CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13507
6.5 MEDIUM

Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process …

Nov 25, 2025
CVE-2025-12893
4.2 MEDIUM

Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Extended Key Usage (EKU) …

Nov 25, 2025
CVE-2025-10646
4.3 MEDIUM

The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capability check on the Base::get_rest_permission() method in all …

Nov 25, 2025
CVE-2025-64506
6.1 MEDIUM

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to …

Nov 25, 2025
CVE-2025-64505
6.1 MEDIUM

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to version 1.6.51, …

Nov 25, 2025
CVE-2025-10144
6.5 MEDIUM

The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attribute of the `products` shortcode in all versions …

Nov 24, 2025
CVE-2025-63674
6.8 MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

Nov 24, 2025
CVE-2025-54341
5.3 MEDIUM

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.

Nov 24, 2025
CVE-2025-63498
6.1 MEDIUM

alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

Nov 24, 2025
CVE-2025-48511
5.5 MEDIUM

Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of …

Nov 24, 2025
CVE-2025-36150
5.9 MEDIUM

IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Nov 24, 2025
CVE-2025-29933
5.5 MEDIUM

Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service

Nov 24, 2025
CVE-2025-0007
5.7 MEDIUM

Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user space to kernel space, potentially compromising confidentiality, integrity, …

Nov 24, 2025
CVE-2025-64048
6.1 MEDIUM

YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the …

Nov 24, 2025
CVE-2025-64047
6.1 MEDIUM

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.

Nov 24, 2025
CVE-2025-63914
6.5 MEDIUM

An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although …

Nov 24, 2025
CVE-2025-36112
5.3 MEDIUM

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information …

Nov 24, 2025
CVE-2025-63953
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Nov 24, 2025
CVE-2025-63952
5.7 MEDIUM

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Nov 24, 2025
CVE-2025-63435
4.3 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not …

Nov 24, 2025
CVE-2025-63433
4.6 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a …

Nov 24, 2025
CVE-2025-63432
4.6 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update …

Nov 24, 2025
CVE-2025-60917
4.6 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the …

Nov 24, 2025
CVE-2025-60916
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the …

Nov 24, 2025
CVE-2025-60914
4.6 MEDIUM

Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo …

Nov 24, 2025
CVE-2025-60633
6.5 MEDIUM

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.

Nov 24, 2025
CVE-2025-60632
6.5 MEDIUM

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl …

Nov 24, 2025
CVE-2025-56423
5.3 MEDIUM

An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error …

Nov 24, 2025
CVE-2025-12978
5.4 MEDIUM

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows …

Nov 24, 2025
CVE-2025-12972
5.3 MEDIUM

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted …

Nov 24, 2025
CVE-2025-12969
6.5 MEDIUM

Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to …

Nov 24, 2025
CVE-2025-65503
5.5 MEDIUM

Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that …

Nov 24, 2025
CVE-2025-65502
4.3 MEDIUM

Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns …

Nov 24, 2025
CVE-2025-65501
4.3 MEDIUM

Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() returns …

Nov 24, 2025
CVE-2025-65500
4.3 MEDIUM

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-65499
4.3 MEDIUM

Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-65498
4.3 MEDIUM

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-65497
4.3 MEDIUM

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-65496
4.3 MEDIUM

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-12628
6.3 MEDIUM

The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing …

Nov 24, 2025
CVE-2025-13588
6.3 MEDIUM

A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown function of the file public/proxy.php. Performing …

Nov 24, 2025
CVE-2025-13586
4.7 MEDIUM

A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file /Admin/changepassword.php. This manipulation of the …

Nov 24, 2025
CVE-2025-12569
4.7 MEDIUM

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, …

Nov 24, 2025
CVE-2025-12394
5.9 MEDIUM

The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log …

Nov 24, 2025
CVE-2025-13581
6.3 MEDIUM

A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of …

Nov 24, 2025
CVE-2025-13580
6.3 MEDIUM

A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.php. This manipulation of the argument ID causes …

Nov 24, 2025
CVE-2025-13579
6.3 MEDIUM

A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php. The manipulation of the argument ID results …

Nov 24, 2025
CVE-2025-13576
6.3 MEDIUM

A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulation results in improper …

Nov 24, 2025
CVE-2025-13575
6.3 MEDIUM

A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/blog.php of the component Category Handler. …

Nov 24, 2025
CVE-2025-13574
4.7 MEDIUM

A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the …

Nov 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.