CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53413
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Nov 7, 2025
CVE-2025-53412
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-53411
4.9 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, …

Nov 7, 2025
CVE-2025-53410
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Nov 7, 2025
CVE-2025-53409
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Nov 7, 2025
CVE-2025-53408
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-52865
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-47207
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-12861
4.7 MEDIUM

A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the …

Nov 7, 2025
CVE-2025-12860
4.7 MEDIUM

A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results …

Nov 7, 2025
CVE-2025-12859
4.7 MEDIUM

A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_edit.php. The manipulation of the argument ids …

Nov 7, 2025
CVE-2025-12857
4.7 MEDIUM

A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/roombook.php. Such manipulation …

Nov 7, 2025
CVE-2025-12856
4.7 MEDIUM

A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/reservation.php. This manipulation of the argument …

Nov 7, 2025
CVE-2025-12855
4.7 MEDIUM

A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processing of the file /admin/newsletterdel.php. The manipulation of …

Nov 7, 2025
CVE-2025-12853
4.7 MEDIUM

A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the …

Nov 7, 2025
CVE-2025-46413
4.3 MEDIUM

Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. When WPS is enabled, PIN code and/or Wi-Fi password …

Nov 7, 2025
CVE-2025-10966
4.3 MEDIUM

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl …

Nov 7, 2025
CVE-2025-64339
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature is vulnerable to stored Cross-site Scripting (XSS),specifically …

Nov 7, 2025
CVE-2025-12527
4.3 MEDIUM

The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capability check on the 'yydev_notes_save_dashboard_data' function …

Nov 7, 2025
CVE-2025-12520
4.0 MEDIUM

The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2 …

Nov 7, 2025
CVE-2025-64336
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-site Scripting (XSS). …

Nov 7, 2025
CVE-2025-64329
5.5 MEDIUM

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the …

Nov 7, 2025
CVE-2025-4522
6.5 MEDIUM

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in …

Nov 7, 2025
CVE-2025-64323
5.3 MEDIUM

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access …

Nov 7, 2025
CVE-2025-64187
4.4 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML …

Nov 7, 2025
CVE-2025-52662
6.9 MEDIUM

A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under certain configurations. …

Nov 7, 2025
CVE-2025-12789
6.1 MEDIUM

A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter …

Nov 7, 2025
CVE-2025-64302
6.4 MEDIUM

Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing information disclosure or data manipulation.

Nov 6, 2025
CVE-2025-12636
6.5 MEDIUM

The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able …

Nov 6, 2025
CVE-2025-64179
5.3 MEDIUM

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in the /api/v1/usage-report/summary endpoint allows …

Nov 6, 2025
CVE-2025-64177
5.4 MEDIUM

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, there is a stored Cross-Site Scripting (XSS) vulnerability …

Nov 6, 2025
CVE-2025-64176
5.3 MEDIUM

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an attacker can upload any file they wish …

Nov 6, 2025
CVE-2025-11216
6.3 MEDIUM

Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perform domain spoofing via a crafted video file. …

Nov 6, 2025
CVE-2025-11215
4.3 MEDIUM

Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds memory read via …

Nov 6, 2025
CVE-2025-11213
6.3 MEDIUM

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI …

Nov 6, 2025
CVE-2025-11212
6.3 MEDIUM

Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI …

Nov 6, 2025
CVE-2025-11210
5.4 MEDIUM

Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Nov 6, 2025
CVE-2025-11208
6.3 MEDIUM

Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Nov 6, 2025
CVE-2025-11207
6.5 MEDIUM

Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium …

Nov 6, 2025
CVE-2025-64327
5.3 MEDIUM

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contain a Blind Server-Side Request Forgery (SSRF) vulnerability, in …

Nov 6, 2025
CVE-2025-64174
4.8 MEDIUM

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that …

Nov 6, 2025
CVE-2025-33110
5.4 MEDIUM

IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Nov 6, 2025
CVE-2025-34247
6.5 MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable …

Nov 6, 2025
CVE-2025-34246
6.5 MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable …

Nov 6, 2025
CVE-2025-34245
6.5 MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable …

Nov 6, 2025
CVE-2025-34244
6.5 MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable …

Nov 6, 2025
CVE-2025-34243
6.5 MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable …

Nov 6, 2025
CVE-2025-34242
6.5 MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable …

Nov 6, 2025
CVE-2025-34241
6.5 MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable …

Nov 6, 2025
CVE-2025-34240
6.5 MEDIUM

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable …

Nov 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.