CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43334
5.5 MEDIUM

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may …

Nov 4, 2025
CVE-2025-43322
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may …

Nov 4, 2025
CVE-2025-43288
5.5 MEDIUM

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able …

Nov 4, 2025
CVE-2025-46556
6.5 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely …

Nov 4, 2025
CVE-2025-35021
6.5 MEDIUM

By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth …

Nov 4, 2025
CVE-2025-36172
6.4 MEDIUM

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and …

Nov 3, 2025
CVE-2025-11193
5.5 MEDIUM

A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sensitive device specific …

Nov 3, 2025
CVE-2024-13998
6.5 MEDIUM

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should …

Nov 3, 2025
CVE-2021-47698
5.4 MEDIUM

Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient …

Nov 3, 2025
CVE-2025-63293
6.5 MEDIUM

FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets …

Nov 3, 2025
CVE-2025-12657
5.0 MEDIUM

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of …

Nov 3, 2025
CVE-2025-63593
6.1 MEDIUM

Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).

Nov 3, 2025
CVE-2025-8558
5.4 MEDIUM

Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent …

Nov 3, 2025
CVE-2025-50363
5.4 MEDIUM

Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.

Nov 3, 2025
CVE-2025-63450
5.4 MEDIUM

Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.

Nov 3, 2025
CVE-2025-63449
5.4 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.

Nov 3, 2025
CVE-2025-63448
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.

Nov 3, 2025
CVE-2025-63447
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.

Nov 3, 2025
CVE-2025-63446
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.

Nov 3, 2025
CVE-2025-36093
4.8 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in …

Nov 3, 2025
CVE-2025-36092
6.5 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper …

Nov 3, 2025
CVE-2025-36091
4.3 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due …

Nov 3, 2025
CVE-2025-63443
5.4 MEDIUM

School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.

Nov 3, 2025
CVE-2025-63442
4.6 MEDIUM

Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, …

Nov 3, 2025
CVE-2025-60892
6.8 MEDIUM

An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub …

Nov 3, 2025
CVE-2025-45663
6.5 MEDIUM

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

Nov 3, 2025
CVE-2025-29699
6.5 MEDIUM

NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

Nov 3, 2025
CVE-2024-51317
6.5 MEDIUM

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

Nov 3, 2025
CVE-2025-64294
5.3 MEDIUM

Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through …

Nov 3, 2025
CVE-2025-12626
4.3 MEDIUM

A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the …

Nov 3, 2025
CVE-2025-12503
6.5 MEDIUM

EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database …

Nov 3, 2025
CVE-2025-12615
5.0 MEDIUM

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of …

Nov 3, 2025
CVE-2025-12614
4.7 MEDIUM

A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of …

Nov 3, 2025
CVE-2025-12612
6.3 MEDIUM

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The …

Nov 3, 2025
CVE-2025-12610
4.7 MEDIUM

A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument …

Nov 3, 2025
CVE-2025-12609
4.7 MEDIUM

A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation …

Nov 3, 2025
CVE-2025-12598
4.7 MEDIUM

A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. …

Nov 2, 2025
CVE-2025-12597
4.7 MEDIUM

A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing …

Nov 2, 2025
CVE-2025-12594
4.7 MEDIUM

A security flaw has been discovered in code-projects Simple Online Hotel Reservation System 2.0. This affects an unknown function of the file /admin/add_account.php. The manipulation …

Nov 2, 2025
CVE-2025-12593
4.7 MEDIUM

A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the …

Nov 2, 2025
CVE-2025-6988
6.4 MEDIUM

The kallyas theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 4.23.0 …

Nov 1, 2025
CVE-2025-12137
4.9 MEDIUM

The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions …

Nov 1, 2025
CVE-2025-12180
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. This is due to the plugin …

Nov 1, 2025
CVE-2025-12090
6.4 MEDIUM

The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Social URLs in …

Nov 1, 2025
CVE-2025-12038
4.3 MEDIUM

The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the /wp-json/folderly/v1/config/clear-all-data REST API endpoint in …

Nov 1, 2025
CVE-2025-11983
4.3 MEDIUM

The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9. This is due to the plugin …

Nov 1, 2025
CVE-2025-11740
6.5 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to, and including, 2.4.9 due to …

Nov 1, 2025
CVE-2025-11502
6.4 MEDIUM

The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'saswp_tiny_multiple_faq' shortcode in all …

Nov 1, 2025
CVE-2025-12118
6.4 MEDIUM

The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions up to, and including, 1.6.1 due …

Nov 1, 2025
CVE-2025-11927
4.4 MEDIUM

The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in …

Nov 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.