CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-61911
6.5 MEDIUM

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to …

Oct 10, 2025
CVE-2025-11589
6.3 MEDIUM

A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/user-payment.php. Performing a manipulation of …

Oct 10, 2025
CVE-2025-11588
6.3 MEDIUM

A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /customer/index.php. Such manipulation of the argument fullname …

Oct 10, 2025
CVE-2025-62245
4.3 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update …

Oct 10, 2025
CVE-2025-62158
5.3 MEDIUM

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by …

Oct 10, 2025
CVE-2025-61925
6.5 MEDIUM

Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any validation. It is …

Oct 10, 2025
CVE-2025-61505
6.5 MEDIUM

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` …

Oct 10, 2025
CVE-2025-11581
5.3 MEDIUM

A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such …

Oct 10, 2025
CVE-2025-60838
6.5 MEDIUM

An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

Oct 10, 2025
CVE-2025-60268
6.5 MEDIUM

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An …

Oct 10, 2025
CVE-2025-11618
4.3 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect …

Oct 10, 2025
CVE-2025-11617
5.4 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths …

Oct 10, 2025
CVE-2025-11616
5.4 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which …

Oct 10, 2025
CVE-2025-11580
5.3 MEDIUM

A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The …

Oct 10, 2025
CVE-2025-61780
5.8 MEDIUM

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running …

Oct 10, 2025
CVE-2025-60308
4.1 MEDIUM

code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room function of the online hotel reservation system. …

Oct 10, 2025
CVE-2025-8887
6.1 MEDIUM

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Forceful …

Oct 10, 2025
CVE-2025-8886
6.7 MEDIUM

Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect Authorization vulnerability in Usta Information Systems Inc. Aybs …

Oct 10, 2025
CVE-2025-61319
6.1 MEDIUM

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the …

Oct 10, 2025
CVE-2025-61152
6.5 MEDIUM

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged …

Oct 10, 2025
CVE-2025-60868
6.5 MEDIUM

The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded …

Oct 10, 2025
CVE-2025-62239
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 …

Oct 10, 2025
CVE-2025-62238
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 …

Oct 10, 2025
CVE-2025-62237
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, …

Oct 10, 2025
CVE-2025-7781
6.4 MEDIUM

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘cs_job_title’ parameter in all versions up …

Oct 10, 2025
CVE-2025-7374
5.4 MEDIUM

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This …

Oct 10, 2025
CVE-2025-11579
5.3 MEDIUM

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR …

Oct 10, 2025
CVE-2025-52624
5.4 MEDIUM

A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk …

Oct 10, 2025
CVE-2025-11190
5.4 MEDIUM

The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.

Oct 10, 2025
CVE-2025-52632
6.5 MEDIUM

A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-37727
5.7 MEDIUM

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API …

Oct 10, 2025
CVE-2025-40640
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of …

Oct 10, 2025
CVE-2025-62292
4.3 MEDIUM

In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, …

Oct 10, 2025
CVE-2025-21070
4.0 MEDIUM

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-21069
4.0 MEDIUM

Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21068
4.0 MEDIUM

Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21067
4.0 MEDIUM

Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21066
4.0 MEDIUM

Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21065
6.6 MEDIUM

Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

Oct 10, 2025
CVE-2025-21063
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording …

Oct 10, 2025
CVE-2025-21060
5.5 MEDIUM

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required …

Oct 10, 2025
CVE-2025-21059
6.2 MEDIUM

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

Oct 10, 2025
CVE-2025-21057
4.0 MEDIUM

Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

Oct 10, 2025
CVE-2025-21055
4.3 MEDIUM

Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21054
4.0 MEDIUM

Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21053
4.0 MEDIUM

Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

Oct 10, 2025
CVE-2025-21052
4.0 MEDIUM

Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory …

Oct 10, 2025
CVE-2025-21051
4.0 MEDIUM

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-21049
5.5 MEDIUM

Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this …

Oct 10, 2025
CVE-2025-21048
6.7 MEDIUM

Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.

Oct 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.