CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9905
7.3 HIGH

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, …

Sep 19, 2025
CVE-2025-10647
8.8 HIGH

The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_download_pdf_media function in …

Sep 19, 2025
CVE-2025-7702
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust …

Sep 19, 2025
CVE-2025-7403
7.6 HIGH

Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes are attacker-controlled, enabling precise memory corruption.

Sep 19, 2025
CVE-2025-5948
9.8 CRITICAL

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is …

Sep 19, 2025
CVE-2025-10458
7.6 HIGH

Parameters are not validated or sanitized, and are later used in various internal operations.

Sep 19, 2025
CVE-2025-10457
4.3 MEDIUM

The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. …

Sep 19, 2025
CVE-2025-10456
7.1 HIGH

A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a …

Sep 19, 2025
CVE-2025-5955
8.1 HIGH

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to …

Sep 19, 2025
CVE-2025-10146
6.1 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due …

Sep 19, 2025
CVE-2025-8487
5.4 MEDIUM

The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action …

Sep 19, 2025
CVE-2025-59717
5.4 MEDIUM

In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead …

Sep 19, 2025
CVE-2025-7937
7.2 HIGH

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially …

Sep 19, 2025
CVE-2025-59715
4.8 MEDIUM

SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.

Sep 19, 2025
CVE-2025-59714
6.5 MEDIUM

In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.

Sep 19, 2025
CVE-2025-59713
6.8 MEDIUM

Snipe-IT before 8.1.18 allows unsafe deserialization.

Sep 19, 2025
CVE-2025-59712
6.4 MEDIUM

Snipe-IT before 8.1.18 allows XSS.

Sep 19, 2025
CVE-2025-59678

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59677

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59676

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59675

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59674

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59673

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59672

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59671

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59670

Rejected reason: Not used

Sep 19, 2025
CVE-2025-10690
9.8 CRITICAL

The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the …

Sep 19, 2025
CVE-2025-6198
7.2 HIGH

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially …

Sep 19, 2025
CVE-2025-30755
6.1 MEDIUM

OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens through improper handling of the revision parameter. The …

Sep 19, 2025
CVE-2025-59692
3.7 LOW

PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to …

Sep 18, 2025
CVE-2025-59691
3.7 LOW

PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or …

Sep 18, 2025
CVE-2025-59220
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Sep 18, 2025
CVE-2025-59216
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 18, 2025
CVE-2025-59215
7.0 HIGH

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 18, 2025
CVE-2025-54860
7.7 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as …

Sep 18, 2025
CVE-2025-54818
8.0 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The …

Sep 18, 2025
CVE-2025-54810
8.0 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The …

Sep 18, 2025
CVE-2025-54497
8.1 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, …

Sep 18, 2025
CVE-2025-53969
8.8 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service implementing a proprietary protocol on TCP port 1069 to allow the client-side software, such as …

Sep 18, 2025
CVE-2025-52873
8.1 HIGH

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 to allow management operations such as firmware upgrades and device reboots, …

Sep 18, 2025
CVE-2025-10035
10.0 CRITICAL KEV

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary …

Sep 18, 2025
CVE-2025-57295
8.0 HIGH

H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and …

Sep 18, 2025
CVE-2025-57293
8.8 HIGH

A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt. The phy_interface parameter is …

Sep 18, 2025
CVE-2025-55068
8.2 HIGH

Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time …

Sep 18, 2025
CVE-2025-54807
9.8 CRITICAL

The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, …

Sep 18, 2025
CVE-2025-54754
8.0 HIGH

An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then …

Sep 18, 2025
CVE-2025-53947
7.7 HIGH

A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data. A data …

Sep 18, 2025
CVE-2025-47698

An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.

Sep 18, 2025
CVE-2025-30519
9.8 CRITICAL

Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access to …

Sep 18, 2025
CVE-2025-10689
6.3 MEDIUM

A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads …

Sep 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.