CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-7847
8.8 HIGH

The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 …

Jul 31, 2025
CVE-2025-5720
6.4 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, …

Jul 31, 2025
CVE-2025-8365
3.5 LOW

A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Jul 31, 2025
CVE-2025-8348
7.3 HIGH

A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability affects unknown code of the file /home. …

Jul 31, 2025
CVE-2025-8347
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an unknown part of the file /sys/task/findAllTask. …

Jul 31, 2025
CVE-2025-8346
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue is some unknown functionality of the file …

Jul 31, 2025
CVE-2025-8345
6.3 MEDIUM

A vulnerability classified as critical was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this vulnerability is the function delete_user …

Jul 31, 2025
CVE-2025-54829

Rejected reason: Not used

Jul 31, 2025
CVE-2025-54828

Rejected reason: Not used

Jul 31, 2025
CVE-2025-54827

Rejected reason: Not used

Jul 31, 2025
CVE-2025-54826

Rejected reason: Not used

Jul 31, 2025
CVE-2025-54825

Rejected reason: Not used

Jul 31, 2025
CVE-2025-54824

Rejected reason: Not used

Jul 31, 2025
CVE-2025-54823

Rejected reason: Not used

Jul 31, 2025
CVE-2023-41674

Rejected reason: Not used

Jul 31, 2025
CVE-2025-8344
6.3 MEDIUM

A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation …

Jul 31, 2025
CVE-2025-8343
4.3 MEDIUM

A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file …

Jul 31, 2025
CVE-2025-8340
4.3 MEDIUM

A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Jul 31, 2025
CVE-2025-8339
7.3 HIGH

A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jul 31, 2025
CVE-2025-8338
7.3 HIGH

A vulnerability was found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jul 31, 2025
CVE-2025-54085
3.8 LOW

CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who …

Jul 31, 2025
CVE-2025-49084
9.1 CRITICAL

CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without …

Jul 31, 2025
CVE-2025-49083
7.2 HIGH

CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to …

Jul 31, 2025
CVE-2025-49082
2.7 LOW

CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who …

Jul 31, 2025
CVE-2025-36040
6.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

Jul 31, 2025
CVE-2025-36039
6.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,

Jul 31, 2025
CVE-2025-8337
2.4 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the …

Jul 30, 2025
CVE-2025-8336
7.3 HIGH

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_user. The manipulation …

Jul 30, 2025
CVE-2025-7356

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 30, 2025
CVE-2024-11478

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 30, 2025
CVE-2025-8335
4.3 MEDIUM

A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part. The manipulation leads to cross-site …

Jul 30, 2025
CVE-2025-8334
7.3 HIGH

A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 30, 2025
CVE-2025-54586
7.1 HIGH

GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commits into the …

Jul 30, 2025
CVE-2025-8333
7.3 HIGH

A vulnerability was found in code-projects Online Farm System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 30, 2025
CVE-2025-8332
7.3 HIGH

A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /register.php. …

Jul 30, 2025
CVE-2025-54585
6.5 MEDIUM

GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can exploit the way GitProxy handles …

Jul 30, 2025
CVE-2025-8331
7.3 HIGH

A vulnerability was found in code-projects Online Farm System 1.0 and classified as critical. This issue affects some unknown processing of the file /forgot_pass.php. The …

Jul 30, 2025
CVE-2025-8330
7.3 HIGH

A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit1.php. The manipulation …

Jul 30, 2025
CVE-2025-54584
5.7 MEDIUM

GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19.1 and below, an attacker can craft a …

Jul 30, 2025
CVE-2025-54583
6.5 MEDIUM

GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote …

Jul 30, 2025
CVE-2025-54582

Rejected reason: Reason: This candidate was issued in error. Valid Netty requests are issued via https://github.com/netty/netty.

Jul 30, 2025
CVE-2025-54581
7.5 HIGH

vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-controlled HTTP Proxy-Authorization header and passed to Extension::try_from …

Jul 30, 2025
CVE-2025-54576
9.1 CRITICAL

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load …

Jul 30, 2025
CVE-2025-54575
5.3 MEDIUM

ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment extension block …

Jul 30, 2025
CVE-2025-53022
8.6 HIGH

TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a …

Jul 30, 2025
CVE-2025-52187
8.2 HIGH

GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php.

Jul 30, 2025
CVE-2025-51954
6.1 MEDIUM

playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability.

Jul 30, 2025
CVE-2024-48916
8.1 HIGH

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" …

Jul 30, 2025
CVE-2025-8329
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /filter3.php. The manipulation …

Jul 30, 2025
CVE-2025-51951
6.1 MEDIUM

andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability.

Jul 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.