CVE Database

58607+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48206
6.1 MEDIUM

The ns_backup extension through 13.0.0 for TYPO3 allows XSS.

May 21, 2025
CVE-2025-48204
6.8 MEDIUM

The ns_backup extension through 13.0.0 for TYPO3 allows command injection.

May 21, 2025
CVE-2025-48203
6.4 MEDIUM

The cs_seo extension through 9.2.0 for TYPO3 allows XSS.

May 21, 2025
CVE-2025-48202
5.3 MEDIUM

The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.

May 21, 2025
CVE-2025-5029
5.4 MEDIUM

A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by …

May 21, 2025
CVE-2024-23337
4.3 MEDIUM

jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, …

May 21, 2025
CVE-2025-44895
6.5 MEDIUM

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.

May 21, 2025
CVE-2025-44892
6.5 MEDIUM

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.

May 21, 2025
CVE-2024-42922
6.5 MEDIUM

AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.

May 21, 2025
CVE-2025-48417
6.5 MEDIUM

The certificate and private key used for providing transport layer security for connections to the web interface (TCP port 443) is hard-coded in the firmware …

May 21, 2025
CVE-2025-48415
6.2 MEDIUM

A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted "salia.ini" files. The .ini file can contain several "commands" …

May 21, 2025
CVE-2025-4611
6.4 MEDIUM

The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in …

May 21, 2025
CVE-2025-4221
6.4 MEDIUM

The Animated Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-downloader' shortcode in all versions up to, and including, 1.0.0 …

May 21, 2025
CVE-2025-4219
6.4 MEDIUM

The DPEPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dpe' shortcode in all versions up to, and including, 0.3 due …

May 21, 2025
CVE-2025-4217
6.4 MEDIUM

The WP YouTube Video Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ib_youtube' shortcode in all versions up to, and …

May 21, 2025
CVE-2025-4105
5.4 MEDIUM

The Splitit plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions in the 'splitIt-flexfields-payment-gateway.php' file in …

May 21, 2025
CVE-2025-48414
6.5 MEDIUM

There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functionality and are …

May 21, 2025
CVE-2025-3781
6.4 MEDIUM

The Raisely Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's raisely_donation_form shortcode in all versions up to, and including, …

May 21, 2025
CVE-2025-3750
6.4 MEDIUM

The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ parameter in all versions up to, and including, 7.7.1 …

May 21, 2025
CVE-2025-27804
6.5 MEDIUM

Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publishing a specially crafted message to a certain MQTT topic …

May 21, 2025
CVE-2025-27803
6.5 MEDIUM

The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network access to the device immediately …

May 21, 2025
CVE-2024-12561
6.1 MEDIUM

The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.0. …

May 21, 2025
CVE-2025-4949
5.3 MEDIUM

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 …

May 21, 2025
CVE-2021-25262
5.4 MEDIUM

Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.

May 21, 2025
CVE-2021-25254
5.3 MEDIUM

Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.

May 21, 2025
CVE-2025-5013
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the …

May 21, 2025
CVE-2025-4969
6.5 MEDIUM

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can …

May 21, 2025
CVE-2025-5000
6.3 MEDIUM

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the …

May 20, 2025
CVE-2025-4999
6.3 MEDIUM

A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function sub_4153FC of …

May 20, 2025
CVE-2025-4998
6.5 MEDIUM

A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of …

May 20, 2025
CVE-2025-4997
6.5 MEDIUM

A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function UpdateWanParams/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList/Edit_BasicSSID/Edit_GuestSSIDFor2P4G/Edit_BasicSSID_5G/SetAPInfoById of the file /goform/aspForm of …

May 20, 2025
CVE-2025-48056
5.3 MEDIUM

Hubble is a fully distributed networking and security observability platform for cloud native workloads. Prior to version 1.17.2, a network attacker could inject malicious control …

May 20, 2025
CVE-2025-47290
5.9 MEDIUM

containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially …

May 20, 2025
CVE-2025-47854
4.3 MEDIUM

In JetBrains TeamCity before 2025.03.2 open redirect was possible on editing VCS Root page

May 20, 2025
CVE-2025-47853
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via Jira integration was possible

May 20, 2025
CVE-2025-47852
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possible

May 20, 2025
CVE-2025-47851
4.8 MEDIUM

In JetBrains TeamCity before 2025.03.2 stored XSS via GitHub Checks Webhook was possible

May 20, 2025
CVE-2025-47850
4.3 MEDIUM

In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

May 20, 2025
CVE-2025-37990
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The function brcmf_usb_dl_writeimage() calls the function brcmf_usb_dl_cmd() …

May 20, 2025
CVE-2025-37989
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: phy: leds: fix memory leak A network restart test on a router led to …

May 20, 2025
CVE-2025-37988
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fix a couple of races in MNT_TREE_BENEATH handling by do_move_mount() Normally do_lock_mount(path, _) is locking …

May 20, 2025
CVE-2025-37987
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent possible adminq overflow/stuck condition The pds_core's adminq is protected by the adminq_lock, which …

May 20, 2025
CVE-2025-37986
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: typec: class: Invalidate USB device pointers on partner unregistration To avoid using invalid USB …

May 20, 2025
CVE-2025-37985
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wdm_open and wdm_wwan_port_stop Clearing WDM_WWAN_IN_USE must be the last action …

May 20, 2025
CVE-2025-37984
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow …

May 20, 2025
CVE-2025-37983
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: qibfs: fix _another_ leak failure to allocate inode => leaked dentry... this one had been …

May 20, 2025
CVE-2025-37982
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: fix memory leak in wl1251_tx_work The skb dequeued from tx_queue is lost when …

May 20, 2025
CVE-2025-37980
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix resource leak in blk_register_queue() error path When registering a queue fails after blk_mq_sysfs_register() …

May 20, 2025
CVE-2025-37978
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: integrity: Do not call set_page_dirty_lock() Placing multiple protection information buffers inside the same page …

May 20, 2025
CVE-2025-37977
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set If dma-coherent property isn't set …

May 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.