CVE Database

46519+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2676
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file /add-subadmin.php. …

Mar 24, 2025
CVE-2025-2675
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. Affected by this issue is some unknown functionality …

Mar 24, 2025
CVE-2025-2674
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Bank Locker Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mar 24, 2025
CVE-2025-2665
7.3 HIGH

A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been classified as critical. This affects an unknown part of the …

Mar 23, 2025
CVE-2025-2663
7.3 HIGH

A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Mar 23, 2025
CVE-2025-2661
7.3 HIGH

A vulnerability was found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file …

Mar 23, 2025
CVE-2025-2660
7.3 HIGH

A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Mar 23, 2025
CVE-2025-2659
7.3 HIGH

A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file …

Mar 23, 2025
CVE-2025-2658
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0. Affected by this issue is some unknown …

Mar 23, 2025
CVE-2025-2657
7.3 HIGH

A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mar 23, 2025
CVE-2025-2656
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/login.php. The manipulation …

Mar 23, 2025
CVE-2025-2655
7.3 HIGH

A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation …

Mar 23, 2025
CVE-2025-29795
7.8 HIGH

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

Mar 23, 2025
CVE-2025-2654
7.3 HIGH

A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the …

Mar 23, 2025
CVE-2025-2691
8.2 HIGH

Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a …

Mar 23, 2025
CVE-2025-27553
7.5 HIGH

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. …

Mar 23, 2025
CVE-2025-2649
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0. This vulnerability affects unknown code of the file /check-appointment.php. The manipulation …

Mar 23, 2025
CVE-2025-2648
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/view-enquiry-detail.php. The …

Mar 23, 2025
CVE-2025-2647
7.3 HIGH

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 23, 2025
CVE-2025-2646
7.3 HIGH

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 23, 2025
CVE-2025-2644
7.3 HIGH

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add-art-product.php. …

Mar 23, 2025
CVE-2025-2643
7.3 HIGH

A vulnerability has been found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-art-type-detail.php?editid=1. …

Mar 23, 2025
CVE-2025-2642
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/edit-art-product-detail.php?editid=2. …

Mar 23, 2025
CVE-2025-2641
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. Affected by this issue is some unknown functionality …

Mar 23, 2025
CVE-2025-2640
7.3 HIGH

A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /doctor/appointment-bwdates-reports-details.php. …

Mar 23, 2025
CVE-2025-2186
7.5 HIGH

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’ parameter in …

Mar 22, 2025
CVE-2025-1971
7.2 HIGH

The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via …

Mar 22, 2025
CVE-2025-1970
7.6 HIGH

The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.2 via …

Mar 22, 2025
CVE-2025-2303
8.8 HIGH

The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, …

Mar 22, 2025
CVE-2025-0724
8.8 HIGH

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 …

Mar 22, 2025
CVE-2025-2610
7.6 HIGH

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with …

Mar 21, 2025
CVE-2025-2609
8.2 HIGH

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log …

Mar 21, 2025
CVE-2025-30204
7.5 HIGH

golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via …

Mar 21, 2025
CVE-2025-25035
7.3 HIGH

Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 allows for Reflected XSS and Stored XSS.This issue affects JPlatform …

Mar 21, 2025
CVE-2025-30349
7.2 HIGH

Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message …

Mar 21, 2025
CVE-2025-29230
8.6 HIGH

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.

Mar 21, 2025
CVE-2024-53350
7.4 HIGH

Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escalation of privileges.

Mar 21, 2025
CVE-2024-53349
7.4 HIGH

Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in …

Mar 21, 2025
CVE-2024-53348
7.4 HIGH

LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.

Mar 21, 2025
CVE-2025-29641
7.3 HIGH

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' parameter.

Mar 21, 2025
CVE-2025-24915
7.8 HIGH

When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. …

Mar 21, 2025
CVE-2024-57490
7.7 HIGH

Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system administrator through …

Mar 21, 2025
CVE-2025-25068
7.5 HIGH

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers …

Mar 21, 2025
CVE-2025-26336
8.3 HIGH

Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior …

Mar 21, 2025
CVE-2025-2585
8.8 HIGH

EBM Maintenance Center From EBM Technologies has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify, …

Mar 21, 2025
CVE-2025-29807
8.7 HIGH

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mar 21, 2025
CVE-2024-54551
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, …

Mar 21, 2025
CVE-2024-44305
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root …

Mar 21, 2025
CVE-2024-44199
7.1 HIGH

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may be able to cause unexpected …

Mar 21, 2025
CVE-2025-25758
7.5 HIGH

An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

Mar 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.