CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54261
10.0 CRITICAL

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could …

Sep 9, 2025
CVE-2025-47579
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.

Sep 9, 2025
CVE-2025-47569
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Blind SQL Injection.This issue …

Sep 9, 2025
CVE-2025-32486
9.8 CRITICAL

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.

Sep 9, 2025
CVE-2025-10183
9.1 CRITICAL

A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an …

Sep 9, 2025
CVE-2025-9994
9.8 CRITICAL

The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.

Sep 9, 2025
CVE-2025-54236
9.1 CRITICAL KEV

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this …

Sep 9, 2025
CVE-2025-40804
9.1 CRITICAL

A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This …

Sep 9, 2025
CVE-2025-40795
9.8 CRITICAL

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions), User …

Sep 9, 2025
CVE-2025-10134
9.1 CRITICAL

The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_restore_data() …

Sep 9, 2025
CVE-2025-42958
9.1 CRITICAL

Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or …

Sep 9, 2025
CVE-2025-42944
10.0 CRITICAL

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an …

Sep 9, 2025
CVE-2025-42922
9.9 CRITICAL

SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. …

Sep 9, 2025
CVE-2025-58746
9.0 CRITICAL

The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to …

Sep 8, 2025
CVE-2025-58745
9.9 CRITICAL

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only …

Sep 8, 2025
CVE-2025-9114
9.8 CRITICAL

The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0. This is due to the plugin …

Sep 8, 2025
CVE-2025-9113
9.8 CRITICAL

The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'doccure_temp_upload_to_media' function in all versions …

Sep 8, 2025
CVE-2025-57285
9.8 CRITICAL

codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, …

Sep 8, 2025
CVE-2025-56267
9.8 CRITICAL

A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.

Sep 8, 2025
CVE-2025-56266
9.8 CRITICAL

A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.

Sep 8, 2025
CVE-2025-57141
9.8 CRITICAL

rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.

Sep 8, 2025
CVE-2025-52161
9.8 CRITICAL

Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.

Sep 8, 2025
CVE-2025-22956
9.8 CRITICAL

OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState contains …

Sep 8, 2025
CVE-2025-58443
9.1 CRITICAL

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to …

Sep 6, 2025
CVE-2025-8359
9.8 CRITICAL

The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not …

Sep 6, 2025
CVE-2025-58371
9.8 CRITICAL

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github workflow used unsanitized pull request …

Sep 5, 2025
CVE-2025-35452
9.8 CRITICAL

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.

Sep 5, 2025
CVE-2025-35451
9.8 CRITICAL

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cracked. Many cameras have SSH or telnet listening …

Sep 5, 2025
CVE-2025-58628
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous miraculous allows Blind SQL Injection.This issue affects Miraculous: from …

Sep 5, 2025
CVE-2025-49401
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue affects smart SEO: from n/a through <= 4.0.

Sep 5, 2025
CVE-2025-58819
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web Server.This issue affects …

Sep 5, 2025
CVE-2025-55037
9.8 CRITICAL

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is …

Sep 5, 2025
CVE-2025-55244
9.0 CRITICAL

Azure Bot Service Elevation of Privilege Vulnerability

Sep 4, 2025
CVE-2025-55241
10.0 CRITICAL

Azure Entra ID Elevation of Privilege Vulnerability

Sep 4, 2025
CVE-2025-55190
9.9 CRITICAL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through …

Sep 4, 2025
CVE-2025-54914
10.0 CRITICAL

Azure Networking Elevation of Privilege Vulnerability

Sep 4, 2025
CVE-2025-58361
9.3 CRITICAL

Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive URL scheme check that does not protect …

Sep 4, 2025
CVE-2025-41034
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2025-41033
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2025-41032
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2025-58357
9.6 CRITICAL

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 contains a vulnerability in the chat page's script gadgets that …

Sep 4, 2025
CVE-2025-36904
9.8 CRITICAL

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

Sep 4, 2025
CVE-2025-36897
9.8 CRITICAL

In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Sep 4, 2025
CVE-2025-36896
9.8 CRITICAL

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

Sep 4, 2025
CVE-2025-36890
9.8 CRITICAL

Elevation of Privilege

Sep 4, 2025
CVE-2025-55747
9.1 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are …

Sep 3, 2025
CVE-2025-53690
9.0 CRITICAL KEV

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience …

Sep 3, 2025
CVE-2025-56752
9.4 CRITICAL

A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter …

Sep 3, 2025
CVE-2025-57148
9.1 CRITICAL

phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.

Sep 3, 2025
CVE-2025-57052
9.8 CRITICAL

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data …

Sep 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.