CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11842
6.3 MEDIUM

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handler. The …

Oct 16, 2025
CVE-2025-61540
6.5 MEDIUM

SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.

Oct 16, 2025
CVE-2025-61539
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.

Oct 16, 2025
CVE-2025-41254
4.3 MEDIUM

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: …

Oct 16, 2025
CVE-2025-36002
5.5 MEDIUM

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files …

Oct 16, 2025
CVE-2025-53951
5.3 MEDIUM

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for Windows 11.5.1 and 11.4.2 …

Oct 16, 2025
CVE-2025-53950
5.5 MEDIUM

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 …

Oct 16, 2025
CVE-2025-46752
4.4 MEDIUM

A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the …

Oct 16, 2025
CVE-2025-9955
5.7 MEDIUM

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs …

Oct 16, 2025
CVE-2025-58426
4.3 MEDIUM

desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applications.

Oct 16, 2025
CVE-2025-58079
4.3 MEDIUM

Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.

Oct 16, 2025
CVE-2025-55072
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-54859
4.8 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-54760
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-52583
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-24833
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-58115
6.1 MEDIUM

ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be executed on the web browser of the user …

Oct 16, 2025
CVE-2025-54461
5.3 MEDIUM

ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited, an uninvited guest user may register itself as a …

Oct 16, 2025
CVE-2025-53858
5.4 MEDIUM

ChatLuck contains a cross-site scripting vulnerability in Chat Rooms. If exploited, an arbitrary script may be executed on the web browser of the user who …

Oct 16, 2025
CVE-2025-41410
5.4 MEDIUM

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create …

Oct 16, 2025
CVE-2025-0277
6.5 MEDIUM

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing …

Oct 16, 2025
CVE-2025-0276
6.5 MEDIUM

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick …

Oct 16, 2025
CVE-2025-55091
6.5 MEDIUM

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function …

Oct 16, 2025
CVE-2025-41443
4.3 MEDIUM

Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover …

Oct 16, 2025
CVE-2025-41021
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) in Sergestec's Exito v8.0, consisting of a stored XSS due to a lack of proper validation of user input by sending …

Oct 16, 2025
CVE-2025-55090
6.5 MEDIUM

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function …

Oct 16, 2025
CVE-2025-55084
5.3 MEDIUM

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.

Oct 16, 2025
CVE-2025-10849
5.3 MEDIUM

The Felan Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_plugin_actions' function called via …

Oct 16, 2025
CVE-2025-0275
5.3 MEDIUM

HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access …

Oct 16, 2025
CVE-2025-11814
6.4 MEDIUM

The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 3.21.1 (exclusive) due to insufficient input …

Oct 16, 2025
CVE-2025-0274
5.3 MEDIUM

HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, …

Oct 16, 2025
CVE-2025-10700
4.3 MEDIUM

The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This …

Oct 16, 2025
CVE-2025-11683
6.5 MEDIUM

YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds …

Oct 16, 2025
CVE-2025-43313
5.5 MEDIUM

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may …

Oct 15, 2025
CVE-2025-43282
5.5 MEDIUM

A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, …

Oct 15, 2025
CVE-2025-43280
4.7 MEDIUM

The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote …

Oct 15, 2025
CVE-2025-11568
4.4 MEDIUM

A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker with the necessary permissions …

Oct 15, 2025
CVE-2025-62378
6.1 MEDIUM

CommandKit is the discord.js meta-framework for building Discord bots. In versions 1.2.0-rc.1 through 1.2.0-rc.11, a logic flaw exists in the message command handler that affects …

Oct 15, 2025
CVE-2025-58133
5.3 MEDIUM

Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a disclosure of information via network access.

Oct 15, 2025
CVE-2025-58132
4.1 MEDIUM

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

Oct 15, 2025
CVE-2025-54271
5.6 MEDIUM

Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. …

Oct 15, 2025
CVE-2025-20360
5.8 MEDIUM

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the Snort …

Oct 15, 2025
CVE-2025-20359
6.5 MEDIUM

Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure …

Oct 15, 2025
CVE-2025-20351
6.1 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 running …

Oct 15, 2025
CVE-2025-20329
4.9 MEDIUM

A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive …

Oct 15, 2025
CVE-2025-61933
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of …

Oct 15, 2025
CVE-2025-53860
4.1 MEDIUM

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries …

Oct 15, 2025
CVE-2025-9548
5.5 MEDIUM

A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticated user to cause a Windows …

Oct 15, 2025
CVE-2025-56748
6.4 MEDIUM

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks …

Oct 15, 2025
CVE-2025-55083
5.3 MEDIUM

In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of …

Oct 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.