CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-63402
5.5 MEDIUM

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on …

Dec 3, 2025
CVE-2025-63401
5.5 MEDIUM

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

Dec 3, 2025
CVE-2025-13992
4.7 MEDIUM

Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML …

Dec 3, 2025
CVE-2025-12084
5.3 MEDIUM

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when …

Dec 3, 2025
CVE-2025-64527
6.5 MEDIUM

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes when JWT authentication is configured with the remote JWKS fetching, …

Dec 3, 2025
CVE-2025-65842
5.1 MEDIUM

The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local …

Dec 3, 2025
CVE-2025-65841
6.2 MEDIUM

Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings using a weak obfuscation scheme. The password is "encrypted" through …

Dec 3, 2025
CVE-2025-62686
6.2 MEDIUM

A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 on macOS. Due to the absence …

Dec 3, 2025
CVE-2025-55076
6.2 MEDIUM

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections …

Dec 3, 2025
CVE-2025-53965
5.3 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, …

Dec 3, 2025
CVE-2025-20389
4.3 MEDIUM

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk …

Dec 3, 2025
CVE-2025-20384
5.3 MEDIUM

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject …

Dec 3, 2025
CVE-2025-20383
4.3 MEDIUM

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, …

Dec 3, 2025
CVE-2025-20381
5.4 MEDIUM

In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command …

Dec 3, 2025
CVE-2025-13751
5.5 MEDIUM

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service …

Dec 3, 2025
CVE-2025-57202
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML …

Dec 3, 2025
CVE-2025-57200
6.5 MEDIUM

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary …

Dec 3, 2025
CVE-2025-13949
6.3 MEDIUM

A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.go. The manipulation of the argument File leads to …

Dec 3, 2025
CVE-2025-13948
5.6 MEDIUM

A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. …

Dec 3, 2025
CVE-2025-13756
4.3 MEDIUM

The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in …

Dec 3, 2025
CVE-2025-13401
6.4 MEDIUM

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, …

Dec 3, 2025
CVE-2025-13359
6.5 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in …

Dec 3, 2025
CVE-2025-13354
4.3 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and …

Dec 3, 2025
CVE-2025-13109
4.3 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Dec 3, 2025
CVE-2025-12887
5.4 MEDIUM

The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin …

Dec 3, 2025
CVE-2025-12358
4.3 MEDIUM

The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is …

Dec 3, 2025
CVE-2025-39665
5.3 MEDIUM

User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.

Dec 3, 2025
CVE-2025-13946
5.5 MEDIUM

MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service

Dec 3, 2025
CVE-2025-13945
5.5 MEDIUM

HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

Dec 3, 2025
CVE-2025-13495
4.9 MEDIUM

The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, and including, 1.3.1. This is due …

Dec 3, 2025
CVE-2025-12585
5.3 MEDIUM

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 via …

Dec 3, 2025
CVE-2025-10304
5.3 MEDIUM

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Dec 3, 2025
CVE-2025-13448
6.4 MEDIUM

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 …

Dec 3, 2025
CVE-2025-65955
4.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ …

Dec 2, 2025
CVE-2025-55181
5.3 MEDIUM

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends …

Dec 2, 2025
CVE-2025-65657
6.5 MEDIUM

FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files …

Dec 2, 2025
CVE-2025-65380
6.5 MEDIUM

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated …

Dec 2, 2025
CVE-2025-65379
6.5 MEDIUM

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is …

Dec 2, 2025
CVE-2025-66460
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66459
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66458
6.1 MEDIUM

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior …

Dec 2, 2025
CVE-2025-66454
6.5 MEDIUM

Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret …

Dec 2, 2025
CVE-2025-57850
6.4 MEDIUM

A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during …

Dec 2, 2025
CVE-2025-13637
4.3 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Dec 2, 2025
CVE-2025-13636
4.3 MEDIUM

Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Dec 2, 2025
CVE-2025-13635
4.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Dec 2, 2025
CVE-2025-13634
4.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted …

Dec 2, 2025
CVE-2025-13632
5.4 MEDIUM

Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a user to install a malicious extension to potentially perform …

Dec 2, 2025
CVE-2025-65881
6.1 MEDIUM

Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php.

Dec 2, 2025
CVE-2025-65215
6.1 MEDIUM

Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product_expiry/add-supplier.php via the Supplier Name field.

Dec 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.