CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-65408
6.5 MEDIUM

A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a …

Dec 1, 2025
CVE-2025-65406
6.5 MEDIUM

A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Dec 1, 2025
CVE-2025-65405
6.5 MEDIUM

A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC …

Dec 1, 2025
CVE-2025-65404
6.5 MEDIUM

A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 …

Dec 1, 2025
CVE-2025-65403
6.5 MEDIUM

A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Dec 1, 2025
CVE-2025-63095
6.5 MEDIUM

Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Dec 1, 2025
CVE-2024-48894
5.9 MEDIUM

A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to a disclosure …

Dec 1, 2025
CVE-2024-32388
5.3 MEDIUM

Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the …

Dec 1, 2025
CVE-2024-32384
6.8 MEDIUM

Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows …

Dec 1, 2025
CVE-2025-64030
5.4 MEDIUM

Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter …

Dec 1, 2025
CVE-2025-63529
6.1 MEDIUM

A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier …

Dec 1, 2025
CVE-2025-63523
6.5 MEDIUM

FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the …

Dec 1, 2025
CVE-2025-63522
4.6 MEDIUM

Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function

Dec 1, 2025
CVE-2025-63520
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).

Dec 1, 2025
CVE-2025-13129
4.3 MEDIUM

Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contracting and Industry Ltd. Co. Onaylarım allows Functionality Misuse.This issue affects Onaylarım: …

Dec 1, 2025
CVE-2025-49643
6.5 MEDIUM

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to …

Dec 1, 2025
CVE-2025-27232
4.9 MEDIUM

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

Dec 1, 2025
CVE-2025-58408
5.9 MEDIUM

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel …

Dec 1, 2025
CVE-2025-13296
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Forgery.This issue affects T-Soft E-Commerce: through 28112025.

Dec 1, 2025
CVE-2025-8045
4.0 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user …

Dec 1, 2025
CVE-2025-6349
5.1 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user …

Dec 1, 2025
CVE-2025-2879
5.1 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver …

Dec 1, 2025
CVE-2025-41739
5.9 MEDIUM

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux …

Dec 1, 2025
CVE-2025-13819
6.1 MEDIUM

Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to arbitrary external websites via …

Dec 1, 2025
CVE-2025-13816
6.3 MEDIUM

A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile …

Dec 1, 2025
CVE-2025-13815
6.3 MEDIUM

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This …

Dec 1, 2025
CVE-2025-13813
5.6 MEDIUM

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component …

Dec 1, 2025
CVE-2025-13811
6.3 MEDIUM

A vulnerability was determined in jsnjfz WebStack-Guns 1.0. This vulnerability affects unknown code of the file src/main/java/com/jsnjfz/manage/core/common/constant/factory/PageFactory.java. Executing a manipulation of the argument sort can …

Dec 1, 2025
CVE-2025-13810
5.3 MEDIUM

A vulnerability was found in jsnjfz WebStack-Guns 1.0. This affects the function renderPicture of the file src/main/java/com/jsnjfz/manage/modular/system/controller/KaptchaController.java. Performing a manipulation results in path traversal. It …

Dec 1, 2025
CVE-2025-13809
6.3 MEDIUM

A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this issue is some unknown functionality of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineInfoController.java of the …

Dec 1, 2025
CVE-2025-13807
4.3 MEDIUM

A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineKeyController.java of the component API. The manipulation …

Dec 1, 2025
CVE-2025-13804
4.3 MEDIUM

A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the …

Dec 1, 2025
CVE-2025-13802
4.3 MEDIUM

A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted is an unknown function of the component Make a Reservation. This manipulation of the …

Dec 1, 2025
CVE-2025-13800
6.3 MEDIUM

A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The manipulation of the argument mac results …

Dec 1, 2025
CVE-2025-13799
6.3 MEDIUM

A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.cgi. The manipulation of the argument mac …

Dec 1, 2025
CVE-2025-13798
6.3 MEDIUM

A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulation of the argument mac can …

Dec 1, 2025
CVE-2025-13797
6.3 MEDIUM

A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cgi. Performing manipulation of the argument …

Dec 1, 2025
CVE-2025-13796
6.3 MEDIUM

A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of …

Dec 1, 2025
CVE-2025-13793
4.3 MEDIUM

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the …

Nov 30, 2025
CVE-2025-13791
6.3 MEDIUM

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation …

Nov 30, 2025
CVE-2025-13790
4.3 MEDIUM

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated …

Nov 30, 2025
CVE-2025-13789
6.3 MEDIUM

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results …

Nov 30, 2025
CVE-2025-13787
5.4 MEDIUM

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File …

Nov 30, 2025
CVE-2025-13785
4.3 MEDIUM

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile …

Nov 30, 2025
CVE-2025-13783
6.3 MEDIUM

A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/CommentadminController.class.php of the component CommentadminController. …

Nov 30, 2025
CVE-2025-66433
4.2 MEDIUM

HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed …

Nov 30, 2025
CVE-2025-66432
5.0 MEDIUM

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

Nov 30, 2025
CVE-2025-66424
6.5 MEDIUM

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Nov 30, 2025
CVE-2025-66422
4.3 MEDIUM

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Nov 30, 2025
CVE-2025-66421
5.4 MEDIUM

Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.69.

Nov 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.