CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13783
6.3 MEDIUM

A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/CommentadminController.class.php of the component CommentadminController. …

Nov 30, 2025
CVE-2025-66433
4.2 MEDIUM

HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed …

Nov 30, 2025
CVE-2025-66432
5.0 MEDIUM

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

Nov 30, 2025
CVE-2025-66424
6.5 MEDIUM

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Nov 30, 2025
CVE-2025-66422
4.3 MEDIUM

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Nov 30, 2025
CVE-2025-66421
5.4 MEDIUM

Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.69.

Nov 30, 2025
CVE-2025-66420
5.4 MEDIUM

Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and 6.0.67.

Nov 30, 2025
CVE-2025-66291
4.3 MEDIUM

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files …

Nov 29, 2025
CVE-2025-66290
4.3 MEDIUM

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required …

Nov 29, 2025
CVE-2025-65892
6.1 MEDIUM

Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted …

Nov 29, 2025
CVE-2025-65540
6.1 MEDIUM

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are …

Nov 29, 2025
CVE-2025-66221
5.3 MEDIUM

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there …

Nov 29, 2025
CVE-2025-61915
6.0 MEDIUM

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group …

Nov 29, 2025
CVE-2025-58436
5.1 MEDIUM

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd …

Nov 29, 2025
CVE-2025-53939
6.3 MEDIUM

Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly …

Nov 29, 2025
CVE-2025-53900
6.5 MEDIUM

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could …

Nov 29, 2025
CVE-2025-53897
6.8 MEDIUM

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from …

Nov 29, 2025
CVE-2025-66036
6.1 MEDIUM

Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cross-site scripting (XSS) in the input …

Nov 29, 2025
CVE-2025-66034
6.3 MEDIUM

fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script …

Nov 29, 2025
CVE-2025-66027
6.5 MEDIUM

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through …

Nov 29, 2025
CVE-2025-65113
6.5 MEDIUM

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging system allows …

Nov 29, 2025
CVE-2025-64715
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference …

Nov 29, 2025
CVE-2025-13683
6.5 MEDIUM

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

Nov 28, 2025
CVE-2025-59792
5.3 MEDIUM

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade …

Nov 28, 2025
CVE-2025-59790
5.4 MEDIUM

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which …

Nov 28, 2025
CVE-2025-51736
6.3 MEDIUM

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-51734
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-51733
5.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-12143
6.1 MEDIUM

Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

Nov 28, 2025
CVE-2025-13771
6.5 MEDIUM

WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

Nov 28, 2025
CVE-2025-13770
6.5 MEDIUM

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Nov 28, 2025
CVE-2025-13769
6.5 MEDIUM

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Nov 28, 2025
CVE-2025-66386
4.1 MEDIUM

app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

Nov 28, 2025
CVE-2025-66371
5.0 MEDIUM

Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and …

Nov 28, 2025
CVE-2025-66370
5.0 MEDIUM

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the …

Nov 28, 2025
CVE-2025-64312
4.9 MEDIUM

Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58311
5.8 MEDIUM

UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58305
6.2 MEDIUM

Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58304
4.9 MEDIUM

Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-13737
4.3 MEDIUM

The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is …

Nov 28, 2025
CVE-2025-64315
4.4 MEDIUM

Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.

Nov 28, 2025
CVE-2025-64313
5.3 MEDIUM

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-64311
5.1 MEDIUM

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58315
5.5 MEDIUM

Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58314
6.6 MEDIUM

Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58312
5.1 MEDIUM

Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-58309
6.8 MEDIUM

Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58307
6.4 MEDIUM

UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-58294
6.2 MEDIUM

Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-66361
6.5 MEDIUM

An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.

Nov 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.