CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8221
4.3 MEDIUM

A vulnerability classified as problematic was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f75042c9f7f615a3fed2ec1cefb999. Affected by this vulnerability is the function goodsSearch of the file …

Jul 27, 2025
CVE-2025-8104
4.3 MEDIUM

The Memory Usage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.98. This is due to missing …

Jul 27, 2025
CVE-2025-8220
7.3 HIGH

A vulnerability has been found in Engeman Web up to 12.0.0.2. The affected element is an unknown function of the file /Login/RecoveryPass of the component …

Jul 27, 2025
CVE-2025-8219
6.3 MEDIUM

A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. It has been rated as critical. This issue affects some unknown …

Jul 27, 2025
CVE-2025-54597
7.2 HIGH

LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.

Jul 27, 2025
CVE-2025-6241
4.4 MEDIUM

LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable …

Jul 27, 2025
CVE-2025-8211
3.5 LOW

A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the …

Jul 26, 2025
CVE-2025-8210
5.3 MEDIUM

A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affected is an unknown function of …

Jul 26, 2025
CVE-2025-8207
5.3 MEDIUM

A vulnerability was found in Canara ai1 Mobile Banking App 3.6.23 on Android and classified as problematic. This issue affects some unknown processing of the …

Jul 26, 2025
CVE-2025-8206
3.1 LOW

A vulnerability, which was classified as problematic, was found in Comodo Dragon up to 134.0.6998.179. This affects an unknown part of the component IP DNS …

Jul 26, 2025
CVE-2025-8205
3.7 LOW

A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by this issue is some unknown functionality of …

Jul 26, 2025
CVE-2025-8204
3.1 LOW

A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerability is an unknown functionality of the component HSTS …

Jul 26, 2025
CVE-2025-8203
6.3 MEDIUM

A vulnerability classified as critical has been found in Jingmen Zeyou Large File Upload Control up to 6.3. Affected is an unknown function of the …

Jul 26, 2025
CVE-2025-8191
3.5 LOW

A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of …

Jul 26, 2025
CVE-2025-8190
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Courier Management System 1.0. This issue affects some unknown processing of the file …

Jul 26, 2025
CVE-2025-8189
6.3 MEDIUM

A vulnerability classified as critical was found in Campcodes Courier Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The manipulation of …

Jul 26, 2025
CVE-2025-8188
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Courier Management System 1.0. This affects an unknown part of the file /edit_staff.php. The manipulation …

Jul 26, 2025
CVE-2025-8187
6.3 MEDIUM

A vulnerability was found in Campcodes Courier Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 26, 2025
CVE-2025-8186
6.3 MEDIUM

A vulnerability was found in Campcodes Courier Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 26, 2025
CVE-2025-8185
7.3 HIGH

A vulnerability was found in 1000 Projects ABC Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Jul 26, 2025
CVE-2025-8184
8.8 HIGH

A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file /goform/formSetWanL2TPtriggers of …

Jul 26, 2025
CVE-2025-8182
5.6 MEDIUM

A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component …

Jul 26, 2025
CVE-2025-6991
7.5 HIGH

The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via the 'TH_LatestPosts4` widget. This makes …

Jul 26, 2025
CVE-2025-6989
8.1 HIGH

The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in all versions up …

Jul 26, 2025
CVE-2025-5529
6.4 MEDIUM

The Educenter theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Circle Counter Block in all versions up to, and including, 1.6.2 due …

Jul 26, 2025
CVE-2025-8181
7.2 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.conf of …

Jul 26, 2025
CVE-2025-8180
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formdeleteUserName of the file …

Jul 26, 2025
CVE-2025-8097
5.3 MEDIUM

The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient validation …

Jul 26, 2025
CVE-2025-7501
6.4 MEDIUM

The Wonder Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image title and description DOM in all versions up to, and …

Jul 26, 2025
CVE-2025-6987
6.4 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 …

Jul 26, 2025
CVE-2025-8198
7.5 HIGH

The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. …

Jul 26, 2025
CVE-2025-8179
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of …

Jul 26, 2025
CVE-2025-8178
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /goform/RequestsProcessLaid. The manipulation of the …

Jul 26, 2025
CVE-2025-6895
9.8 CRITICAL

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. …

Jul 26, 2025
CVE-2025-8177
5.3 MEDIUM

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. …

Jul 26, 2025
CVE-2025-8176
5.3 MEDIUM

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. …

Jul 26, 2025
CVE-2025-8103
4.3 MEDIUM

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due …

Jul 26, 2025
CVE-2025-54416
9.1 CRITICAL

tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, …

Jul 26, 2025
CVE-2025-54415

dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0a8 and below, a high-severity vulnerability has been identified …

Jul 26, 2025
CVE-2025-54414

Anubis is a Web AI Firewall Utility that weighs the soul of users' connections using one or more challenges in order to protect upstream resources …

Jul 26, 2025
CVE-2025-54413

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain an inconsistency in MethodNode, which …

Jul 26, 2025
CVE-2025-54412

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode …

Jul 26, 2025
CVE-2025-54385
9.8 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions between 17.0.0-rc1 to 17.2.2 and versions …

Jul 26, 2025
CVE-2025-54380
6.5 MEDIUM

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would incorrectly send the …

Jul 26, 2025
CVE-2025-54378
8.3 HIGH

HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 and …

Jul 26, 2025
CVE-2025-54366
8.8 HIGH

FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a …

Jul 26, 2025
CVE-2025-50185

DbGate is cross-platform database manager. In versions 6.6.0 and below, DbGate allows unauthorized file access due to insufficient validation of file paths and types. A …

Jul 26, 2025
CVE-2025-50184

DbGate is cross-platform database manager. In versions 6.4.3-premium-beta.5 and below, DbGate is vulnerable to a directory traversal flaw. The file parameter is not properly restricted …

Jul 26, 2025
CVE-2024-13507
7.5 HIGH

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in …

Jul 26, 2025
CVE-2025-8175
6.5 MEDIUM

A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the …

Jul 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.