025
CVE-2025-53519
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, …

Jul 11, 2025
CVE-2025-53509
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. …

Jul 11, 2025
CVE-2025-53471
5.1 MEDIUM

Emerson ValveLink products receive input or data, but it do not validate or incorrectly validates that the input has the properties that are required to …

Jul 11, 2025
CVE-2025-53397
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, …

Jul 11, 2025
CVE-2025-52459
6.5 MEDIUM

A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain …

Jul 11, 2025
CVE-2025-48496
5.1 MEDIUM

Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the …

Jul 11, 2025
CVE-2025-46704
4.3 MEDIUM

A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least …

Jul 11, 2025
CVE-2025-41442
5.4 MEDIUM

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input …

Jul 11, 2025
CVE-2025-31267
4.6 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an …

Jul 10, 2025
CVE-2025-6392
4.4 MEDIUM

Brocade SANnav before Brocade SANnav 2.4.0a could log database passwords in clear text in audit logs when the daily data dump collector invokes docker exec …

Jul 10, 2025
CVE-2025-53637
4.1 MEDIUM

Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be …

Jul 10, 2025
CVE-2025-24798
4.3 MEDIUM

Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. …

Jul 10, 2025
CVE-2025-7415
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of …

Jul 10, 2025
CVE-2025-7414
6.3 MEDIUM

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. …

Jul 10, 2025
CVE-2025-6390
4.4 MEDIUM

Brocade SANnav before SANnav 2.4.0a logs passwords and pbe keys in the Brocade SANnav server audit logs after installation and under specific conditions. These audit …

Jul 10, 2025
CVE-2025-4662
4.4 MEDIUM

Brocade SANnav before SANnav 2.4.0a logs plaintext passphrases in the Brocade SANnav host server audit logs while executing OpenSSL command using a passphrase from the …

Jul 10, 2025
CVE-2025-2522
6.5 MEDIUM

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit …

Jul 10, 2025
CVE-2025-7413
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/profile.php. The manipulation of …

Jul 10, 2025
CVE-2025-7412
6.3 MEDIUM

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jul 10, 2025
CVE-2025-7021
6.5 MEDIUM

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker …

Jul 10, 2025
CVE-2025-45662
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's …

Jul 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.