CVE Database

9968+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38824
9.6 CRITICAL

Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.

Jun 13, 2025
CVE-2025-5288
9.8 CRITICAL

The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to …

Jun 13, 2025
CVE-2025-43863
9.8 CRITICAL

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access …

Jun 12, 2025
CVE-2024-56158
9.8 CRITICAL

XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki …

Jun 12, 2025
CVE-2025-4973
9.8 CRITICAL

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and …

Jun 12, 2025
CVE-2022-4976
9.8 CRITICAL

Archive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilities. The bundled library is affected by CVE-2014-8139, …

Jun 12, 2025
CVE-2025-40912
9.8 CRITICAL

CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds the tomcrypt library. The versions of that …

Jun 11, 2025
CVE-2025-40914
9.8 CRITICAL

Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that …

Jun 11, 2025
CVE-2025-32711
9.3 CRITICAL

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Jun 11, 2025
CVE-2025-49710
9.8 CRITICAL

An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.

Jun 11, 2025
CVE-2025-49709
9.8 CRITICAL

Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.

Jun 11, 2025
CVE-2025-41663
9.8 CRITICAL

For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers, which are then …

Jun 11, 2025
CVE-2025-2474
9.8 CRITICAL

Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition …

Jun 10, 2025
CVE-2024-57190
9.8 CRITICAL

Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them …

Jun 10, 2025
CVE-2025-40585
9.9 CRITICAL

A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentials. This could allow an attacker to …

Jun 10, 2025
CVE-2025-30220
9.9 CRITICAL

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent …

Jun 10, 2025
CVE-2024-34711
9.3 CRITICAL

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized …

Jun 10, 2025
CVE-2025-49507
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affects CozyStay: from n/a through < 1.7.1.

Jun 10, 2025
CVE-2025-49455
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge WordPress-WPJobBoard click-pledge-wpjobboard allows Blind SQL Injection.This issue affects WordPress-WPJobBoard: from …

Jun 10, 2025
CVE-2025-43698
9.1 CRITICAL

Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before Spring 2025

Jun 10, 2025
CVE-2025-40657
9.8 CRITICAL

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the …

Jun 10, 2025
CVE-2025-40656
9.8 CRITICAL

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the …

Jun 10, 2025
CVE-2025-40655
9.8 CRITICAL

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the …

Jun 10, 2025
CVE-2025-40654
9.8 CRITICAL

A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the …

Jun 10, 2025
CVE-2025-1041
9.9 CRITICAL

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include …

Jun 10, 2025
CVE-2025-42989
9.6 CRITICAL

RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact …

Jun 10, 2025
CVE-2025-30515
9.8 CRITICAL

CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.

Jun 9, 2025
CVE-2025-30184
9.8 CRITICAL

CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.

Jun 9, 2025
CVE-2025-49652
9.8 CRITICAL

Missing Authentication in the registration feature of Lablup's BackendAI allows arbitrary users to create user accounts that can access private data even when registration is …

Jun 9, 2025
CVE-2025-49136
9.0 CRITICAL

listmonk is a standalone, self-hosted, newsletter and mailing list manager. Starting in version 4.0.0 and prior to version 5.0.2, the `env` and `expandenv` template functions …

Jun 9, 2025
CVE-2025-48281
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform MyStyle Custom Product Designer mystyle-custom-product-designer allows Blind SQL Injection.This issue …

Jun 9, 2025
CVE-2025-48141
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Multi CryptoCurrency Payments multi-crypto-currency-payment allows SQL Injection.This issue affects …

Jun 9, 2025
CVE-2025-48140
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI metalpriceapi allows Code Injection.This issue affects MetalpriceAPI: from n/a through <= 1.1.4.

Jun 9, 2025
CVE-2025-48129
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Privilege Escalation.This issue affects Spreadsheet Price …

Jun 9, 2025
CVE-2025-48123
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Code …

Jun 9, 2025
CVE-2025-48122
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – …

Jun 9, 2025
CVE-2025-47608
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sonalsinha21 Recover abandoned cart for WooCommerce recover-wc-abandoned-cart allows SQL Injection.This issue …

Jun 9, 2025
CVE-2025-32291
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Using Malicious Files.This issue affects SUMO Affiliates Pro: from n/a …

Jun 9, 2025
CVE-2025-31429
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in themeton PressGrid - Frontend Publish Reaction & Multimedia Theme allows Object Injection. This issue affects PressGrid - Frontend Publish …

Jun 9, 2025
CVE-2025-31424
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Blind SQL Injection.This issue …

Jun 9, 2025
CVE-2025-31398
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in themeton PIMP - Creative MultiPurpose allows Object Injection. This issue affects PIMP - Creative MultiPurpose: from n/a through 1.7.

Jun 9, 2025
CVE-2025-31396
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in themeton FLAP - Business WordPress Theme allows Object Injection. This issue affects FLAP - Business WordPress Theme: from n/a …

Jun 9, 2025
CVE-2025-31059
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in woobewoo WBW Product Table PRO woo-producttables-pro allows SQL Injection.This issue affects …

Jun 9, 2025
CVE-2025-31052
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme nrgfashion allows Object Injection.This issue affects The Fashion - …

Jun 9, 2025
CVE-2025-31039
9.1 CRITICAL

Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue affects Category Icon: from n/a through <= …

Jun 9, 2025
CVE-2025-31022
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU India PayU India payu-india allows Authentication Abuse.This issue affects PayU India: from n/a through …

Jun 9, 2025
CVE-2025-24767
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturaone TicketBAI Facturas para WooCommerce wp-ticketbai allows Blind SQL Injection.This issue …

Jun 9, 2025
CVE-2025-49013
9.9 CRITICAL

WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage …

Jun 9, 2025
CVE-2025-48877
9.8 CRITICAL

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the …

Jun 9, 2025
CVE-2025-3835
9.6 CRITICAL

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

Jun 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.