CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9140
6.3 MEDIUM

A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this issue is some unknown functionality of the file …

Aug 19, 2025
CVE-2025-54336
9.8 CRITICAL

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can …

Aug 19, 2025
CVE-2025-50567
10.0 CRITICAL

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL …

Aug 19, 2025
CVE-2025-50461
6.5 MEDIUM

A deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script when using the "fsdp" backend. The script calls torch.load() with weights_only=False on …

Aug 19, 2025
CVE-2025-4690
4.3 MEDIUM

A regular expression used by AngularJS' linky https://docs.angularjs.org/api/ngSanitize/filter/linky filter to detect URLs in input text is vulnerable to super-linear runtime due to backtracking. With a …

Aug 19, 2025
CVE-2025-4046
8.5 HIGH

A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization

Aug 19, 2025
CVE-2025-4044
8.2 HIGH

Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.

Aug 19, 2025
CVE-2025-43739
4.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 …

Aug 19, 2025
CVE-2024-45062
6.4 MEDIUM

A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer that supports IPP-over-USB can cause a buffer overflow which …

Aug 19, 2025
CVE-2025-9139
4.3 MEDIUM

A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information …

Aug 19, 2025
CVE-2025-9138
3.5 LOW

A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Performing manipulation of the argument Title results in cross …

Aug 19, 2025
CVE-2025-9137
3.5 LOW

A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm. Such manipulation of the argument alias leads to …

Aug 19, 2025
CVE-2025-43740
5.4 MEDIUM

A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 …

Aug 19, 2025
CVE-2025-9136
5.3 MEDIUM

A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation causes out-of-bounds read. The attack …

Aug 19, 2025
CVE-2025-9135
5.3 MEDIUM

A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 12.1.1(258) on Android. The impacted element is an unknown function …

Aug 19, 2025
CVE-2025-9134
5.3 MEDIUM

A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected element is an unknown function of the …

Aug 19, 2025
CVE-2025-8783
4.4 MEDIUM

The Contact Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title’ parameter in all versions up to, and including, 8.6.5 due …

Aug 19, 2025
CVE-2025-8567
6.4 MEDIUM

The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to …

Aug 19, 2025
CVE-2025-41689
7.5 HIGH

An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access to the stored measurement data.

Aug 19, 2025
CVE-2025-41685
6.5 MEDIUM

A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.

Aug 19, 2025
CVE-2025-8723
9.8 CRITICAL

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in …

Aug 19, 2025
CVE-2025-8622
6.4 MEDIUM

The Flexible Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Flexible Maps shortcode in all versions up to, and including, …

Aug 19, 2025
CVE-2025-7670
7.5 HIGH

The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in all versions up to, and including, 6.1.5 …

Aug 19, 2025
CVE-2025-7654
8.8 HIGH

Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, …

Aug 19, 2025
CVE-2025-8218
8.8 HIGH

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, …

Aug 19, 2025
CVE-2025-6758
9.8 CRITICAL

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, …

Aug 19, 2025
CVE-2025-38553
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: Restrict conditions for adding duplicating netems to qdisc tree netem_enqueue's duplication prevention logic breaks …

Aug 19, 2025
CVE-2025-8357
4.3 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file deletion in the /wp-content/uploads directory due to insufficient file path validation and user …

Aug 19, 2025
CVE-2025-5417
6.1 MEDIUM

An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has …

Aug 19, 2025
CVE-2025-7496
6.4 MEDIUM

The WPC Smart Compare for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via DOM elements in all versions up to, and including, …

Aug 19, 2025
CVE-2025-57725

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57724

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57723

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57722

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57721

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57720

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57719

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57718

Rejected reason: Not used

Aug 19, 2025
CVE-2025-57717

Rejected reason: Not used

Aug 19, 2025
CVE-2025-54862
5.4 MEDIUM

Sante PACS Server web portal is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage …

Aug 18, 2025
CVE-2025-54759
6.1 MEDIUM

Sante PACS Server is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage and stealing …

Aug 18, 2025
CVE-2025-54156
7.4 HIGH

The Sante PACS Server Web Portal sends credential information without encryption.

Aug 18, 2025
CVE-2025-53948
7.5 HIGH

The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application …

Aug 18, 2025
CVE-2025-52584
7.8 HIGH

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing XE …

Aug 18, 2025
CVE-2025-46269
7.8 HIGH

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 …

Aug 18, 2025
CVE-2025-9119
2.4 LOW

A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation …

Aug 18, 2025
CVE-2025-53705
7.8 HIGH

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO …

Aug 18, 2025
CVE-2025-41392
7.8 HIGH

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing AR …

Aug 18, 2025
CVE-2025-8098
7.8 HIGH

An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges.

Aug 18, 2025
CVE-2025-55591
9.8 CRITICAL

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.

Aug 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.