CVE Database

9921+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21450
9.1 CRITICAL

Cryptographic issue occurs due to use of insecure connection method while downloading.

Jul 8, 2025
CVE-2025-40717
9.8 CRITICAL

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases …

Jul 8, 2025
CVE-2025-40716
9.8 CRITICAL

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases …

Jul 8, 2025
CVE-2025-40715
9.8 CRITICAL

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases …

Jul 8, 2025
CVE-2025-40714
9.8 CRITICAL

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases …

Jul 8, 2025
CVE-2025-40713
9.8 CRITICAL

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases …

Jul 8, 2025
CVE-2025-40712
9.8 CRITICAL

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases …

Jul 8, 2025
CVE-2025-40711
9.8 CRITICAL

SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases …

Jul 8, 2025
CVE-2025-40736
9.8 CRITICAL

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application exposes an endpoint that allows an unauthorized modification of administrative …

Jul 8, 2025
CVE-2025-25270
9.8 CRITICAL

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

Jul 8, 2025
CVE-2025-20684
9.8 CRITICAL

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jul 8, 2025
CVE-2025-20683
9.8 CRITICAL

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jul 8, 2025
CVE-2025-20682
9.8 CRITICAL

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jul 8, 2025
CVE-2025-20681
9.8 CRITICAL

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Jul 8, 2025
CVE-2025-20680
9.8 CRITICAL

In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Jul 8, 2025
CVE-2025-42980
9.1 CRITICAL

SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead …

Jul 8, 2025
CVE-2025-42967
9.9 CRITICAL

SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report …

Jul 8, 2025
CVE-2025-42966
9.1 CRITICAL

SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted …

Jul 8, 2025
CVE-2025-42964
9.1 CRITICAL

SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a …

Jul 8, 2025
CVE-2025-42963
9.1 CRITICAL

A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can …

Jul 8, 2025
CVE-2025-53499
9.1 CRITICAL

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki - AbuseFilter Extension: from 1.43.X before 1.43.2.

Jul 7, 2025
CVE-2025-53495
9.1 CRITICAL

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access.This issue affects Mediawiki - AbuseFilter Extension: from 1.43.X before 1.43.2.

Jul 7, 2025
CVE-2025-53529
9.8 CRITICAL

WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionario/profile_funcionario.php endpoint. The id_funcionario parameter is not properly sanitized …

Jul 7, 2025
CVE-2025-53527
9.8 CRITICAL

WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This …

Jul 7, 2025
CVE-2024-25178
9.1 CRITICAL

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.

Jul 7, 2025
CVE-2024-25176
9.8 CRITICAL

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.

Jul 7, 2025
CVE-2025-47202
9.1 CRITICAL

In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, …

Jul 7, 2025
CVE-2025-45479
9.8 CRITICAL

Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container.

Jul 7, 2025
CVE-2025-45065
9.8 CRITICAL

employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.

Jul 7, 2025
CVE-2025-43933
9.8 CRITICAL

fblog through 983bede allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP …

Jul 7, 2025
CVE-2025-43932
9.8 CRITICAL

JobCenter through 7e7b0b2 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP …

Jul 7, 2025
CVE-2025-43931
9.8 CRITICAL

flask-boilerplate through a170e7c allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP …

Jul 7, 2025
CVE-2025-6811
9.8 CRITICAL

Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius …

Jul 7, 2025
CVE-2025-6810
9.8 CRITICAL

Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius …

Jul 7, 2025
CVE-2025-6805
9.1 CRITICAL

Marvell QConvergeConsole deleteEventLogFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Marvell QConvergeConsole. Authentication …

Jul 7, 2025
CVE-2025-6802
9.8 CRITICAL

Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. …

Jul 7, 2025
CVE-2025-6798
9.1 CRITICAL

Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Marvell QConvergeConsole. Authentication …

Jul 7, 2025
CVE-2025-6794
9.8 CRITICAL

Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication …

Jul 7, 2025
CVE-2025-6793
9.4 CRITICAL

Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability allows remote attackers to delete arbitrary files and disclose sensitive information …

Jul 7, 2025
CVE-2025-43930
9.8 CRITICAL

Hashview 0.8.1 allows account takeover via the password reset feature because SERVER_NAME is not configured and thus a reset depends on the Host HTTP header.

Jul 7, 2025
CVE-2025-3626
9.1 CRITICAL

A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command …

Jul 7, 2025
CVE-2025-41672
10.0 CRITICAL

A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.

Jul 7, 2025
CVE-2025-48501
9.8 CRITICAL

An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be …

Jul 7, 2025
CVE-2025-26850
9.3 CRITICAL

The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.

Jul 5, 2025
CVE-2025-48952
9.4 CRITICAL

NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to bypass password verification …

Jul 4, 2025
CVE-2025-53484
9.8 CRITICAL

User-controlled inputs are improperly escaped in: * VotePage.php (poll option input) * ResultPage::getPagesTab() and getErrorsTab() (user-controllable page names) This allows attackers to inject JavaScript and …

Jul 4, 2025
CVE-2025-52833
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in designthemes LMS lms allows SQL Injection.This issue affects LMS: from n/a …

Jul 4, 2025
CVE-2025-52832
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows SQL Injection.This issue affects …

Jul 4, 2025
CVE-2025-52831
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager video-list-manager allows SQL Injection.This issue affects Video …

Jul 4, 2025
CVE-2025-52830
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bSecure – Your Universal Checkout bSecure – Your Universal Checkout bsecure …

Jul 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.