CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54967
6.5 MEDIUM

An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An attacker who is able to social …

Oct 27, 2025
CVE-2025-12299
4.3 MEDIUM

A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /addproduct.php. The manipulation of …

Oct 27, 2025
CVE-2025-12298
4.3 MEDIUM

A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the file /editcategory.php. The manipulation of the argument …

Oct 27, 2025
CVE-2025-12297
4.3 MEDIUM

A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. …

Oct 27, 2025
CVE-2025-12296
4.7 MEDIUM

A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Update Handler. The manipulation …

Oct 27, 2025
CVE-2025-12295
6.6 MEDIUM

A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the component Firmware Update Handler. Executing manipulation can …

Oct 27, 2025
CVE-2025-60791
6.2 MEDIUM

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory after a …

Oct 27, 2025
CVE-2025-12294
4.7 MEDIUM

A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /delete_category.php. Performing manipulation of the …

Oct 27, 2025
CVE-2025-12291
4.7 MEDIUM

A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file /admin/index.php?add_product of the …

Oct 27, 2025
CVE-2025-10023
6.2 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules) allows Stored XSS by users …

Oct 27, 2025
CVE-2023-37749
5.3 MEDIUM

Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.

Oct 27, 2025
CVE-2025-36121
5.4 MEDIUM

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed …

Oct 27, 2025
CVE-2025-12351
6.8 MEDIUM

Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to …

Oct 27, 2025
CVE-2025-12290
4.3 MEDIUM

A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality …

Oct 27, 2025
CVE-2025-12289
4.3 MEDIUM

A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality …

Oct 27, 2025
CVE-2025-12288
4.3 MEDIUM

A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User …

Oct 27, 2025
CVE-2025-12287
4.7 MEDIUM

A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the …

Oct 27, 2025
CVE-2025-50055
6.4 MEDIUM

Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) …

Oct 27, 2025
CVE-2025-12283
4.3 MEDIUM

A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results in authorization bypass. …

Oct 27, 2025
CVE-2025-41384
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include …

Oct 27, 2025
CVE-2025-12276
4.3 MEDIUM

A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation results …

Oct 27, 2025
CVE-2025-12270
4.3 MEDIUM

A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file /api/v1/assignments/{assignment_id}/tasks/{task_id}/sub_file of the component Student Assignment …

Oct 27, 2025
CVE-2025-12268
6.3 MEDIUM

A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/courses/ of the component Course Thumbnail Handler. …

Oct 27, 2025
CVE-2025-59463
4.3 MEDIUM

An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.

Oct 27, 2025
CVE-2025-59462
6.5 MEDIUM

An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.

Oct 27, 2025
CVE-2025-59459
5.5 MEDIUM

An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.

Oct 27, 2025
CVE-2025-12267
4.3 MEDIUM

A flaw has been found in abhicodebox ModernShop 20250922. This issue affects some unknown processing of the file /search. Executing manipulation of the argument q …

Oct 27, 2025
CVE-2025-12266
6.3 MEDIUM

A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the function _empty of the file /index.php/auth/widget. …

Oct 27, 2025
CVE-2025-12263
6.3 MEDIUM

A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /edit_judge.php. The manipulation of the argument …

Oct 27, 2025
CVE-2025-12262
6.3 MEDIUM

A vulnerability was determined in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /edit_criteria.php. Executing manipulation of the argument …

Oct 27, 2025
CVE-2025-46583
5.3 MEDIUM

There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service …

Oct 27, 2025
CVE-2025-12261
6.3 MEDIUM

A vulnerability was found in CodeAstro Gym Management System 1.0. This affects an unknown function of the file /admin/actions/remove-announcement.php. Performing a manipulation of the argument …

Oct 27, 2025
CVE-2025-12256
6.3 MEDIUM

A weakness has been identified in code-projects Online Event Judging System 1.0. This vulnerability affects unknown code of the file /edit_contestant.php. Executing manipulation of the …

Oct 27, 2025
CVE-2025-12255
6.3 MEDIUM

A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown part of the file /add_contestant.php. Performing manipulation of …

Oct 27, 2025
CVE-2025-12254
6.3 MEDIUM

A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected by this issue is some unknown functionality of the file /add_judge.php. Such manipulation …

Oct 27, 2025
CVE-2025-12252
6.3 MEDIUM

A vulnerability was found in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /ajax/action.php. The manipulation of the argument …

Oct 27, 2025
CVE-2025-12250
4.7 MEDIUM

A flaw has been found in OpenWGA 7.11.12 Build 737. This affects an unknown function of the file WGA.File of the component TMLScript API. Executing …

Oct 27, 2025
CVE-2025-12249
6.3 MEDIUM

A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. The impacted element is an unknown function of the component Edit Ticket Page. Performing …

Oct 27, 2025
CVE-2025-12246
4.3 MEDIUM

A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/IframeLoader.vue of the component Admin …

Oct 27, 2025
CVE-2025-12245
5.3 MEDIUM

A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation …

Oct 27, 2025
CVE-2025-12244
4.3 MEDIUM

A vulnerability was determined in code-projects Simple E-Banking System 1.0. This affects an unknown part of the file /eBank/register.php. Executing manipulation of the argument Username …

Oct 27, 2025
CVE-2025-12243
6.3 MEDIUM

A vulnerability was found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the file clientdetails/welcome.php of the component …

Oct 27, 2025
CVE-2025-12242
6.3 MEDIUM

A vulnerability has been found in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/actions/check-attendance.php. Such manipulation …

Oct 27, 2025
CVE-2025-12238
6.3 MEDIUM

A security flaw has been discovered in code-projects Automated Voting System 1.0. The affected element is an unknown function of the file /admin/user.php. Performing manipulation …

Oct 27, 2025
CVE-2025-11154
5.4 MEDIUM

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary …

Oct 27, 2025
CVE-2025-12226
4.7 MEDIUM

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house of the file /admin_class.php. Performing manipulation of the …

Oct 27, 2025
CVE-2025-12223
6.3 MEDIUM

A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the component Package …

Oct 27, 2025
CVE-2025-12222
6.3 MEDIUM

A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some unknown functionality of the file …

Oct 27, 2025
CVE-2025-58918
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Waituk Entrada theme allows Cross Site Request Forgery.This issue affects Entrada: from n/a through 5.7.7.

Oct 27, 2025
CVE-2025-48088
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Stored XSS.This issue affects …

Oct 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.