CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-66330
4.9 MEDIUM

App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 8, 2025
CVE-2025-66329
4.0 MEDIUM

Permission control vulnerability in the window management module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66325
6.2 MEDIUM

Permission control vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 8, 2025
CVE-2025-58279
4.4 MEDIUM

Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 8, 2025
CVE-2025-26489
6.5 MEDIUM

Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, thus causing a …

Dec 8, 2025
CVE-2025-14224
4.3 MEDIUM

A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown functionality of the component File …

Dec 8, 2025
CVE-2025-66326
6.7 MEDIUM

Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66323
5.3 MEDIUM

Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66322
5.1 MEDIUM

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66321
5.1 MEDIUM

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-66320
5.1 MEDIUM

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Dec 8, 2025
CVE-2025-14255
6.5 MEDIUM

Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Dec 8, 2025
CVE-2025-14254
6.5 MEDIUM

Vitals ESP developed by Galaxy Software Services has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Dec 8, 2025
CVE-2025-14253
4.9 MEDIUM

Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary …

Dec 8, 2025
CVE-2025-14222
6.3 MEDIUM

A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file /print_personnel_report.php. This manipulation of the …

Dec 8, 2025
CVE-2025-14220
4.3 MEDIUM

A security vulnerability has been detected in ORICO CD3510 1.9.12. This affects an unknown function of the component File Upload. The manipulation leads to path …

Dec 8, 2025
CVE-2025-14219
4.7 MEDIUM

A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_running.php. Executing …

Dec 8, 2025
CVE-2025-14214
6.3 MEDIUM

A vulnerability has been found in itsourcecode Student Information System 1.0. This affects an unknown part of the file /section_edit1.php. The manipulation of the argument …

Dec 8, 2025
CVE-2025-14208
6.3 MEDIUM

A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the …

Dec 8, 2025
CVE-2025-14206
6.5 MEDIUM

A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/delete-fee.php of the component …

Dec 8, 2025
CVE-2025-14204
6.3 MEDIUM

A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthorization of the file /.well-known/oauth-authorization-server of the component OAuth Server Discovery. …

Dec 7, 2025
CVE-2025-14203
6.3 MEDIUM

A flaw has been found in code-projects Question Paper Generator up to 1.0. This vulnerability affects unknown code of the file /selectquestionuser.php. This manipulation of …

Dec 7, 2025
CVE-2025-14199
6.3 MEDIUM

A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text.txt?override=false of the component Web Administration …

Dec 7, 2025
CVE-2025-14198
5.3 MEDIUM

A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummytoken of the component Web Administration Module. Performing manipulation …

Dec 7, 2025
CVE-2025-14197
5.3 MEDIUM

A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/resources/f96956469e7be39d of the …

Dec 7, 2025
CVE-2025-14195
6.3 MEDIUM

A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/add_file_query.php. The manipulation of …

Dec 7, 2025
CVE-2025-14193
6.3 MEDIUM

A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file /view_personnel.php. Executing a manipulation of the …

Dec 7, 2025
CVE-2025-14185
6.3 MEDIUM

A vulnerability was identified in Yonyou U8 Cloud 5.0/5.0sp/5.1/5.1sp. The affected element is an unknown function of the file nc/pubitf/erm/mobile/appservice/AppServletService.class. Such manipulation of the argument …

Dec 7, 2025
CVE-2025-14184
6.3 MEDIUM

A vulnerability was determined in SGAI Space1 NAS N1211DS up to 1.0.915. Impacted is the function RENAME_FILE/OPERATE_FILE/NGNIX_UPLOAD of the file /cgi-bin/JSONAPI of the component gsaiagent. …

Dec 7, 2025
CVE-2025-14183
4.3 MEDIUM

A vulnerability was found in SGAI Space1 NAS N1211DS up to 1.0.915. This issue affects the function GET_FACTORY_INFO/GET_USER_INFO of the file /cgi-bin/JSONAPI of the component …

Dec 7, 2025
CVE-2025-14182
6.3 MEDIUM

A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the file /sobey-mchEditor/watermark/upload. The manipulation of the argument …

Dec 7, 2025
CVE-2025-14140
6.5 MEDIUM

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/websHostFilter. Performing manipulation of the argument …

Dec 6, 2025
CVE-2025-14139
5.7 MEDIUM

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Impacted is the function strcpy of the file /goform/formConfigDnsFilterGlobal. Such manipulation of the argument …

Dec 6, 2025
CVE-2025-13748
5.3 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Dec 6, 2025
CVE-2025-14117
4.3 MEDIUM

A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The attack may be …

Dec 6, 2025
CVE-2025-13907
6.4 MEDIUM

The CSS3 Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 0.1 …

Dec 6, 2025
CVE-2025-13899
6.4 MEDIUM

The TR Timthumb plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.0.4 due to …

Dec 6, 2025
CVE-2025-13898
6.4 MEDIUM

The Ultra Skype Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_id' parameter of the [ultra_skype] shortcode in all versions up …

Dec 6, 2025
CVE-2025-13896
6.4 MEDIUM

The Social Feed Gallery Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [igp-wp] shortcode in all versions …

Dec 6, 2025
CVE-2025-13894
6.1 MEDIUM

The CSV Sumotto plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 1.0 due …

Dec 6, 2025
CVE-2025-13863
6.4 MEDIUM

The RevInsite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `token` parameter in all versions up to, and including, 1.1.0 due to …

Dec 6, 2025
CVE-2025-13857
6.4 MEDIUM

The Yet Another WebClap for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' parameter of the webclap_button shortcode in all …

Dec 6, 2025
CVE-2025-13856
6.4 MEDIUM

The Extra Post Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the extra-images shortcode in all versions up …

Dec 6, 2025
CVE-2025-13666
5.3 MEDIUM

The Helloprint plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.2. This is due to the plugin registering a …

Dec 6, 2025
CVE-2025-13656
6.4 MEDIUM

The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in all versions up to, and including, …

Dec 6, 2025
CVE-2025-13629
4.3 MEDIUM

The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to …

Dec 6, 2025
CVE-2025-13626
6.1 MEDIUM

The myLCO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.8.1 due to …

Dec 6, 2025
CVE-2025-13358
5.3 MEDIUM

The Accessiy By CodeConfig Accessibility plugin for WordPress is vulnerable to unauthorized page creation due to missing authorization checks in versions up to, and including, …

Dec 6, 2025
CVE-2025-13309
4.3 MEDIUM

The Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters plugin for WordPress is vulnerable to authorization bypass in versions up to, …

Dec 6, 2025
CVE-2025-13308
5.4 MEDIUM

The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This …

Dec 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.