CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9288
9.1 CRITICAL

Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.

Aug 20, 2025
CVE-2025-9287
9.1 CRITICAL

Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.

Aug 20, 2025
CVE-2024-57155
9.8 CRITICAL

Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.

Aug 20, 2025
CVE-2024-57154
9.8 CRITICAL

Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.

Aug 20, 2025
CVE-2025-55746
9.3 CRITICAL

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update …

Aug 20, 2025
CVE-2025-8611
9.8 CRITICAL

AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Aug 20, 2025
CVE-2025-8610
9.8 CRITICAL

AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Aug 20, 2025
CVE-2025-55444
9.8 CRITICAL

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker …

Aug 20, 2025
CVE-2025-50904
9.8 CRITICAL

There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any …

Aug 20, 2025
CVE-2025-50901
9.8 CRITICAL

JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file reading.

Aug 20, 2025
CVE-2024-50640
9.8 CRITICAL

jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function

Aug 20, 2025
CVE-2024-57157
9.8 CRITICAL

Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.

Aug 20, 2025
CVE-2011-10026
9.8 CRITICAL

Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell …

Aug 20, 2025
CVE-2010-20103
9.8 CRITICAL

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden …

Aug 20, 2025
CVE-2025-27129
9.8 CRITICAL

An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code …

Aug 20, 2025
CVE-2025-54726
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects …

Aug 20, 2025
CVE-2025-54713
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse.This issue affects Taxi Booking Manager …

Aug 20, 2025
CVE-2025-54677
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Malicious Files.This issue …

Aug 20, 2025
CVE-2025-54049
9.9 CRITICAL

Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2.

Aug 20, 2025
CVE-2025-54048
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects …

Aug 20, 2025
CVE-2025-54014
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Object Injection.This issue affects MediCenter - Health Medical Clinic: from n/a …

Aug 20, 2025
CVE-2025-53580
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.

Aug 20, 2025
CVE-2025-53577
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Code Inclusion.This issue affects Global DNS: from n/a through …

Aug 20, 2025
CVE-2025-53299
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer allows Object Injection.This issue affects ThemeMakers Visual Content Composer: from n/a through <= …

Aug 20, 2025
CVE-2025-53213
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping elex-reachship-multi-carrier-conditional-shipping allows Using Malicious Files.This issue affects ReachShip WooCommerce …

Aug 20, 2025
CVE-2025-49890
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in ThemeREX Organic Beauty organic-beauty allows Object Injection.This issue affects Organic Beauty: from n/a through <= 1.4.6.

Aug 20, 2025
CVE-2025-49434
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue affects Cars4Rent: from n/a through <= 1.4.2.

Aug 20, 2025
CVE-2025-49422
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.This issue affects Support Ticket: from n/a through <= 1.9.

Aug 20, 2025
CVE-2025-49410
10.0 CRITICAL

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testimonials allows Stored XSS. This issue affects TC Testimonials: from …

Aug 20, 2025
CVE-2025-49409
9.8 CRITICAL

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SensorPress allows Stored XSS. This issue affects SensorPress: from n/a through 1.0.

Aug 20, 2025
CVE-2025-49408
10.0 CRITICAL

Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data. This issue affects Templately: from n/a through 3.2.7.

Aug 20, 2025
CVE-2025-49400
9.8 CRITICAL

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects …

Aug 20, 2025
CVE-2025-49381
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Site Request Forgery.This issue affects ads.txt Guru Connect: from n/a through …

Aug 20, 2025
CVE-2025-48169
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Remote Code Inclusion.This issue affects Code Engine: from n/a …

Aug 20, 2025
CVE-2025-48148
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Using Malicious Files.This issue affects StoreKeeper for WooCommerce: from …

Aug 20, 2025
CVE-2025-9187
9.8 CRITICAL

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Aug 19, 2025
CVE-2025-9179
9.8 CRITICAL

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly …

Aug 19, 2025
CVE-2025-8042
9.8 CRITICAL

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.

Aug 19, 2025
CVE-2025-55031
9.8 CRITICAL

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …

Aug 19, 2025
CVE-2025-54145
9.1 CRITICAL

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL …

Aug 19, 2025
CVE-2025-54143
9.8 CRITICAL

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed …

Aug 19, 2025
CVE-2025-51543
9.8 CRITICAL

An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password endpoint.

Aug 19, 2025
CVE-2025-55733
9.6 CRITICAL

DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker …

Aug 19, 2025
CVE-2025-55306
9.8 CRITICAL

GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys …

Aug 19, 2025
CVE-2024-44373
9.8 CRITICAL

A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content …

Aug 19, 2025
CVE-2025-55294
9.8 CRITICAL

screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option …

Aug 19, 2025
CVE-2025-54336
9.8 CRITICAL

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can …

Aug 19, 2025
CVE-2025-50567
10.0 CRITICAL

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL …

Aug 19, 2025
CVE-2025-8723
9.8 CRITICAL

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in …

Aug 19, 2025
CVE-2025-6758
9.8 CRITICAL

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, …

Aug 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.