CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-23281
7.0 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race condition might be able …

Aug 2, 2025
CVE-2025-23279
7.0 HIGH

NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of …

Aug 2, 2025
CVE-2025-23278
7.1 HIGH

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index validation by issuing a call with crafted …

Aug 2, 2025
CVE-2025-23277
7.3 HIGH

NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under …

Aug 2, 2025
CVE-2025-23276
7.8 HIGH

NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful exploit of this vulnerability may lead to …

Aug 2, 2025
CVE-2025-8471
7.3 HIGH

A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file …

Aug 2, 2025
CVE-2025-8470
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/deleteroom.php. The manipulation …

Aug 2, 2025
CVE-2025-8469
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The …

Aug 2, 2025
CVE-2025-8468
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Aug 2, 2025
CVE-2025-7710
9.8 CRITICAL

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to …

Aug 2, 2025
CVE-2025-7500
6.4 MEDIUM

The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 …

Aug 2, 2025
CVE-2025-8467
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 2, 2025
CVE-2025-8488
4.3 MEDIUM

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Aug 2, 2025
CVE-2025-6722
5.3 MEDIUM

The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Aug 2, 2025
CVE-2025-8466
7.3 HIGH

A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. …

Aug 2, 2025
CVE-2025-8400
6.1 MEDIUM

The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization …

Aug 2, 2025
CVE-2025-8399
6.4 MEDIUM

The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 …

Aug 2, 2025
CVE-2025-8391
6.4 MEDIUM

The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, …

Aug 2, 2025
CVE-2025-6832
6.1 MEDIUM

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via …

Aug 2, 2025
CVE-2025-8317
6.4 MEDIUM

The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all versions up to, and including, 0.3 …

Aug 2, 2025
CVE-2025-8212
6.4 MEDIUM

The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter widget in all versions up to, and …

Aug 2, 2025
CVE-2025-8152
5.3 MEDIUM

The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a …

Aug 2, 2025
CVE-2025-6754
8.8 HIGH

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() …

Aug 2, 2025
CVE-2025-6626
4.4 MEDIUM

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in …

Aug 2, 2025
CVE-2025-4588
6.4 MEDIUM

The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, …

Aug 2, 2025
CVE-2025-8146
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut Text widget in all versions up to, …

Aug 2, 2025
CVE-2025-7694
6.8 MEDIUM

The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versions …

Aug 2, 2025
CVE-2025-6078
5.4 MEDIUM

Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but …

Aug 2, 2025
CVE-2025-6077
9.8 CRITICAL

Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.

Aug 2, 2025
CVE-2025-6076
8.8 HIGH

Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authenticated attacker to upload a …

Aug 2, 2025
CVE-2025-54796
7.5 HIGH

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is …

Aug 2, 2025
CVE-2025-54790
6.5 MEDIUM

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the …

Aug 2, 2025
CVE-2025-54789
6.1 MEDIUM

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic …

Aug 2, 2025
CVE-2025-54782
8.8 HIGH

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in …

Aug 2, 2025
CVE-2025-54781
2.8 LOW

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau in version 1.0.0, the himmelblaud_tasks service leaks …

Aug 2, 2025
CVE-2025-54386
9.8 CRITICAL

Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered …

Aug 2, 2025
CVE-2025-54136
7.2 HIGH

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by modifying …

Aug 2, 2025
CVE-2025-54133
9.6 CRITICAL

Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosure vulnerability in Cursor's MCP …

Aug 2, 2025
CVE-2025-54792
6.8 MEDIUM

LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection. In versions 1.16.1 …

Aug 1, 2025
CVE-2025-54424
8.1 HIGH

1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below, …

Aug 1, 2025
CVE-2025-54132
4.4 MEDIUM

Cursor is a code editor built for programming with AI. In versions below 1.3, Mermaid (which is used to render diagrams) allows embedding images which …

Aug 1, 2025
CVE-2025-54131
6.4 MEDIUM

Cursor is a code editor built for programming with AI. In versions below 1.3, an attacker can bypass the allow list in auto-run mode with …

Aug 1, 2025
CVE-2024-13978
2.5 LOW

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the …

Aug 1, 2025
CVE-2013-10063

A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded web server. Authenticated attackers can exploit crafted …

Aug 1, 2025
CVE-2013-10062

A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi …

Aug 1, 2025
CVE-2013-10061
7.2 HIGH

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in …

Aug 1, 2025
CVE-2013-10060
7.2 HIGH

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware versions 1.0.0.36 and prior via the pppoe.cgi endpoint. A …

Aug 1, 2025
CVE-2013-10059
7.2 HIGH

An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface …

Aug 1, 2025
CVE-2013-10058

An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web …

Aug 1, 2025
CVE-2013-10057

A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically the ConnectToSynactis method. When a long string is passed to this …

Aug 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.