CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58040

Rejected reason: Not used

Aug 23, 2025
CVE-2025-58039

Rejected reason: Not used

Aug 23, 2025
CVE-2025-58038

Rejected reason: Not used

Aug 23, 2025
CVE-2025-58037

Rejected reason: Not used

Aug 23, 2025
CVE-2025-58036

Rejected reason: Not used

Aug 23, 2025
CVE-2025-58035

Rejected reason: Not used

Aug 23, 2025
CVE-2025-43769
6.1 MEDIUM

Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 …

Aug 23, 2025
CVE-2025-43768
7.7 HIGH

Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update …

Aug 23, 2025
CVE-2025-24469

Rejected reason: Not used

Aug 23, 2025
CVE-2025-24468

Rejected reason: Not used

Aug 23, 2025
CVE-2025-22864

Rejected reason: Not used

Aug 23, 2025
CVE-2025-22863

Rejected reason: Not used

Aug 23, 2025
CVE-2025-22861

Rejected reason: Not used

Aug 23, 2025
CVE-2025-22860

Rejected reason: Not used

Aug 23, 2025
CVE-2025-43770
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, …

Aug 23, 2025
CVE-2025-8193

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 22, 2025
CVE-2025-9356
8.8 HIGH

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function inboundFilterAdd of the file …

Aug 22, 2025
CVE-2025-9355
8.8 HIGH

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function scheduleAdd of the file …

Aug 22, 2025
CVE-2025-55455
3.5 LOW

DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext.

Aug 22, 2025
CVE-2025-52451
8.5 HIGH

Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before …

Aug 22, 2025
CVE-2025-52450
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (abdoc api - create-data-source-from-file-upload modules) allows …

Aug 22, 2025
CVE-2025-4609
9.6 CRITICAL

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox …

Aug 22, 2025
CVE-2025-43761
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, …

Aug 22, 2025
CVE-2025-26498
7.3 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) allows Absolute Path Traversal.This issue affects Tableau Server: …

Aug 22, 2025
CVE-2025-26497
7.3 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Path Traversal.This issue affects Tableau …

Aug 22, 2025
CVE-2025-26496
9.3 CRITICAL

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This …

Aug 22, 2025
CVE-2022-45133
6.5 MEDIUM

Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 allows unsafe font upload for skins. A particularly structured XML file could allow one …

Aug 22, 2025
CVE-2025-57801
9.1 CRITICAL

gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a …

Aug 22, 2025
CVE-2022-43110
9.8 CRITICAL

Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated …

Aug 22, 2025
CVE-2022-31491
10.0 CRITICAL

Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified …

Aug 22, 2025
CVE-2025-6791
8.8 HIGH

In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an …

Aug 22, 2025
CVE-2025-55454
8.8 HIGH

An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploading a crafted file.

Aug 22, 2025
CVE-2025-54813
7.5 HIGH

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain …

Aug 22, 2025
CVE-2025-54812
5.4 MEDIUM

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. …

Aug 22, 2025
CVE-2025-51092
9.8 CRITICAL

The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in DataBase.php. The functions logIn() and signUp() build …

Aug 22, 2025
CVE-2025-50859
6.1 MEDIUM

Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template …

Aug 22, 2025
CVE-2025-50858
6.1 MEDIUM

Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the …

Aug 22, 2025
CVE-2025-4650
7.2 HIGH

User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements used …

Aug 22, 2025
CVE-2025-43762
6.5 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 …

Aug 22, 2025
CVE-2025-43759
2.7 LOW

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through …

Aug 22, 2025
CVE-2025-43758
5.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 …

Aug 22, 2025
CVE-2024-48988
7.6 HIGH

SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes …

Aug 22, 2025
CVE-2022-45134
9.8 CRITICAL

Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly structured XML file could cause …

Aug 22, 2025
CVE-2025-55613
9.8 CRITICAL

Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.

Aug 22, 2025
CVE-2025-55581
7.3 HIGH

D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The script monitors and respawns the `dcp` and …

Aug 22, 2025
CVE-2025-52287
8.8 HIGH

OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.

Aug 22, 2025
CVE-2025-52085
8.8 HIGH

An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries via a request to a backend API endpoint. Successful …

Aug 22, 2025
CVE-2025-43760
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.6, 2024.Q3.0 through 2024.Q3.13, …

Aug 22, 2025
CVE-2024-53499
9.8 CRITICAL

Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.

Aug 22, 2025
CVE-2024-53496
9.8 CRITICAL

Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

Aug 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.