CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54438
9.8 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a …

Jul 23, 2025
CVE-2025-8044
9.8 CRITICAL

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Jul 22, 2025
CVE-2025-8043
9.8 CRITICAL

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.

Jul 22, 2025
CVE-2025-8038
9.8 CRITICAL

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141, and …

Jul 22, 2025
CVE-2025-8037
9.1 CRITICAL

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the …

Jul 22, 2025
CVE-2025-8031
9.8 CRITICAL

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, …

Jul 22, 2025
CVE-2025-8028
9.8 CRITICAL

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and …

Jul 22, 2025
CVE-2025-4285
10.0 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies Agentis allows SQL Injection.This issue affects Agentis: before …

Jul 22, 2025
CVE-2025-6187
9.8 CRITICAL

The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions 1.3.7 through 1.7.9. The …

Jul 22, 2025
CVE-2015-10137
9.8 CRITICAL

The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' …

Jul 22, 2025
CVE-2012-10020
9.8 CRITICAL

The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions up to, …

Jul 22, 2025
CVE-2025-54127
9.8 CRITICAL

HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of …

Jul 21, 2025
CVE-2025-54122
10.0 CRITICAL

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified in the proxy handler component of both manager …

Jul 21, 2025
CVE-2025-52362
9.1 CRITICAL

Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation for the _proxurl parameter can …

Jul 21, 2025
CVE-2020-26799
9.8 CRITICAL

A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.

Jul 21, 2025
CVE-2025-44654
9.8 CRITICAL

In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, …

Jul 21, 2025
CVE-2025-36846
9.8 CRITICAL

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS …

Jul 21, 2025
CVE-2025-7393
9.8 CRITICAL

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before …

Jul 21, 2025
CVE-2025-44658
9.8 CRITICAL

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may …

Jul 21, 2025
CVE-2025-44655
9.8 CRITICAL

In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system …

Jul 21, 2025
CVE-2025-46122
9.1 CRITICAL

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the …

Jul 21, 2025
CVE-2025-46121
9.8 CRITICAL

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to …

Jul 21, 2025
CVE-2025-46120
9.8 CRITICAL

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in …

Jul 21, 2025
CVE-2025-46117
9.1 CRITICAL

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script …

Jul 21, 2025
CVE-2025-7624
9.8 CRITICAL

An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, …

Jul 21, 2025
CVE-2025-6704
9.8 CRITICAL

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth …

Jul 21, 2025
CVE-2024-6107
9.6 CRITICAL

Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been …

Jul 21, 2025
CVE-2025-7921
9.8 CRITICAL

Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and potentially execute …

Jul 21, 2025
CVE-2025-7343
9.8 CRITICAL

The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database …

Jul 21, 2025
CVE-2025-24937
9.0 CRITICAL

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a …

Jul 21, 2025
CVE-2025-24936
9.0 CRITICAL

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the …

Jul 21, 2025
CVE-2025-7918
9.8 CRITICAL

WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and …

Jul 21, 2025
CVE-2025-7916
9.8 CRITICAL

WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted …

Jul 21, 2025
CVE-2025-53770
9.8 CRITICAL KEV

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit …

Jul 20, 2025
CVE-2015-10138
9.8 CRITICAL

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server …

Jul 19, 2025
CVE-2016-15043
9.8 CRITICAL

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up …

Jul 19, 2025
CVE-2015-10135
9.8 CRITICAL

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in …

Jul 19, 2025
CVE-2012-10019
9.8 CRITICAL

The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions …

Jul 19, 2025
CVE-2025-7697
9.8 CRITICAL

The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions …

Jul 19, 2025
CVE-2025-7696
9.8 CRITICAL

The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Jul 19, 2025
CVE-2025-7394
9.8 CRITICAL

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() …

Jul 18, 2025
CVE-2025-54309
9.0 CRITICAL KEV

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to …

Jul 18, 2025
CVE-2025-49747
9.9 CRITICAL

Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

Jul 18, 2025
CVE-2025-49746
9.9 CRITICAL

Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

Jul 18, 2025
CVE-2025-47158
9.0 CRITICAL

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Jul 18, 2025
CVE-2025-53888
9.8 CRITICAL

RIOT-OS, an operating system that supports Internet of Things devices, has an ineffective size check implemented with `assert()` can lead to buffer overflow in versions …

Jul 18, 2025
CVE-2025-46001
9.8 CRITICAL

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Jul 18, 2025
CVE-2025-7444
9.8 CRITICAL

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification …

Jul 18, 2025
CVE-2025-26855
9.8 CRITICAL

A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

Jul 18, 2025
CVE-2025-26854
9.8 CRITICAL

A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

Jul 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.