CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-65105
4.5 MEDIUM

Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used …

Dec 2, 2025
CVE-2025-64750
4.5 MEDIUM

SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.3.5 and SingularityPRO 4.1.11 and 4.3.5, if a user relies on LSM restrictions to …

Dec 2, 2025
CVE-2025-52622
5.4 MEDIUM

The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the application's client-side security posture, making it more vulnerable …

Dec 2, 2025
CVE-2025-65186
6.1 MEDIUM

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The …

Dec 2, 2025
CVE-2025-64070
5.4 MEDIUM

Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject Description field.

Dec 2, 2025
CVE-2025-65187
6.1 MEDIUM

A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this …

Dec 2, 2025
CVE-2025-63872
6.1 MEDIUM

DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated SVG content.

Dec 2, 2025
CVE-2025-59704
4.6 MEDIUM

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the the BIOS menu because is …

Dec 2, 2025
CVE-2025-58113
6.5 MEDIUM

An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401. By using a specially crafted EMF file, an attacker …

Dec 2, 2025
CVE-2025-13877
5.6 MEDIUM

A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. …

Dec 2, 2025
CVE-2025-13372
4.3 MEDIUM

An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to SQL injection in column aliases, using …

Dec 2, 2025
CVE-2025-12630
4.9 MEDIUM

The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability check on its AJAX request handler, allowing users …

Dec 2, 2025
CVE-2025-59705
6.8 MEDIUM

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB …

Dec 2, 2025
CVE-2025-59701
4.1 MEDIUM

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker (with elevated privileges) to read and modify …

Dec 2, 2025
CVE-2025-59699
6.8 MEDIUM

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by booting from a …

Dec 2, 2025
CVE-2025-59698
6.8 MEDIUM

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate attacker to gain access to the EOL …

Dec 2, 2025
CVE-2025-59694
6.8 MEDIUM

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to persistently …

Dec 2, 2025
CVE-2025-13876
5.3 MEDIUM

A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the component …

Dec 2, 2025
CVE-2025-13875
6.3 MEDIUM

A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/main/java/com/yohann/ocihelper/service/impl/OciServiceImpl.java of the component OCI …

Dec 2, 2025
CVE-2025-13505
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability …

Dec 2, 2025
CVE-2025-41086
6.5 MEDIUM

Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage restrictions. The validator …

Dec 2, 2025
CVE-2025-41066
5.3 MEDIUM

Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on the system. To exploit …

Dec 2, 2025
CVE-2025-13731
6.4 MEDIUM

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nxt-year' shortcode in all versions up …

Dec 2, 2025
CVE-2025-41012
5.3 MEDIUM

Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by …

Dec 2, 2025
CVE-2025-40700
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScript code in the victim's browser when a malicious URL …

Dec 2, 2025
CVE-2025-13090
4.9 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 1.4.6 due …

Dec 2, 2025
CVE-2025-41743
4.0 MEDIUM

Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited …

Dec 2, 2025
CVE-2025-13353
5.5 MEDIUM

In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and the AES-GCM …

Dec 2, 2025
CVE-2025-13873
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which …

Dec 2, 2025
CVE-2025-13534
6.3 MEDIUM

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This …

Dec 2, 2025
CVE-2025-10543
5.3 MEDIUM

In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds …

Dec 2, 2025
CVE-2025-13696
5.3 MEDIUM

The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin exposing …

Dec 2, 2025
CVE-2025-11726
4.3 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is …

Dec 2, 2025
CVE-2025-13685
4.3 MEDIUM

The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due …

Dec 2, 2025
CVE-2025-13140
4.3 MEDIUM

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. …

Dec 2, 2025
CVE-2025-13007
6.1 MEDIUM

The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up …

Dec 2, 2025
CVE-2025-12483
6.5 MEDIUM

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'query' parameter in all versions up to, …

Dec 2, 2025
CVE-2025-13001
4.1 MEDIUM

The donation WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users, such …

Dec 2, 2025
CVE-2025-13606
6.5 MEDIUM

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Dec 2, 2025
CVE-2025-20792
5.3 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20791
6.5 MEDIUM

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20790
5.3 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Dec 2, 2025
CVE-2025-20789
4.4 MEDIUM

In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with no additional …

Dec 2, 2025
CVE-2025-20788
4.4 MEDIUM

In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of service with no …

Dec 2, 2025
CVE-2025-20777
6.7 MEDIUM

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Dec 2, 2025
CVE-2025-20776
6.7 MEDIUM

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if …

Dec 2, 2025
CVE-2025-20775
6.7 MEDIUM

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Dec 2, 2025
CVE-2025-20774
6.7 MEDIUM

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Dec 2, 2025
CVE-2025-20773
6.7 MEDIUM

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Dec 2, 2025
CVE-2025-20772
6.7 MEDIUM

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Dec 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.