CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60969
5.7 MEDIUM

Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.

Oct 6, 2025
CVE-2025-60961
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and …

Oct 6, 2025
CVE-2025-0038
6.6 MEDIUM

In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or …

Oct 6, 2025
CVE-2025-61765
6.4 MEDIUM

python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers …

Oct 6, 2025
CVE-2025-61224
6.5 MEDIUM

Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter

Oct 6, 2025
CVE-2025-61198
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Optimod 5950 - Optimod 5950HD - Optimod 5750 - Optimod 5750HD - Optimod Trio - Optimod version 1.0.0.33 …

Oct 6, 2025
CVE-2025-11337
5.3 MEDIUM

A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneReport/index.do/../../aloneReport/download.do;othersusrlogout.do. Performing manipulation of …

Oct 6, 2025
CVE-2025-11336
5.3 MEDIUM

A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown functionality of the …

Oct 6, 2025
CVE-2025-11335
4.7 MEDIUM

A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.htm?flag=qos of …

Oct 6, 2025
CVE-2025-11331
4.7 MEDIUM

A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the component Website Name …

Oct 6, 2025
CVE-2025-11330
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/sales-reports-detail.php. Such manipulation …

Oct 6, 2025
CVE-2025-0609
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Software Inc. Logo Cloud allows Cross-Site Scripting (XSS).This issue affects …

Oct 6, 2025
CVE-2025-0608
5.5 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forceful Browsing.This issue affects Logo Cloud: before 2025.R6.

Oct 6, 2025
CVE-2025-0607
4.3 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing.This issue affects Logo Cloud: before 2.57.

Oct 6, 2025
CVE-2025-0606
6.0 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing, Resource Leak Exposure.This issue affects Logo Cloud: before 0.67.

Oct 6, 2025
CVE-2025-9914
4.3 MEDIUM

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to …

Oct 6, 2025
CVE-2025-9913
4.5 MEDIUM

JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

Oct 6, 2025
CVE-2025-58591
6.5 MEDIUM

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive …

Oct 6, 2025
CVE-2025-58590
6.5 MEDIUM

It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.

Oct 6, 2025
CVE-2025-58587
6.5 MEDIUM

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to …

Oct 6, 2025
CVE-2025-58586
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Oct 6, 2025
CVE-2025-58585
5.3 MEDIUM

Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.

Oct 6, 2025
CVE-2025-58584
5.3 MEDIUM

In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such …

Oct 6, 2025
CVE-2025-58583
5.3 MEDIUM

The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

Oct 6, 2025
CVE-2025-58582
5.3 MEDIUM

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated …

Oct 6, 2025
CVE-2025-58581
4.3 MEDIUM

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as …

Oct 6, 2025
CVE-2025-58580
6.5 MEDIUM

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated …

Oct 6, 2025
CVE-2025-58579
5.3 MEDIUM

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user …

Oct 6, 2025
CVE-2025-9710
6.3 MEDIUM

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality …

Oct 6, 2025
CVE-2025-9703
4.3 MEDIUM

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the …

Oct 6, 2025
CVE-2025-11321
4.3 MEDIUM

A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performing manipulation of the …

Oct 6, 2025
CVE-2025-11320
6.3 MEDIUM

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the …

Oct 6, 2025
CVE-2025-11319
6.3 MEDIUM

A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16e87b965024097. This issue affects some unknown processing of the file /delete.php. This manipulation of the …

Oct 6, 2025
CVE-2025-11306
4.3 MEDIUM

A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The …

Oct 5, 2025
CVE-2025-11304
6.3 MEDIUM

A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown functionality of the component API. Executing …

Oct 5, 2025
CVE-2025-11303
6.3 MEDIUM

A vulnerability was detected in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/mp. Performing a manipulation of the argument command results …

Oct 5, 2025
CVE-2025-11298
6.3 MEDIUM

A vulnerability was determined in Belkin F9K1015 1.00.10. Impacted is an unknown function of the file /goform/formSetWanStatic. Executing a manipulation of the argument m_wan_ipaddr can …

Oct 5, 2025
CVE-2025-11292
6.3 MEDIUM

A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetSitesurvey. Executing a manipulation of the argument wan_ipaddr …

Oct 5, 2025
CVE-2025-11291
4.3 MEDIUM

A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts an unknown function of the file /map.php of the component HTTP …

Oct 5, 2025
CVE-2025-11290
5.6 MEDIUM

A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the …

Oct 5, 2025
CVE-2025-8917
5.8 MEDIUM

A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw …

Oct 5, 2025
CVE-2025-11288
6.3 MEDIUM

A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET …

Oct 5, 2025
CVE-2025-11286
4.7 MEDIUM

A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controllers/serverController.ts of the component MCPRouter Service. This …

Oct 5, 2025
CVE-2025-11285
6.3 MEDIUM

A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverController.ts. The manipulation of …

Oct 5, 2025
CVE-2025-11281
5.0 MEDIUM

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course …

Oct 5, 2025
CVE-2025-11279
5.5 MEDIUM

A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing of the component Add Work Item Page. The …

Oct 5, 2025
CVE-2025-11278
4.3 MEDIUM

A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of the component AllMon2. The manipulation leads to …

Oct 5, 2025
CVE-2025-11277
5.3 MEDIUM

A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can …

Oct 5, 2025
CVE-2025-11275
5.3 MEDIUM

A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation …

Oct 5, 2025
CVE-2025-11273
6.3 MEDIUM

A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oauth/provider.ts. The manipulation of the argument URL …

Oct 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.