CVE Database

9968+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53260
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress file-manager-plugin-for-wordpress allows Upload a Web Shell to a Web Server.This …

Jun 27, 2025
CVE-2025-52834
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Homey homey allows SQL Injection.This issue affects Homey: from n/a …

Jun 27, 2025
CVE-2025-52829
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DirectIQ DirectIQ Email Marketing directiq-wp allows SQL Injection.This issue affects DirectIQ …

Jun 27, 2025
CVE-2025-52725
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in pebas CouponXxL couponxxl allows Object Injection.This issue affects CouponXxL: from n/a through <= 3.0.0.

Jun 27, 2025
CVE-2025-52724
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk amwerk allows Object Injection.This issue affects Amwerk: from n/a through <= 1.2.0.

Jun 27, 2025
CVE-2025-52722
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoinWebs Classiera classiera allows SQL Injection.This issue affects Classiera: from n/a …

Jun 27, 2025
CVE-2025-52717
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chrisbadgett LifterLMS lifterlms allows SQL Injection.This issue affects LifterLMS: from n/a …

Jun 27, 2025
CVE-2025-49885
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce drag-and-drop-file-upload-wc-pro allows Upload a Web Shell …

Jun 27, 2025
CVE-2025-39474
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Amely amely allows SQL Injection.This issue affects Amely: from n/a …

Jun 27, 2025
CVE-2025-28970
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in pep.vn WP Optimize By xTraffic wp-optimize-by-xtraffic allows Object Injection.This issue affects WP Optimize By xTraffic: from n/a through <= …

Jun 27, 2025
CVE-2025-23967
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpopal GG Bought Together for WooCommerce gg-bought-together allows SQL Injection.This issue …

Jun 27, 2025
CVE-2024-12827
9.8 CRITICAL

The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and …

Jun 27, 2025
CVE-2025-6688
9.8 CRITICAL

The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying …

Jun 27, 2025
CVE-2025-5306
9.8 CRITICAL

Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778

Jun 27, 2025
CVE-2025-3699
9.8 CRITICAL

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, …

Jun 26, 2025
CVE-2015-0843
9.8 CRITICAL

yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.

Jun 26, 2025
CVE-2015-0842
9.8 CRITICAL

yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.

Jun 26, 2025
CVE-2014-7210
9.8 CRITICAL

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql …

Jun 26, 2025
CVE-2014-0468
9.8 CRITICAL

Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have uploaded in their raw SCM …

Jun 26, 2025
CVE-2025-49603
9.1 CRITICAL

Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.

Jun 26, 2025
CVE-2025-30131
9.8 CRITICAL

An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploading a CGI-based …

Jun 26, 2025
CVE-2024-52928
9.6 CRITICAL

Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when …

Jun 26, 2025
CVE-2025-29331
9.8 CRITICAL

An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no …

Jun 26, 2025
CVE-2025-49003
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in …

Jun 26, 2025
CVE-2025-6561
9.8 CRITICAL

Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a …

Jun 26, 2025
CVE-2025-4334
9.8 CRITICAL

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient …

Jun 26, 2025
CVE-2025-36038
9.0 CRITICAL

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of …

Jun 25, 2025
CVE-2025-52483
9.8 CRITICAL

Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the …

Jun 25, 2025
CVE-2025-52480
9.8 CRITICAL

Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the …

Jun 25, 2025
CVE-2025-20282
10.0 CRITICAL

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected …

Jun 25, 2025
CVE-2025-20281
10.0 CRITICAL KEV

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying …

Jun 25, 2025
CVE-2021-4457
9.1 CRITICAL

The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

Jun 25, 2025
CVE-2025-6543
9.8 CRITICAL KEV

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, …

Jun 25, 2025
CVE-2024-51978
9.8 CRITICAL

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover …

Jun 25, 2025
CVE-2025-52572
10.0 CRITICAL

Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an …

Jun 24, 2025
CVE-2025-52571
9.6 CRITICAL

Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to …

Jun 24, 2025
CVE-2025-52471
9.8 CRITICAL

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been identified in the ESP-NOW protocol implementation within the ESP …

Jun 24, 2025
CVE-2025-49853
9.1 CRITICAL

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL …

Jun 24, 2025
CVE-2025-49851
9.8 CRITICAL

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions …

Jun 24, 2025
CVE-2024-37743
9.8 CRITICAL

An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.

Jun 24, 2025
CVE-2025-4378
10.0 CRITICAL

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass.This issue affects ATA-AOF Mobile …

Jun 24, 2025
CVE-2025-4383
9.3 CRITICAL

Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot allows Authentication Abuse, Authentication Bypass.This …

Jun 24, 2025
CVE-2021-41691
9.8 CRITICAL

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.

Jun 24, 2025
CVE-2025-32977
9.6 CRITICAL

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch …

Jun 24, 2025
CVE-2025-32975
10.0 CRITICAL KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch …

Jun 24, 2025
CVE-2025-6433
9.8 CRITICAL

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that …

Jun 24, 2025
CVE-2025-6427
9.1 CRITICAL

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from …

Jun 24, 2025
CVE-2025-6424
9.8 CRITICAL

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, …

Jun 24, 2025
CVE-2025-50213
9.8 CRITICAL

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: …

Jun 24, 2025
CVE-2025-48890
9.8 CRITICAL

WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a …

Jun 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.