CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8760
9.8 CRITICAL

A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the …

Aug 13, 2025
CVE-2025-6715
9.8 CRITICAL

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and …

Aug 13, 2025
CVE-2025-7384
9.8 CRITICAL

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Aug 13, 2025
CVE-2025-49457
9.6 CRITICAL

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

Aug 12, 2025
CVE-2025-55168
9.8 CRITICAL

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability …

Aug 12, 2025
CVE-2025-25256
9.8 CRITICAL

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through …

Aug 12, 2025
CVE-2025-53766
9.8 CRITICAL

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

Aug 12, 2025
CVE-2025-50171
9.1 CRITICAL

Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-50165
9.8 CRITICAL

Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Aug 12, 2025
CVE-2025-55167
9.8 CRITICAL

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability …

Aug 12, 2025
CVE-2025-55010
9.1 CRITICAL

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users …

Aug 12, 2025
CVE-2025-40746
9.1 CRITICAL

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. …

Aug 12, 2025
CVE-2025-8059
9.8 CRITICAL

The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input validation within the rgfr_registration() function in all …

Aug 12, 2025
CVE-2025-42957
9.9 CRITICAL

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of …

Aug 12, 2025
CVE-2025-42950
9.9 CRITICAL

SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the …

Aug 12, 2025
CVE-2024-32640
9.8 CRITICAL

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability …

Aug 11, 2025
CVE-2025-53187
9.8 CRITICAL

Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an …

Aug 11, 2025
CVE-2025-45146
9.8 CRITICAL

ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code via …

Aug 11, 2025
CVE-2025-8853
9.8 CRITICAL

Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use …

Aug 11, 2025
CVE-2025-8660
9.8 CRITICAL

Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.

Aug 11, 2025
CVE-2025-8854
9.8 CRITICAL

Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file …

Aug 11, 2025
CVE-2025-54997
9.1 CRITICAL

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some …

Aug 9, 2025
CVE-2025-6573
9.8 CRITICAL

Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).

Aug 9, 2025
CVE-2025-5095
9.8 CRITICAL

Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing an attacker to take over the device. A password change …

Aug 8, 2025
CVE-2025-52913
9.8 CRITICAL

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker to conduct a path …

Aug 8, 2025
CVE-2025-8284
9.8 CRITICAL

By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauthorized users to access and manipulate …

Aug 8, 2025
CVE-2025-8731
9.8 CRITICAL

A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation …

Aug 8, 2025
CVE-2025-8356
9.8 CRITICAL

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to …

Aug 8, 2025
CVE-2025-8730
9.8 CRITICAL

A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functionality of the component …

Aug 8, 2025
CVE-2025-53606
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which …

Aug 8, 2025
CVE-2025-48913
9.8 CRITICAL

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. …

Aug 8, 2025
CVE-2025-54887
9.1 CRITICAL

jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs can …

Aug 8, 2025
CVE-2025-54952
9.8 CRITICAL

An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other …

Aug 8, 2025
CVE-2025-54951
9.8 CRITICAL

A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution …

Aug 7, 2025
CVE-2025-54950
9.8 CRITICAL

An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable …

Aug 7, 2025
CVE-2025-54949
9.8 CRITICAL

A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or other undesirable effects. This issue affects ExecuTorch …

Aug 7, 2025
CVE-2025-30405
9.8 CRITICAL

An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their allocated memory area, potentially resulting in code …

Aug 7, 2025
CVE-2025-30404
9.8 CRITICAL

An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially resulting in code execution or other undesirable effects. This issue …

Aug 7, 2025
CVE-2025-53792
9.1 CRITICAL

Azure Portal Elevation of Privilege Vulnerability

Aug 7, 2025
CVE-2025-53767
10.0 CRITICAL

Azure OpenAI Elevation of Privilege Vulnerability

Aug 7, 2025
CVE-2025-45765
9.1 CRITICAL

ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more …

Aug 7, 2025
CVE-2025-50692
9.8 CRITICAL

FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

Aug 7, 2025
CVE-2023-41530
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

Aug 7, 2025
CVE-2023-41528
9.8 CRITICAL

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.

Aug 7, 2025
CVE-2023-41527
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.

Aug 7, 2025
CVE-2023-41526
9.8 CRITICAL

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.

Aug 7, 2025
CVE-2023-41525
9.8 CRITICAL

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

Aug 7, 2025
CVE-2025-30127
9.8 CRITICAL

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings …

Aug 6, 2025
CVE-2025-23317
9.1 CRITICAL

NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP …

Aug 6, 2025
CVE-2025-23311
9.8 CRITICAL

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requests. A successful exploit of this …

Aug 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.