CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62242
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and …

Oct 13, 2025
CVE-2025-62241
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to …

Oct 13, 2025
CVE-2025-62243
5.4 MEDIUM

Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 …

Oct 13, 2025
CVE-2025-62244
4.3 MEDIUM

Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 …

Oct 13, 2025
CVE-2025-43991
6.3 MEDIUM

SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. …

Oct 13, 2025
CVE-2025-39965
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but …

Oct 13, 2025
CVE-2025-10720
6.5 MEDIUM

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only …

Oct 13, 2025
CVE-2025-11674
6.8 MEDIUM

SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe internal network information.

Oct 13, 2025
CVE-2025-11672
5.3 MEDIUM

Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain user group names.

Oct 13, 2025
CVE-2025-11671
5.3 MEDIUM

Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain information such as …

Oct 13, 2025
CVE-2025-11668
4.7 MEDIUM

A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/update_user.php. This manipulation of …

Oct 13, 2025
CVE-2025-11667
6.3 MEDIUM

A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_candidate_modal.php.. The manipulation of …

Oct 13, 2025
CVE-2025-27259
5.4 MEDIUM

Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites …

Oct 13, 2025
CVE-2025-11666
6.7 MEDIUM

A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware …

Oct 13, 2025
CVE-2025-11665
4.7 MEDIUM

A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation …

Oct 13, 2025
CVE-2025-11664
4.7 MEDIUM

A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element is an unknown function of the file /admin/search-appointment.php. …

Oct 13, 2025
CVE-2025-9698
6.8 MEDIUM

The Plus Addons for Elementor WordPress plugin before 6.3.16 does not sanitize SVG file contents, which could allow users with minimum role access as Author …

Oct 13, 2025
CVE-2025-11663
4.7 MEDIUM

A weakness has been identified in Campcodes Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/manage-services.php. This …

Oct 13, 2025
CVE-2025-31996
5.3 MEDIUM

HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive information such as private or system information …

Oct 13, 2025
CVE-2025-31994
4.3 MEDIUM

HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected …

Oct 13, 2025
CVE-2025-11655
4.7 MEDIUM

A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. …

Oct 13, 2025
CVE-2025-11648
5.6 MEDIUM

A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. Impacted is an unknown function of the file TF_FQDN.json of the component GATT …

Oct 12, 2025
CVE-2025-11646
6.3 MEDIUM

A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the component GATT Service. The manipulation results in …

Oct 12, 2025
CVE-2025-11642
4.0 MEDIUM

A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected is an unknown function of the component Registration Handler. Such manipulation leads to …

Oct 12, 2025
CVE-2025-11638
4.3 MEDIUM

A flaw has been found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Bluetooth Handler. Executing …

Oct 12, 2025
CVE-2025-11637
4.3 MEDIUM

A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component Audio Handler. Performing manipulation results in …

Oct 12, 2025
CVE-2025-11636
5.6 MEDIUM

A security vulnerability has been detected in Tomofun Furbo 360 up to FB0035_FW_036. This issue affects some unknown processing of the component Account Handler. Such …

Oct 12, 2025
CVE-2025-33096
6.5 MEDIUM

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted …

Oct 12, 2025
CVE-2025-2140
5.7 MEDIUM

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender …

Oct 12, 2025
CVE-2025-11635
4.3 MEDIUM

A weakness has been identified in Tomofun Furbo 360 up to FB0035_FW_036. This vulnerability affects unknown code of the component File Upload. This manipulation causes …

Oct 12, 2025
CVE-2025-31969
4.0 MEDIUM

HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources getting loaded and browsers may come across certain …

Oct 12, 2025
CVE-2025-11631
5.4 MEDIUM

A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of …

Oct 12, 2025
CVE-2025-11630
6.3 MEDIUM

A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing …

Oct 12, 2025
CVE-2025-11629
6.3 MEDIUM

A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql …

Oct 12, 2025
CVE-2025-31992
4.6 MEDIUM

HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of …

Oct 12, 2025
CVE-2025-52616
5.3 MEDIUM

HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the …

Oct 12, 2025
CVE-2025-11628
4.7 MEDIUM

A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory …

Oct 12, 2025
CVE-2025-31997
4.2 MEDIUM

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, …

Oct 12, 2025
CVE-2025-11613
6.3 MEDIUM

A vulnerability was found in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file /addcategory.php. The manipulation of the argument …

Oct 11, 2025
CVE-2025-11612
6.3 MEDIUM

A vulnerability has been found in code-projects Simple Food Ordering System 1.0. This impacts an unknown function of the file /addproduct.php. The manipulation of the …

Oct 11, 2025
CVE-2025-11611
6.3 MEDIUM

A weakness has been identified in SourceCodester Simple Inventory System 1.0. Impacted is an unknown function of the file /user.php. This manipulation of the argument …

Oct 11, 2025
CVE-2025-11610
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Simple Inventory System 1.0. This issue affects some unknown processing of the file /brand.php. The manipulation of …

Oct 11, 2025
CVE-2025-11607
6.3 MEDIUM

A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the component …

Oct 11, 2025
CVE-2025-11606
6.3 MEDIUM

A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The affected element is an unknown function of the component Search. …

Oct 11, 2025
CVE-2025-11605
6.3 MEDIUM

A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/update-profile.php. Such manipulation of the argument uid …

Oct 11, 2025
CVE-2025-11603
6.3 MEDIUM

A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /editproduct.php. The manipulation of the argument …

Oct 11, 2025
CVE-2025-11600
6.3 MEDIUM

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file editcategory.php. Such manipulation of …

Oct 11, 2025
CVE-2025-11597
6.3 MEDIUM

A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of the file /pages/product_add_qty.php. The manipulation of the argument …

Oct 11, 2025
CVE-2025-9975
6.8 MEDIUM

The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.8.1 via the wp_scraper_extract_content function. This …

Oct 11, 2025
CVE-2025-9950
4.9 MEDIUM

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwr_get_file …

Oct 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.