CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8860
4.3 MEDIUM

The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function, tf_order_bulk_action_edit_function, …

Aug 26, 2025
CVE-2025-9476
7.3 HIGH

A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some unknown functionality of the file /Superadmin_Dashboard/process/editemployee_process.php. Such …

Aug 26, 2025
CVE-2025-9475
7.3 HIGH

A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin_Dashboard/process/editemployee_process.php. This …

Aug 26, 2025
CVE-2025-41702
9.8 CRITICAL

The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid …

Aug 26, 2025
CVE-2025-9474
4.5 MEDIUM

A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of the component Socket …

Aug 26, 2025
CVE-2025-9473
7.3 HIGH

A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. This impacts an unknown function of the file /feedback.php. The manipulation of …

Aug 26, 2025
CVE-2025-9472
7.3 HIGH

A vulnerability was found in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /owner_utility/add_owner_utility.php. The manipulation of the argument …

Aug 26, 2025
CVE-2025-5931
8.8 HIGH

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is due …

Aug 26, 2025
CVE-2025-9471
7.3 HIGH

A vulnerability has been found in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /maintenance/add_maintenance_cost.php. The manipulation of the argument …

Aug 26, 2025
CVE-2025-9470
7.3 HIGH

A flaw has been found in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /management/add_m_committee.php. Executing manipulation of the argument …

Aug 26, 2025
CVE-2025-9469
7.3 HIGH

A vulnerability was detected in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /fund/add_fund.php. Performing manipulation of …

Aug 26, 2025
CVE-2025-9468
7.3 HIGH

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /bill/add_bill.php. Such …

Aug 26, 2025
CVE-2025-9172
7.5 HIGH

The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up to, and including, 2.2.0 due to …

Aug 26, 2025
CVE-2025-9461
4.3 MEDIUM

A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java of the component …

Aug 26, 2025
CVE-2025-9444
7.3 HIGH

A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue affects some unknown processing of the file /admin/controller/delete_group_student.php. …

Aug 26, 2025
CVE-2025-9443
8.8 HIGH

A flaw has been found in Tenda CH22 1.0.0.1. This vulnerability affects the function formeditUserName of the file /goform/editUserName. Executing manipulation of the argument new_account …

Aug 26, 2025
CVE-2025-9440
4.3 MEDIUM

A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some unknown functionality of …

Aug 26, 2025
CVE-2025-9439
4.3 MEDIUM

A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this vulnerability is an unknown functionality of the …

Aug 26, 2025
CVE-2025-9438
4.3 MEDIUM

A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected is an unknown function of the file /admin/add_student.php. …

Aug 26, 2025
CVE-2025-9434
4.3 MEDIUM

A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects an unknown function of the file /admin/edit_title.php?id=1. Executing manipulation …

Aug 26, 2025
CVE-2025-9433
4.3 MEDIUM

A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin …

Aug 26, 2025
CVE-2025-8447
3.1 LOW

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from …

Aug 26, 2025
CVE-2025-9432
4.3 MEDIUM

A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component …

Aug 26, 2025
CVE-2025-9431
4.3 MEDIUM

A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument …

Aug 26, 2025
CVE-2025-9430
2.4 LOW

A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument …

Aug 26, 2025
CVE-2025-9429
3.5 LOW

A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post …

Aug 26, 2025
CVE-2025-9426
7.3 HIGH

A weakness has been identified in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /package.php. Executing manipulation …

Aug 25, 2025
CVE-2025-9425
7.3 HIGH

A security flaw has been discovered in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the …

Aug 25, 2025
CVE-2025-9424
4.7 MEDIUM

A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch_import.php?a=branch_list. Such manipulation of the argument …

Aug 25, 2025
CVE-2025-9423
7.3 HIGH

A vulnerability was determined in Campcodes Online Water Billing System 1.0. Affected is an unknown function of the file /editecex.php. This manipulation of the argument …

Aug 25, 2025
CVE-2025-9422
2.4 LOW

A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team of the component Team Image Handler. …

Aug 25, 2025
CVE-2025-9421
7.3 HIGH

A vulnerability has been found in itsourcecode Apartment Management System 1.0. This affects an unknown function of the file /complain/addcomplain.php. The manipulation of the argument …

Aug 25, 2025
CVE-2025-9420
7.3 HIGH

A flaw has been found in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of the file /floor/addfloor.php. Executing manipulation of …

Aug 25, 2025
CVE-2025-8627
8.8 HIGH

The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information leak. This issue affects TP-Link KP303 …

Aug 25, 2025
CVE-2025-57814

request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Versions 1.x.x and earlier contain a vulnerability where HTTPS requests to 127.0.0.1 bypass …

Aug 25, 2025
CVE-2025-57809
7.5 HIGH

XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21, XGrammar has an infinite recursion issue in the grammar. …

Aug 25, 2025
CVE-2025-57805

The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used …

Aug 25, 2025
CVE-2025-9419
7.3 HIGH

A vulnerability was detected in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /unit/addunit.php. Performing manipulation of the …

Aug 25, 2025
CVE-2025-9418
7.3 HIGH

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /owner/addowner.php. Such manipulation of the …

Aug 25, 2025
CVE-2025-6188
7.5 HIGH

On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with …

Aug 25, 2025
CVE-2025-57804

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Prior to version 4.3.0, an HTTP/2 request splitting vulnerability allows attackers to perform request smuggling …

Aug 25, 2025
CVE-2025-9417
6.3 MEDIUM

A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /employee/addemployee.php. This manipulation of the …

Aug 25, 2025
CVE-2025-9416
2.4 LOW

A security flaw has been discovered in oitcode samarium up to 0.9.6. This vulnerability affects unknown code of the file /cms/webpage/ of the component Pages …

Aug 25, 2025
CVE-2025-52130
5.4 MEDIUM

File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can …

Aug 25, 2025
CVE-2025-3456
3.8 LOW

On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge …

Aug 25, 2025
CVE-2025-9415
6.3 MEDIUM

A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The manipulation of the argument upload[] leads …

Aug 25, 2025
CVE-2025-9414
4.7 MEDIUM

A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the file /?explorer/upload/serverDownload of the component Download from …

Aug 25, 2025
CVE-2025-9413
6.3 MEDIUM

A flaw has been found in lostvip-com ruoyi-go up to 2.1. This impacts the function SelectListByPage of the file modules/system/system_router.go. This manipulation of the argument …

Aug 25, 2025
CVE-2025-9412
6.3 MEDIUM

A vulnerability was detected in lostvip-com ruoyi-go up to 2.1. This affects the function SelectListByPage of the file modules/system/dao/DictDataDao.go. The manipulation of the argument orderByColumn/isAsc …

Aug 25, 2025
CVE-2025-57811
7.2 HIGH

Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability …

Aug 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.