CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-56801
5.1 MEDIUM

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application …

Oct 21, 2025
CVE-2025-56800
5.1 MEDIUM

Reolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen password logic entirely on the client side using …

Oct 21, 2025
CVE-2025-56799
6.5 MEDIUM

Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the …

Oct 21, 2025
CVE-2025-8050
6.5 MEDIUM

External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to access files hosted on …

Oct 21, 2025
CVE-2025-60790
6.5 MEDIUM

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, …

Oct 21, 2025
CVE-2025-60427
6.5 MEDIUM

LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can access analytics data via the Web …

Oct 21, 2025
CVE-2025-12031
5.3 MEDIUM

HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: …

Oct 21, 2025
CVE-2025-62763
5.0 MEDIUM

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

Oct 21, 2025
CVE-2025-62605
4.3 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon version 4.4, support for verifiable quote posts with quote controls was added, …

Oct 21, 2025
CVE-2025-62598
6.1 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) …

Oct 21, 2025
CVE-2025-62597
6.1 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) …

Oct 21, 2025
CVE-2025-62595
4.3 MEDIUM

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 …

Oct 21, 2025
CVE-2025-60511
4.3 MEDIUM

Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in …

Oct 21, 2025
CVE-2025-60506
5.4 MEDIUM

Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An attacker with a low-privileged account (e.g., Student) …

Oct 21, 2025
CVE-2025-62250
6.5 MEDIUM

Improper Authentication in Liferay Portal 7.4.0 through 7.4.3.132, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 …

Oct 21, 2025
CVE-2025-61194
6.5 MEDIUM

daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.

Oct 21, 2025
CVE-2025-61181
6.5 MEDIUM

daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.

Oct 21, 2025
CVE-2025-60280
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Bang Resto v1.0 could allow an attacker to inject malicious JavaScript code into the application's web pages. This vulnerability exists …

Oct 21, 2025
CVE-2025-60934
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or …

Oct 21, 2025
CVE-2025-60933
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts …

Oct 21, 2025
CVE-2025-60932
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts …

Oct 21, 2025
CVE-2025-59438
5.3 MEDIUM

Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.

Oct 21, 2025
CVE-2025-57521
6.1 MEDIUM

Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without …

Oct 21, 2025
CVE-2025-56450
6.5 MEDIUM

Log2Space Subscriber Management Software 1.1 is vulnerable to unauthenticated SQL injection via the `lead_id` parameter in the `/l2s/api/selfcareLeadHistory` endpoint. A remote attacker can exploit this …

Oct 21, 2025
CVE-2020-36855
5.3 MEDIUM

A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of …

Oct 21, 2025
CVE-2025-6239
6.5 MEDIUM

Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

Oct 21, 2025
CVE-2025-7473
5.2 MEDIUM

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

Oct 21, 2025
CVE-2025-10612
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in giSoft Information Technologies City Guide allows Reflected XSS.This issue affects City …

Oct 21, 2025
CVE-2025-26392
5.4 MEDIUM

SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege …

Oct 21, 2025
CVE-2025-54764
6.2 MEDIUM

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.

Oct 20, 2025
CVE-2025-12001
6.1 MEDIUM

Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 20, 2025
CVE-2025-11536
5.0 MEDIUM

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via …

Oct 20, 2025
CVE-2025-60783
6.5 MEDIUM

There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerability allows attackers to manipulate the application's database through …

Oct 20, 2025
CVE-2025-60781
6.1 MEDIUM

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_name parameter.

Oct 20, 2025
CVE-2025-8051
6.5 MEDIUM

Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue …

Oct 20, 2025
CVE-2025-8048
6.5 MEDIUM

External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to submit a stored local …

Oct 20, 2025
CVE-2025-62528
5.4 MEDIUM

Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for a project …

Oct 20, 2025
CVE-2025-5517
6.8 MEDIUM

Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (MID/ CE) -Terra AC MID, ABB …

Oct 20, 2025
CVE-2025-11979
5.3 MEDIUM

An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being …

Oct 20, 2025
CVE-2025-6515
6.8 MEDIUM

The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographically secure. This allows network attackers …

Oct 20, 2025
CVE-2025-60856
6.8 MEDIUM

Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attacker with physical access can connect to the exposed interface …

Oct 20, 2025
CVE-2025-48025
4.3 MEDIUM

In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000, there is an improper access control …

Oct 20, 2025
CVE-2025-40005
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle unbind during busy driver support indirect read and indirect …

Oct 20, 2025
CVE-2025-8884
5.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers.This issue affects ACE Center: …

Oct 20, 2025
CVE-2025-61456
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoint. Unsanitized input in the /index parameter is directly reflected back …

Oct 20, 2025
CVE-2025-61454
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoint. Unsanitized input in the /search parameter is directly reflected back …

Oct 20, 2025
CVE-2025-57839
4.0 MEDIUM

Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Oct 20, 2025
CVE-2025-57838
4.0 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Oct 20, 2025
CVE-2025-11947
4.5 MEDIUM

A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. …

Oct 19, 2025
CVE-2025-11944
4.7 MEDIUM

A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the component Raw SQL Handler. …

Oct 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.