CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54423
5.4 MEDIUM

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in …

Jul 28, 2025
CVE-2025-54419
10.0 CRITICAL

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. …

Jul 28, 2025
CVE-2025-50486
7.1 HIGH

Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50485
7.1 HIGH

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-29534
8.8 HIGH

An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker with valid credentials to execute arbitrary commands with root …

Jul 28, 2025
CVE-2025-8283
3.7 LOW

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may …

Jul 28, 2025
CVE-2025-8194
7.5 HIGH

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with …

Jul 28, 2025
CVE-2025-50487
7.1 HIGH

Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50484
7.1 HIGH

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-54299

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

Jul 28, 2025
CVE-2025-54298

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

Jul 28, 2025
CVE-2025-50492
7.5 HIGH

Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50491
7.1 HIGH

Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50489
7.5 HIGH

Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50488
7.1 HIGH

Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-43023
9.1 CRITICAL

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of …

Jul 28, 2025
CVE-2025-7676

DLL hijacking of all PE32 executables when run on Windows for ARM64 CPU architecture. This allows an attacker to execute code, if the attacker can …

Jul 28, 2025
CVE-2025-54538
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command

Jul 28, 2025
CVE-2025-54537
5.5 MEDIUM

In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots

Jul 28, 2025
CVE-2025-54536
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint

Jul 28, 2025
CVE-2025-54535
5.8 MEDIUM

In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms

Jul 28, 2025
CVE-2025-54534
4.8 MEDIUM

In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page

Jul 28, 2025
CVE-2025-54533
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

Jul 28, 2025
CVE-2025-54532
4.3 MEDIUM

In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

Jul 28, 2025
CVE-2025-54531
7.7 HIGH

In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

Jul 28, 2025
CVE-2025-54530
7.5 HIGH

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

Jul 28, 2025
CVE-2025-54529
3.7 LOW

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

Jul 28, 2025
CVE-2025-54528
5.4 MEDIUM

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

Jul 28, 2025
CVE-2025-54527
6.1 MEDIUM

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

Jul 28, 2025
CVE-2025-50494
7.5 HIGH

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50493
7.5 HIGH

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-50490
7.5 HIGH

Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

Jul 28, 2025
CVE-2025-6250
6.7 MEDIUM

Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service …

Jul 28, 2025
CVE-2025-2297
7.8 HIGH

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under …

Jul 28, 2025
CVE-2024-49343
5.4 MEDIUM

IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Jul 28, 2025
CVE-2024-49342
7.5 HIGH

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Jul 28, 2025
CVE-2025-54418
9.8 CRITICAL

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler for …

Jul 28, 2025
CVE-2025-53696

iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious …

Jul 28, 2025
CVE-2025-30125
9.8 CRITICAL

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an …

Jul 28, 2025
CVE-2025-8279
8.7 HIGH

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

Jul 28, 2025
CVE-2025-53695

OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.

Jul 28, 2025
CVE-2025-32731
6.1 MEDIUM

A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream MedDream PACS Premium 7.3.5.860. A specially crafted malicious url can lead to …

Jul 28, 2025
CVE-2025-30133
9.8 CRITICAL

An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app …

Jul 28, 2025
CVE-2025-30126
5.3 MEDIUM

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Via port 7777 without any need to pair or press a physical button, a …

Jul 28, 2025
CVE-2025-30124
9.8 CRITICAL

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is …

Jul 28, 2025
CVE-2025-27724
9.3 CRITICAL

A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilities. …

Jul 28, 2025
CVE-2025-26469
9.3 CRITICAL

An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application can decrypt credentials stored in a …

Jul 28, 2025
CVE-2025-24485
5.8 MEDIUM

A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP request can lead to SSRF. An …

Jul 28, 2025
CVE-2025-8275
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown …

Jul 28, 2025
CVE-2025-54569
4.5 MEDIUM

In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation.

Jul 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.