CVE Database

9968+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49302
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows Remote Code Inclusion.This issue affects Easy Stripe: from n/a …

Jul 4, 2025
CVE-2025-30933
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a Web Shell to a Web Server.This issue affects LogisticsHub: from …

Jul 4, 2025
CVE-2025-28983
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects …

Jul 4, 2025
CVE-2025-23970
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.This issue affects Service Finder Booking: from n/a through <= 6.1.

Jul 4, 2025
CVE-2025-28951
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web Server.This issue affects …

Jul 4, 2025
CVE-2025-53599
9.8 CRITICAL

Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted javascript scheme.

Jul 4, 2025
CVE-2025-23968
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud …

Jul 3, 2025
CVE-2025-45813
9.8 CRITICAL

ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

Jul 2, 2025
CVE-2025-45814
9.8 CRITICAL

Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking …

Jul 2, 2025
CVE-2025-20309
10.0 CRITICAL

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote …

Jul 2, 2025
CVE-2025-53006
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" …

Jul 2, 2025
CVE-2025-34071
9.8 CRITICAL

A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade …

Jul 2, 2025
CVE-2025-34070
9.8 CRITICAL

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible …

Jul 2, 2025
CVE-2025-34069
9.8 CRITICAL

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The …

Jul 2, 2025
CVE-2024-13786
9.8 CRITICAL

The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted input in …

Jul 2, 2025
CVE-2025-5746
9.8 CRITICAL

The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation …

Jul 2, 2025
CVE-2025-4689
9.8 CRITICAL

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in …

Jul 2, 2025
CVE-2025-52101
9.8 CRITICAL

linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and …

Jul 1, 2025
CVE-2025-45006
9.1 CRITICAL

Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks.

Jul 1, 2025
CVE-2025-53104
9.1 CRITICAL

gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commit e6b4271, a command injection vulnerability was discovered in …

Jul 1, 2025
CVE-2025-37099
9.8 CRITICAL

A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

Jul 1, 2025
CVE-2025-49029
9.1 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And …

Jul 1, 2025
CVE-2025-45872
9.8 CRITICAL

zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

Jul 1, 2025
CVE-2025-41656
10.0 CRITICAL

An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured …

Jul 1, 2025
CVE-2025-41648
9.8 CRITICAL

An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available …

Jul 1, 2025
CVE-2025-6934
9.8 CRITICAL

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to …

Jul 1, 2025
CVE-2025-53095
9.6 CRITICAL

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) …

Jul 1, 2025
CVE-2025-53005
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source …

Jul 1, 2025
CVE-2025-53004
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's Redshift Data Source …

Jun 30, 2025
CVE-2025-32463
9.3 CRITICAL KEV

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

Jun 30, 2025
CVE-2025-45931
9.8 CRITICAL

An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file

Jun 30, 2025
CVE-2025-26074
9.8 CRITICAL

Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.

Jun 30, 2025
CVE-2025-40731
9.8 CRITICAL

SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and …

Jun 30, 2025
CVE-2025-53076
9.8 CRITICAL

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.

Jun 30, 2025
CVE-2025-53074
9.1 CRITICAL

Out-of-bounds Read vulnerability in Samsung Open Source rLottie allows Overflow Buffers.This issue affects rLottie: V0.2.

Jun 30, 2025
CVE-2025-53075
9.8 CRITICAL

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.

Jun 30, 2025
CVE-2025-0634
9.8 CRITICAL

Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.

Jun 30, 2025
CVE-2025-24290
9.9 CRITICAL

Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor with low privileges to escalate privileges.

Jun 29, 2025
CVE-2025-53391
9.3 CRITICAL

The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to …

Jun 28, 2025
CVE-2025-32897
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 …

Jun 28, 2025
CVE-2025-5304
9.8 CRITICAL

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. …

Jun 28, 2025
CVE-2025-5310
9.8 CRITICAL

Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, …

Jun 27, 2025
CVE-2025-52207
9.9 CRITICAL

PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.

Jun 27, 2025
CVE-2024-12364
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Software Guest Tracking Software allows SQL Injection.This issue affects …

Jun 27, 2025
CVE-2024-12150
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Wowwo CRM allows Blind SQL Injection.This issue affects Wowwo …

Jun 27, 2025
CVE-2024-12143
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile Informatics Mikro Hand Terminal - MikroDB allows SQL Injection.This …

Jun 27, 2025
CVE-2024-11739
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics Case ERP allows SQL Injection.This issue affects Case ERP: …

Jun 27, 2025
CVE-2025-53091
9.8 CRITICAL

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered …

Jun 27, 2025
CVE-2025-52553
9.6 CRITICAL

authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and …

Jun 27, 2025
CVE-2025-53314
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a through <= 2.5.0.

Jun 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.