CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2011-10037
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web …

Oct 30, 2025
CVE-2011-10036
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2025-62265
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 …

Oct 30, 2025
CVE-2025-57109
6.5 MEDIUM

Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string …

Oct 30, 2025
CVE-2025-52180
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of …

Oct 30, 2025
CVE-2025-52179
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of …

Oct 30, 2025
CVE-2025-64116
6.1 MEDIUM

Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without …

Oct 30, 2025
CVE-2025-64115
6.1 MEDIUM

Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header …

Oct 30, 2025
CVE-2025-62266
6.1 MEDIUM

By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA …

Oct 30, 2025
CVE-2025-56313
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3.9.6 (inclusive). This allows remote attackers to execute arbitrary …

Oct 30, 2025
CVE-2025-63885
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in AIxBlock commit 04f305 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Oct 30, 2025
CVE-2025-60950
6.1 MEDIUM

An arbitrary file upload vulnerability in the Data Preparation function of AIxBlock commit f60975 allows attackers to execute arbitrary code via a crafted SVG file.

Oct 30, 2025
CVE-2025-60319
6.5 MEDIUM

PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java).

Oct 30, 2025
CVE-2025-46363
4.3 MEDIUM

Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative Path Traversal vulnerability in the SCG exposed for an …

Oct 30, 2025
CVE-2025-36592
5.4 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, version(s) 5.20. 5.22, 5.24, 5.26, 5.28, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') …

Oct 30, 2025
CVE-2025-12517
5.3 MEDIUM

Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Oct 30, 2025
CVE-2025-5347
6.3 MEDIUM

Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.

Oct 30, 2025
CVE-2025-5343
6.3 MEDIUM

Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.

Oct 30, 2025
CVE-2025-5342
4.3 MEDIUM

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

Oct 30, 2025
CVE-2025-50574
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in blog-details.php in Hiruna Gallage's Glamour Salon Management System v1 allows remote attackers to inject arbitrary web script or HTML via …

Oct 30, 2025
CVE-2025-50736
6.1 MEDIUM

An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external …

Oct 30, 2025
CVE-2025-63608
5.4 MEDIUM

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form …

Oct 30, 2025
CVE-2025-62503
4.6 MEDIUM

User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.

Oct 30, 2025
CVE-2025-62402
5.4 MEDIUM

API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag …

Oct 30, 2025
CVE-2025-54941
4.6 MEDIUM

An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. …

Oct 30, 2025
CVE-2025-54471
6.5 MEDIUM

NeuVector used a hard-coded cryptographic key embedded in the source code. At compilation time, the key value was replaced with the secret key value and …

Oct 30, 2025
CVE-2025-40090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list access Since commit 305853cce3794 ("ksmbd: Fix race …

Oct 30, 2025
CVE-2025-11906
6.7 MEDIUM

A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect file permissions, allowing a user with access to the …

Oct 30, 2025
CVE-2025-11881
5.3 MEDIUM

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'myappp_verify' …

Oct 30, 2025
CVE-2025-11627
6.5 MEDIUM

The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log file poisoning in all versions …

Oct 30, 2025
CVE-2025-10008
5.3 MEDIUM

The Translate WordPress and go Multilingual – Weglot plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Oct 30, 2025
CVE-2025-12475
6.4 MEDIUM

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blocksy_newsletter_subscribe' shortcode in all versions up to, and including, 2.1.14 …

Oct 30, 2025
CVE-2025-62257
5.3 MEDIUM

Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, …

Oct 30, 2025
CVE-2025-12083
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CivicTheme Design System allows Cross-Site Scripting (XSS).This issue affects CivicTheme Design System: …

Oct 30, 2025
CVE-2025-10930
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects Currency: from 0.0.0 before 3.5.0.

Oct 30, 2025
CVE-2025-10929
5.3 MEDIUM

Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2.

Oct 30, 2025
CVE-2025-10928
6.3 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.5.

Oct 30, 2025
CVE-2025-10927
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible tracking allows Cross-Site Scripting (XSS).This issue affects Plausible tracking: from 0.0.0 …

Oct 30, 2025
CVE-2025-10926
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field allows Cross-Site Scripting (XSS).This issue affects JSON Field: from 0.0.0 …

Oct 30, 2025
CVE-2025-61724
5.3 MEDIUM

The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can …

Oct 29, 2025
CVE-2025-58189
5.3 MEDIUM

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Oct 29, 2025
CVE-2025-58186
5.3 MEDIUM

Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a …

Oct 29, 2025
CVE-2025-58185
5.3 MEDIUM

Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.

Oct 29, 2025
CVE-2025-58183
4.3 MEDIUM

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive …

Oct 29, 2025
CVE-2025-54549
5.9 MEDIUM

Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

Oct 29, 2025
CVE-2025-54548
4.3 MEDIUM

On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)

Oct 29, 2025
CVE-2025-54547
5.3 MEDIUM

On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform …

Oct 29, 2025
CVE-2025-47912
5.3 MEDIUM

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits …

Oct 29, 2025
CVE-2025-61959
5.3 MEDIUM

Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, …

Oct 29, 2025
CVE-2025-60320
6.7 MEDIUM

memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (memoQauhlp101). The affected service is installed with a path …

Oct 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.