CVE Database

46169+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40660
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting …

Jun 10, 2025
CVE-2025-40659
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting …

Jun 10, 2025
CVE-2025-40658
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting …

Jun 10, 2025
CVE-2025-5740
7.2 HIGH

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file writes when an authenticated user on …

Jun 10, 2025
CVE-2025-27819
7.5 HIGH

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is …

Jun 10, 2025
CVE-2025-27818
8.8 HIGH

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and …

Jun 10, 2025
CVE-2025-27817
7.5 HIGH

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER …

Jun 10, 2025
CVE-2025-4954
8.8 HIGH

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload …

Jun 10, 2025
CVE-2025-4840
7.5 HIGH

The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action …

Jun 10, 2025
CVE-2025-5952
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the function exec of the file …

Jun 10, 2025
CVE-2025-5934
8.8 HIGH

A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function sub_41619C of the file /mtd. …

Jun 10, 2025
CVE-2025-5913
7.3 HIGH

A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 10, 2025
CVE-2025-5912
8.8 HIGH

A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the function do_file of the component HTTP POST …

Jun 10, 2025
CVE-2025-4601
8.8 HIGH

The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is …

Jun 10, 2025
CVE-2025-4387
8.8 HIGH

The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in the wcap_add_to_cart_popup_upload_files function in …

Jun 10, 2025
CVE-2025-5911
8.8 HIGH

A vulnerability was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 10, 2025
CVE-2025-5910
8.8 HIGH

A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 10, 2025
CVE-2025-5909
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formReflashClientTbl of …

Jun 10, 2025
CVE-2025-5908
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file …

Jun 10, 2025
CVE-2025-5907
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formFilter of the component …

Jun 10, 2025
CVE-2025-5906
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manipulation leads …

Jun 10, 2025
CVE-2025-42995
7.5 HIGH

SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process …

Jun 10, 2025
CVE-2025-42994
7.5 HIGH

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process …

Jun 10, 2025
CVE-2025-42983
8.5 HIGH

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or …

Jun 10, 2025
CVE-2025-42982
8.8 HIGH

SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes …

Jun 10, 2025
CVE-2025-42977
7.6 HIGH

SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker …

Jun 10, 2025
CVE-2025-23192
8.2 HIGH

SAP BusinessObjects Business Intelligence (BI Workspace) allows an unauthenticated attacker to craft and store malicious script within a workspace. When the victim accesses the workspace, …

Jun 10, 2025
CVE-2025-5905
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file …

Jun 10, 2025
CVE-2025-5904
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file …

Jun 10, 2025
CVE-2025-5903
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the …

Jun 10, 2025
CVE-2025-5902
8.8 HIGH

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component …

Jun 9, 2025
CVE-2025-5901
8.8 HIGH

A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the …

Jun 9, 2025
CVE-2025-30183
7.5 HIGH

CyberData 011209 Intercom does not properly store or protect web server admin credentials.

Jun 9, 2025
CVE-2025-26468
7.5 HIGH

CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a denial-of-service condition or system disruption.

Jun 9, 2025
CVE-2025-49140
7.5 HIGH

Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a bug in a RTP packet factory that can be …

Jun 9, 2025
CVE-2025-49141
8.5 HIGH

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string …

Jun 9, 2025
CVE-2025-49137
8.5 HIGH

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user …

Jun 9, 2025
CVE-2025-49004
7.5 HIGH

Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caido can be loaded on …

Jun 9, 2025
CVE-2025-5914
7.8 HIGH

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to …

Jun 9, 2025
CVE-2025-49653
8.0 HIGH

Exposure of sensitive data in active sessions in Lablup's BackendAI allows attackers to retrieve credentials for users on the management platform.

Jun 9, 2025
CVE-2025-49651
8.1 HIGH

Missing Authorization in Lablup's BackendAI allows attackers to takeover all active sessions; Accessing, stealing, or altering any data accessible in the session. This vulnerability exists …

Jun 9, 2025
CVE-2025-45001
7.5 HIGH

react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers …

Jun 9, 2025
CVE-2025-49297
8.1 HIGH

Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.This issue affects Grill and Chow: from n/a through <= 1.6.

Jun 9, 2025
CVE-2025-49296
8.1 HIGH

Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6.

Jun 9, 2025
CVE-2025-49295
8.1 HIGH

Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This issue affects MediClinic: from n/a through <= 2.1.

Jun 9, 2025
CVE-2025-49282
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Magze magze allows PHP Local File Inclusion.This issue …

Jun 9, 2025
CVE-2025-49281
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Magways magways allows PHP Local File Inclusion.This issue …

Jun 9, 2025
CVE-2025-49280
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Magty magty allows PHP Local File Inclusion.This issue …

Jun 9, 2025
CVE-2025-49279
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Blogvy blogvy allows PHP Local File Inclusion.This issue …

Jun 9, 2025
CVE-2025-49278
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Blogty blogty allows PHP Local File Inclusion.This issue …

Jun 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.