CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40594
6.3 MEDIUM

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 …

Sep 9, 2025
CVE-2025-10134
9.1 CRITICAL

The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the alone_import_pack_restore_data() …

Sep 9, 2025
CVE-2025-9542
5.4 MEDIUM

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of …

Sep 9, 2025
CVE-2025-9539
8.0 HIGH

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due …

Sep 9, 2025
CVE-2025-9111
3.5 LOW

The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such …

Sep 9, 2025
CVE-2025-9061
6.4 MEDIUM

The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.4.5 due to insufficient input …

Sep 9, 2025
CVE-2025-9058
6.4 MEDIUM

The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.5.2 due to insufficient input …

Sep 9, 2025
CVE-2025-8889
3.8 LOW

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files …

Sep 9, 2025
CVE-2025-9489
5.0 MEDIUM

The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.2. This is due …

Sep 9, 2025
CVE-2025-43777
5.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 …

Sep 9, 2025
CVE-2025-10123
7.3 HIGH

A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of …

Sep 9, 2025
CVE-2025-10122
4.7 MEDIUM

A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql …

Sep 9, 2025
CVE-2025-43778
6.1 MEDIUM

A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 …

Sep 9, 2025
CVE-2025-42958
9.1 CRITICAL

Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or …

Sep 9, 2025
CVE-2025-42944
10.0 CRITICAL

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an …

Sep 9, 2025
CVE-2025-42938
6.1 MEDIUM

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly …

Sep 9, 2025
CVE-2025-42933
8.8 HIGH

When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of certain APIs. This leads …

Sep 9, 2025
CVE-2025-42930
6.5 MEDIUM

SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive …

Sep 9, 2025
CVE-2025-42929
8.1 HIGH

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables …

Sep 9, 2025
CVE-2025-42927
3.4 LOW

SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library …

Sep 9, 2025
CVE-2025-42926
5.3 MEDIUM

SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, …

Sep 9, 2025
CVE-2025-42925
4.3 MEDIUM

Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could …

Sep 9, 2025
CVE-2025-42923
4.3 MEDIUM

Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended …

Sep 9, 2025
CVE-2025-42922
9.9 CRITICAL

SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. …

Sep 9, 2025
CVE-2025-42920
6.1 MEDIUM

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publicly …

Sep 9, 2025
CVE-2025-42918
4.3 MEDIUM

SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in …

Sep 9, 2025
CVE-2025-42917
6.5 MEDIUM

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has …

Sep 9, 2025
CVE-2025-42916
8.1 HIGH

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables …

Sep 9, 2025
CVE-2025-42915
5.4 MEDIUM

Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be …

Sep 9, 2025
CVE-2025-42914
3.1 LOW

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform …

Sep 9, 2025
CVE-2025-42913
3.1 LOW

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform …

Sep 9, 2025
CVE-2025-42912
6.5 MEDIUM

SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has …

Sep 9, 2025
CVE-2025-42911
5.0 MEDIUM

SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system …

Sep 9, 2025
CVE-2025-10121
6.3 MEDIUM

A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipulation of the argument note …

Sep 9, 2025
CVE-2025-10120
8.8 HIGH

A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the …

Sep 9, 2025
CVE-2025-10118
7.3 HIGH

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the …

Sep 9, 2025
CVE-2025-10117
3.5 LOW

A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add …

Sep 9, 2025
CVE-2025-10116
7.3 HIGH

A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The …

Sep 9, 2025
CVE-2025-43774

Rejected reason: This CVE ID is rejected. The reported vulnerability was found to be present only in a feature that was under development and protected …

Sep 9, 2025
CVE-2025-10115
7.3 HIGH

A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes …

Sep 9, 2025
CVE-2025-10114
7.3 HIGH

A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the …

Sep 9, 2025
CVE-2025-58757
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in …

Sep 9, 2025
CVE-2025-58756
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, …

Sep 9, 2025
CVE-2025-58755
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compressed files. …

Sep 9, 2025
CVE-2025-43763
6.5 MEDIUM

A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through …

Sep 9, 2025
CVE-2025-10113
7.3 HIGH

A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of …

Sep 9, 2025
CVE-2025-10112
7.3 HIGH

A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation …

Sep 9, 2025
CVE-2025-58752
5.3 MEDIUM

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless …

Sep 8, 2025
CVE-2025-58751
5.3 MEDIUM

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public …

Sep 8, 2025
CVE-2025-58746
9.0 CRITICAL

The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to …

Sep 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.