CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-55591
9.8 CRITICAL

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.

Aug 18, 2025
CVE-2025-55213
9.8 CRITICAL

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1.9.4 ( openfga-0.2.40 <= Helm chart …

Aug 18, 2025
CVE-2025-55299
9.4 CRITICAL

VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty …

Aug 18, 2025
CVE-2025-55293
9.4 CRITICAL

Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with …

Aug 18, 2025
CVE-2025-55283
9.1 CRITICAL

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superuser inside PostgreSQL databases during …

Aug 18, 2025
CVE-2025-55282
9.1 CRITICAL

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to superuser inside …

Aug 18, 2025
CVE-2025-55205
9.0 CRITICAL

Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant users to inject …

Aug 18, 2025
CVE-2025-54117
9.0 CRITICAL

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated …

Aug 18, 2025
CVE-2025-31715
9.8 CRITICAL

In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional …

Aug 18, 2025
CVE-2025-8898
9.8 CRITICAL

The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and …

Aug 16, 2025
CVE-2025-7441
9.8 CRITICAL

The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the /wp-json/storychief/webhook …

Aug 16, 2025
CVE-2025-9060
9.1 CRITICAL

A vulnerability has been found in the MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration …

Aug 15, 2025
CVE-2025-8995
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.4.

Aug 15, 2025
CVE-2025-54466
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before …

Aug 15, 2025
CVE-2025-7778
9.8 CRITICAL

The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in …

Aug 15, 2025
CVE-2025-6679
9.8 CRITICAL

The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and …

Aug 15, 2025
CVE-2025-20265
10.0 CRITICAL

A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell …

Aug 14, 2025
CVE-2025-50518
9.8 CRITICAL

A use-after-free vulnerability exists in the coap_delete_pdu_lkd function within coap_pdu.c of the libcoap library. This issue occurs due to improper handling of memory after the …

Aug 14, 2025
CVE-2025-7972
9.1 CRITICAL

A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass …

Aug 14, 2025
CVE-2025-43983
9.1 CRITICAL

KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and goform/goform_get_cmd_process. These allow an unauthenticated attacker to retrieve sensitive information (including the …

Aug 14, 2025
CVE-2025-27845
9.8 CRITICAL

In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated …

Aug 14, 2025
CVE-2025-43984
9.8 CRITICAL

An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable to unauthenticated /goform/goform_set_cmd_process requests. A crafted POST request, …

Aug 14, 2025
CVE-2025-54707
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows SQL Injection.This issue affects MDTF: from n/a …

Aug 14, 2025
CVE-2025-54693
9.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block form-block allows Upload a Web Shell to a Web Server.This issue affects Form …

Aug 14, 2025
CVE-2025-54686
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio exertio allows Object Injection.This issue affects Exertio: from n/a through <= 1.3.2.

Aug 14, 2025
CVE-2025-54678
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects …

Aug 14, 2025
CVE-2025-54669
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RomanCode MapSVG mapsvg allows SQL Injection.This issue affects MapSVG: from n/a …

Aug 14, 2025
CVE-2025-52720
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp allows SQL Injection.This issue affects Super …

Aug 14, 2025
CVE-2025-49887
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Remote Code Inclusion.This issue affects Product …

Aug 14, 2025
CVE-2025-49059
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: …

Aug 14, 2025
CVE-2025-48293
9.8 CRITICAL

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows PHP Local File …

Aug 14, 2025
CVE-2025-25174
10.0 CRITICAL

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extensions beeteam368-extensions allows PHP Local File Inclusion.This …

Aug 14, 2025
CVE-2025-24775
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issue affects Forms: …

Aug 14, 2025
CVE-2025-8943
9.8 CRITICAL

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent …

Aug 14, 2025
CVE-2025-8047
9.8 CRITICAL

The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It …

Aug 14, 2025
CVE-2025-55346
9.8 CRITICAL

User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of …

Aug 14, 2025
CVE-2012-10060
9.8 CRITICAL

Sysax Multi Server versions prior to 5.55 contains a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username …

Aug 13, 2025
CVE-2012-10054
9.8 CRITICAL

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits …

Aug 13, 2025
CVE-2011-10019
9.8 CRITICAL

Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the …

Aug 13, 2025
CVE-2011-10018
9.8 CRITICAL

myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by …

Aug 13, 2025
CVE-2025-43986
9.8 CRITICAL

An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interface without authentication.

Aug 13, 2025
CVE-2025-43982
9.8 CRITICAL

Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that cannot be disabled in the GUI.

Aug 13, 2025
CVE-2025-52385
9.8 CRITICAL

An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process module

Aug 13, 2025
CVE-2025-51451
9.8 CRITICAL

In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

Aug 13, 2025
CVE-2025-50594
9.8 CRITICAL

An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management System EMR 3.2 allowing attackers to reset any account password.

Aug 13, 2025
CVE-2025-51452
9.8 CRITICAL

In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

Aug 13, 2025
CVE-2025-50251
9.1 CRITICAL

Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.

Aug 13, 2025
CVE-2025-54382
9.6 CRITICAL

Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry …

Aug 13, 2025
CVE-2025-54074
9.8 CRITICAL

Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio is vulnerable to OS Command Injection …

Aug 13, 2025
CVE-2025-8913
9.8 CRITICAL

Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

Aug 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.