CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-41062
5.4 MEDIUM

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of …

Sep 4, 2025
CVE-2025-41061
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41060
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41059
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41058
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41057
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41056
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41055
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41054
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41053
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41052
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41051
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41050
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41049
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41048
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41047
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41046
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41045
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41044
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41043
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41042
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41041
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41040
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41039
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41038
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41037
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41036
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41035
6.5 MEDIUM

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions …

Sep 4, 2025
CVE-2022-39888
4.3 MEDIUM

Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.

Sep 4, 2025
CVE-2025-9942
6.3 MEDIUM

A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulation leads to …

Sep 4, 2025
CVE-2025-9941
6.3 MEDIUM

A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the …

Sep 4, 2025
CVE-2025-9937
5.4 MEDIUM

A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulation results in improper authorization. …

Sep 4, 2025
CVE-2025-9936
4.3 MEDIUM

A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The …

Sep 4, 2025
CVE-2025-9934
6.3 MEDIUM

A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in …

Sep 4, 2025
CVE-2025-9931
4.3 MEDIUM

A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation …

Sep 4, 2025
CVE-2025-9616
5.3 MEDIUM

The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or …

Sep 4, 2025
CVE-2025-9516
4.9 MEDIUM

The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This …

Sep 4, 2025
CVE-2025-36909
5.3 MEDIUM

Information disclosure

Sep 4, 2025
CVE-2025-36908
6.7 MEDIUM

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36902
6.7 MEDIUM

In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36900
6.7 MEDIUM

In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalation of privilege with System …

Sep 4, 2025
CVE-2025-36893
5.5 MEDIUM

In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution …

Sep 4, 2025
CVE-2024-56189
6.5 MEDIUM

In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Sep 4, 2025
CVE-2024-13073
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft TaskPano allows Cross-Site Scripting (XSS).This issue affects TaskPano: s1.06.04.

Sep 4, 2025
CVE-2024-13071
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-Mutabakat allows Cross-Site Scripting (XSS).This issue affects e-Mutabakat: from 2.02.05 …

Sep 4, 2025
CVE-2025-8268
6.5 MEDIUM

The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and …

Sep 3, 2025
CVE-2025-56139
5.3 MEDIUM

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a …

Sep 3, 2025
CVE-2025-55162
6.3 MEDIUM

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1.33.6, …

Sep 3, 2025
CVE-2025-9923
4.3 MEDIUM

A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. Executing manipulation of the …

Sep 3, 2025
CVE-2025-20336
5.3 MEDIUM

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Sep 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.