CVE Database

9968+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5893
9.8 CRITICAL

Smart Parking Management System from Honding Technology has an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access a specific page and obtain …

Jun 9, 2025
CVE-2025-3461
9.1 CRITICAL

The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is …

Jun 8, 2025
CVE-2025-41646
9.8 CRITICAL

An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of …

Jun 6, 2025
CVE-2025-27531
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to …

Jun 6, 2025
CVE-2025-49073
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This issue affects Sweet Dessert: from n/a through < 1.1.13.

Jun 6, 2025
CVE-2025-49072
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy mr-murphy allows Object Injection.This issue affects Mr. Murphy: from n/a through < 1.2.12.1.

Jun 6, 2025
CVE-2025-47586
9.0 CRITICAL

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors - Events stm-motors-events allows PHP Local File …

Jun 6, 2025
CVE-2025-48782
9.8 CRITICAL

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 …

Jun 6, 2025
CVE-2025-48780
9.8 CRITICAL

A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers …

Jun 6, 2025
CVE-2025-3365
9.8 CRITICAL

A missing protection against path traversal allows to access any file on the server.

Jun 6, 2025
CVE-2025-5486
9.8 CRITICAL

The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 …

Jun 6, 2025
CVE-2025-47966
9.8 CRITICAL

Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.

Jun 5, 2025
CVE-2025-1793
9.8 CRITICAL

Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially …

Jun 5, 2025
CVE-2025-5630
9.8 CRITICAL

A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of …

Jun 5, 2025
CVE-2025-5624
9.8 CRITICAL

A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The …

Jun 5, 2025
CVE-2025-5623
9.8 CRITICAL

A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation …

Jun 5, 2025
CVE-2025-5622
9.8 CRITICAL

A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The …

Jun 5, 2025
CVE-2025-48935
9.1 CRITICAL

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's permission read/write …

Jun 4, 2025
CVE-2025-5600
9.8 CRITICAL

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The …

Jun 4, 2025
CVE-2025-20286
9.9 CRITICAL

A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an …

Jun 4, 2025
CVE-2025-4578
9.8 CRITICAL

The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Jun 4, 2025
CVE-2025-49223
9.8 CRITICAL

billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a …

Jun 4, 2025
CVE-2025-49002
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that …

Jun 3, 2025
CVE-2025-49001
9.8 CRITICAL

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user …

Jun 3, 2025
CVE-2025-23097
9.1 CRITICAL

An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.

Jun 3, 2025
CVE-2025-32106
9.8 CRITICAL

In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.

Jun 3, 2025
CVE-2025-32105
9.8 CRITICAL

A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.

Jun 3, 2025
CVE-2025-45854
10.0 CRITICAL

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

Jun 3, 2025
CVE-2025-44148
9.8 CRITICAL

Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component

Jun 3, 2025
CVE-2025-25022
9.6 CRITICAL

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to …

Jun 3, 2025
CVE-2025-4517
9.4 CRITICAL

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract …

Jun 3, 2025
CVE-2025-4797
9.8 CRITICAL

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and …

Jun 3, 2025
CVE-2025-23099
9.1 CRITICAL

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

Jun 2, 2025
CVE-2025-5086
9.0 CRITICAL KEV

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

Jun 2, 2025
CVE-2025-37096
9.8 CRITICAL

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37095
9.8 CRITICAL

A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37093
9.8 CRITICAL

An authentication bypass vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37092
9.8 CRITICAL

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37090
9.8 CRITICAL

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-37089
9.8 CRITICAL

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Jun 2, 2025
CVE-2025-1750
9.8 CRITICAL

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, …

Jun 2, 2025
CVE-2025-0324
9.4 CRITICAL

The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

Jun 2, 2025
CVE-2025-49113
9.9 CRITICAL KEV

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated …

Jun 2, 2025
CVE-2025-20674
9.8 CRITICAL

In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation …

Jun 2, 2025
CVE-2025-20672
9.8 CRITICAL

In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Jun 2, 2025
CVE-2025-5408
9.8 CRITICAL

A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this …

Jun 1, 2025
CVE-2025-40908
9.1 CRITICAL

YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

Jun 1, 2025
CVE-2025-4631
9.8 CRITICAL

The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. …

May 31, 2025
CVE-2025-4607
9.8 CRITICAL

The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() …

May 31, 2025
CVE-2025-48949
9.8 CRITICAL

Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the …

May 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.