CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-57802

Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. In version 1.0.0, an attacker with access …

Aug 25, 2025
CVE-2025-50383
8.1 HIGH

alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.

Aug 25, 2025
CVE-2025-9411
6.3 MEDIUM

A security vulnerability has been detected in lostvip-com ruoyi-go up to 2.1. The impacted element is the function SelectPageList of the file modules/system/service/LoginInforService.go. The manipulation …

Aug 25, 2025
CVE-2025-9410
6.3 MEDIUM

A weakness has been identified in lostvip-com ruoyi-go up to 2.1. The affected element is the function SelectListByPage of the file modules/system/dao/GenTableDao.go. Executing manipulation of …

Aug 25, 2025
CVE-2025-6737
7.2 HIGH

Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material and access …

Aug 25, 2025
CVE-2025-57773
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack …

Aug 25, 2025
CVE-2025-57772
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If …

Aug 25, 2025
CVE-2025-57760
8.8 HIGH

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with …

Aug 25, 2025
CVE-2025-53120
9.4 CRITICAL

A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, …

Aug 25, 2025
CVE-2025-50722
9.8 CRITICAL

Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component

Aug 25, 2025
CVE-2025-29421
7.5 HIGH

PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.

Aug 25, 2025
CVE-2025-29420
7.5 HIGH

PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.

Aug 25, 2025
CVE-2025-9409
4.3 MEDIUM

A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUpload of the file modules/system/controller/CommonController.go. Performing manipulation of the …

Aug 25, 2025
CVE-2025-55575
9.8 CRITICAL

SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with action=service_detail.

Aug 25, 2025
CVE-2025-55574
6.1 MEDIUM

Cross Site Scripting vulnerability in docmost v.0.21.0 and before allows an attacker to execute arbitrary code

Aug 25, 2025
CVE-2025-55409
8.8 HIGH

FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code.

Aug 25, 2025
CVE-2025-55301
6.7 MEDIUM

The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local storage to edit …

Aug 25, 2025
CVE-2025-53119
7.5 HIGH

An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server.

Aug 25, 2025
CVE-2025-53118
9.8 CRITICAL

An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens …

Aug 25, 2025
CVE-2025-3478

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.

Aug 25, 2025
CVE-2025-29523
7.2 HIGH

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function.

Aug 25, 2025
CVE-2025-5302
8.6 HIGH

A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion …

Aug 25, 2025
CVE-2025-56216
8.5 HIGH

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.

Aug 25, 2025
CVE-2025-56215
6.5 MEDIUM

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter.

Aug 25, 2025
CVE-2025-56214
9.8 CRITICAL

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.

Aug 25, 2025
CVE-2025-56212
9.8 CRITICAL

phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.

Aug 25, 2025
CVE-2025-53510
8.8 HIGH

A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .psd file, …

Aug 25, 2025
CVE-2025-53085
8.8 HIGH

A memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a …

Aug 25, 2025
CVE-2025-52930
8.8 HIGH

A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the image data from a …

Aug 25, 2025
CVE-2025-52456
8.8 HIGH

A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .webp animation …

Aug 25, 2025
CVE-2025-51281
7.0 HIGH

D-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. This vulnerability allows authenticated attackers to …

Aug 25, 2025
CVE-2025-50900
9.8 CRITICAL

An issue was discovered in getrebuild/rebuild 4.0.4. The affected source code class is com.rebuild.web.RebuildWebInterceptor, and the affected function is preHandle In the filter code, use …

Aug 25, 2025
CVE-2025-50129
8.8 HIGH

A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a …

Aug 25, 2025
CVE-2025-46407
8.8 HIGH

A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, …

Aug 25, 2025
CVE-2025-44179
6.5 MEDIUM

Hitron CGNF-TWN 3.1.1.43-TWN-pre3 contains a command injection vulnerability in the telnet service. The issue arises due to improper input validation within the telnet command handling …

Aug 25, 2025
CVE-2025-44178
6.5 MEDIUM

DASAN GPON ONU H660WM H660WMR210825 is susceptible to improper access control under its default settings. Attackers can exploit this vulnerability to gain unauthorized access to …

Aug 25, 2025
CVE-2025-35984
8.8 HIGH

A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image data from a …

Aug 25, 2025
CVE-2025-32468
8.8 HIGH

A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, …

Aug 25, 2025
CVE-2025-29525
5.3 MEDIUM

DASAN GPON ONU H660WM OS version H660WMR210825 Hardware version DS-E5-583-A1 was discovered to contain insecure default credentials in the modem's control panel.

Aug 25, 2025
CVE-2025-29524
6.5 MEDIUM

Incorrect access control in the component /cgi-bin/system_diagnostic_main.asp of DASAN GPON ONU H660WM H660WMR210825 allows attackers to access sensitive information.

Aug 25, 2025
CVE-2025-29522
6.5 MEDIUM

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.

Aug 25, 2025
CVE-2025-29521
5.3 MEDIUM

Insecure default credentials for the Adminsitrator account of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to escalate privileges via a bruteforce attack.

Aug 25, 2025
CVE-2025-29520
5.3 MEDIUM

Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated attackers with low-level privileges to arbitrarily change the high-privileged account …

Aug 25, 2025
CVE-2025-29519
5.3 MEDIUM

A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET …

Aug 25, 2025
CVE-2024-46413
5.1 MEDIUM

Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreController#loadDataIndex method.

Aug 25, 2025
CVE-2024-46412
6.5 MEDIUM

Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a crafted GET request sent to /commons/ip-location.

Aug 25, 2025
CVE-2025-54494
9.8 CRITICAL

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER …

Aug 25, 2025
CVE-2025-54493
9.8 CRITICAL

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER …

Aug 25, 2025
CVE-2025-54492
9.8 CRITICAL

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER …

Aug 25, 2025
CVE-2025-54491
9.8 CRITICAL

A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER …

Aug 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.