CVE Database

58482+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49069
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in cimatti Contact Forms by Cimatti contact-forms allows Cross Site Request Forgery.This issue affects Contact Forms by Cimatti: from n/a …

Jun 2, 2025
CVE-2025-45387
5.4 MEDIUM

osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

Jun 2, 2025
CVE-2025-27955
6.5 MEDIUM

Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive …

Jun 2, 2025
CVE-2025-27954
6.5 MEDIUM

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.

Jun 2, 2025
CVE-2025-27953
6.5 MEDIUM

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.

Jun 2, 2025
CVE-2025-23104
6.5 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privilege escalation.

Jun 2, 2025
CVE-2025-20297
4.3 MEDIUM

In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not …

Jun 2, 2025
CVE-2024-8008
5.2 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to insufficient output encoding in error messages generated by the JDBC user store …

Jun 2, 2025
CVE-2024-7074
6.8 MEDIUM

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with …

Jun 2, 2025
CVE-2024-7073
6.5 MEDIUM

A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers …

Jun 2, 2025
CVE-2024-3509
4.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor …

Jun 2, 2025
CVE-2024-1440
5.4 MEDIUM

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is …

Jun 2, 2025
CVE-2025-48941
5.3 MEDIUM

MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine …

Jun 2, 2025
CVE-2025-44115
5.4 MEDIUM

A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads …

Jun 2, 2025
CVE-2024-40114
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before allows an attacker to manipulate the language cookie …

Jun 2, 2025
CVE-2024-40113
6.5 MEDIUM

Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.

Jun 2, 2025
CVE-2024-40112
5.9 MEDIUM

A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the …

Jun 2, 2025
CVE-2025-44172
6.5 MEDIUM

Tenda AC6 V15.03.05.16 was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

Jun 2, 2025
CVE-2025-20001
6.5 MEDIUM

An out-of-bounds read vulnerability exists in High-Logic FontCreator 15.0.0.3015. A specially crafted font file can trigger this vulnerability which can lead to disclosure of sensitive …

Jun 2, 2025
CVE-2025-5447
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function …

Jun 2, 2025
CVE-2025-37094
5.5 MEDIUM

A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-5446
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS …

Jun 2, 2025
CVE-2025-5445
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function …

Jun 2, 2025
CVE-2025-5444
6.3 MEDIUM

A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this vulnerability is the …

Jun 2, 2025
CVE-2025-5443
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function wirelessAdvancedHidden of …

Jun 2, 2025
CVE-2025-48958
5.5 MEDIUM

Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject …

Jun 2, 2025
CVE-2025-48955
6.2 MEDIUM

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret …

Jun 2, 2025
CVE-2025-48495
5.4 MEDIUM

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly name of an API key, an authenticated user …

Jun 2, 2025
CVE-2025-5442
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function …

Jun 2, 2025
CVE-2025-5441
6.3 MEDIUM

A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setDeviceURL of the …

Jun 2, 2025
CVE-2025-48494
5.4 MEDIUM

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encryption, a stored cross-site scripting vulnerability can be exploited …

Jun 2, 2025
CVE-2025-47289
6.3 MEDIUM

CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an …

Jun 2, 2025
CVE-2025-47272
5.5 MEDIUM

The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. …

Jun 2, 2025
CVE-2025-3454
5.0 MEDIUM

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with …

Jun 2, 2025
CVE-2025-5440
6.3 MEDIUM

A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function NTP of the …

Jun 2, 2025
CVE-2025-5439
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rated as critical. Affected by this issue is …

Jun 2, 2025
CVE-2025-5438
6.3 MEDIUM

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Affected by this vulnerability is …

Jun 2, 2025
CVE-2025-5437
5.3 MEDIUM

A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component …

Jun 2, 2025
CVE-2025-5436
5.3 MEDIUM

A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi. …

Jun 2, 2025
CVE-2025-0325
4.3 MEDIUM

A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the …

Jun 2, 2025
CVE-2025-5433
6.3 MEDIUM

A vulnerability was found in Fengoffice Feng Office 3.5.1.5 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php?c=account&a=set_timezone. …

Jun 2, 2025
CVE-2025-1235
4.3 MEDIUM

A low privileged attacker can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This …

Jun 2, 2025
CVE-2025-5432
6.3 MEDIUM

A vulnerability has been found in AssamLook CMS 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_tender.php. …

Jun 2, 2025
CVE-2025-5431
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of the file /department-profile.php. The manipulation of …

Jun 2, 2025
CVE-2025-3951
4.1 MEDIUM

The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role …

Jun 2, 2025
CVE-2025-1485
4.8 MEDIUM

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent WordPress plugin before 5.1.6, real-cookie-banner-pro WordPress plugin before 5.1.6 does not sanitise and escape some of …

Jun 2, 2025
CVE-2025-5430
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in AssamLook CMS 1.0. This issue affects some unknown processing of the file /product.php. The …

Jun 2, 2025
CVE-2025-5429
6.3 MEDIUM

A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /admin-cp/plugin/install of the component …

Jun 2, 2025
CVE-2025-5428
6.3 MEDIUM

A vulnerability classified as critical has been found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/log-viewer of the …

Jun 2, 2025
CVE-2025-5427
6.3 MEDIUM

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jun 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.