CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0640
4.7 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure.This issue affects OctoCloud: from s1.09.02 before v1.11.01.

Sep 2, 2025
CVE-2024-12973
4.7 MEDIUM

Origin Validation Error vulnerability in Akinsoft OctoCloud allows HTTP Response Splitting, CAPEC - 87 - Forceful Browsing.This issue affects OctoCloud: from s1.09.01 before v1.11.01.

Sep 2, 2025
CVE-2024-12972
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft OctoCloud allows Cross-Site Scripting (XSS).This issue affects OctoCloud: from s1.09.01 …

Sep 2, 2025
CVE-2025-44017
4.3 MEDIUM

"Gunosy" App contains a vulnerability where sensitive information may be included in the application's outbound communication. If a user accesses a crafted URL, an attacker …

Sep 2, 2025
CVE-2025-8662
4.3 MEDIUM

OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue affects OpenAM: …

Sep 2, 2025
CVE-2025-9805
6.3 MEDIUM

A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unknown processing of the file apps/sim/app/api/proxy/image/route.ts. The manipulation results in server-side …

Sep 2, 2025
CVE-2025-58162
6.5 MEDIUM

MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files …

Sep 2, 2025
CVE-2025-58161
4.3 MEDIUM

MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an …

Sep 2, 2025
CVE-2025-9802
4.7 MEDIUM

A vulnerability was detected in RemoteClinic 2.0. This vulnerability affects unknown code of the file /staff/profile.php. The manipulation of the argument ID results in sql …

Sep 2, 2025
CVE-2025-9801
5.4 MEDIUM

A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affects an unknown part. The manipulation of the argument filePath leads to …

Sep 1, 2025
CVE-2025-9800
6.3 MEDIUM

A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of the file apps/sim/app/api/files/upload/route.ts of the …

Sep 1, 2025
CVE-2025-9799
5.0 MEDIUM

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the …

Sep 1, 2025
CVE-2025-9795
6.3 MEDIUM

A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation …

Sep 1, 2025
CVE-2025-9810
6.8 MEDIUM

TOCTOU in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path …

Sep 1, 2025
CVE-2025-33102
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Sep 1, 2025
CVE-2025-33099
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate …

Sep 1, 2025
CVE-2025-33084
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Sep 1, 2025
CVE-2025-33083
5.4 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web …

Sep 1, 2025
CVE-2025-33082
5.4 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web …

Sep 1, 2025
CVE-2025-0656
6.1 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web …

Sep 1, 2025
CVE-2024-12924
6.3 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing.This issue affects QR Menü: from s1.05.05 before v1.05.12.

Sep 1, 2025
CVE-2024-12914
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR Menü allows Cross-Site Scripting (XSS).This issue affects QR Menü: …

Sep 1, 2025
CVE-2025-36133
5.9 MEDIUM

IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files …

Sep 1, 2025
CVE-2025-9774
4.3 MEDIUM

A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patients/edit-patient.php. The manipulation of the argument …

Sep 1, 2025
CVE-2025-9773
4.3 MEDIUM

A flaw has been found in RemoteClinic up to 2.0. This vulnerability affects unknown code of the file /staff/edit.php. Executing manipulation of the argument Last …

Sep 1, 2025
CVE-2025-9769
4.1 MEDIUM

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr …

Sep 1, 2025
CVE-2025-9768
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sports Management System 1.0. This impacts an unknown function of the file /Admin/mode.php. The manipulation of the argument code …

Sep 1, 2025
CVE-2025-20707
6.7 MEDIUM

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Sep 1, 2025
CVE-2025-20703
6.5 MEDIUM

In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if …

Sep 1, 2025
CVE-2025-9760
6.3 MEDIUM

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Matricula API. …

Sep 1, 2025
CVE-2025-9758
6.3 MEDIUM

A vulnerability was identified in deepakmisal24 Chemical Inventory Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory_form.php. …

Sep 1, 2025
CVE-2025-9570
4.9 MEDIUM

The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download …

Sep 1, 2025
CVE-2025-9569
6.1 MEDIUM

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Sep 1, 2025
CVE-2025-9568
6.1 MEDIUM

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Sep 1, 2025
CVE-2025-9567
6.1 MEDIUM

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Sep 1, 2025
CVE-2025-9756
6.3 MEDIUM

A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid …

Sep 1, 2025
CVE-2025-9755
4.3 MEDIUM

A vulnerability has been found in Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24. This affects an unknown function of the file /index.php. The manipulation of …

Sep 1, 2025
CVE-2025-9747
4.3 MEDIUM

A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request …

Aug 31, 2025
CVE-2025-9745
4.7 MEDIUM

A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. …

Aug 31, 2025
CVE-2025-9732
5.3 MEDIUM

A vulnerability was identified in DCMTK up to 3.6.9. This affects an unknown function in the library dcmimage/include/dcmtk/dcmimage/diybrpxt.h of the component dcm2img. Such manipulation leads …

Aug 31, 2025
CVE-2025-9728
4.3 MEDIUM

A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password …

Aug 31, 2025
CVE-2025-9727
6.3 MEDIUM

A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulation of the …

Aug 31, 2025
CVE-2025-5083
5.5 MEDIUM

The Amministrazione Trasparente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.0 due to …

Aug 31, 2025
CVE-2025-9695
5.3 MEDIUM

A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file …

Aug 30, 2025
CVE-2025-9690
6.3 MEDIUM

A flaw has been found in SourceCodester Advanced School Management System 1.0. This affects an unknown function of the file /index.php/stock/vendordetails. This manipulation of the …

Aug 30, 2025
CVE-2025-9689
6.3 MEDIUM

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/stock/item_select. The manipulation of …

Aug 30, 2025
CVE-2025-9688
5.0 MEDIUM

A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_viewer of the file src/device/cart/is_viewer.c. The manipulation leads …

Aug 30, 2025
CVE-2025-9687
6.3 MEDIUM

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoApi. Executing manipulation can lead to …

Aug 30, 2025
CVE-2025-9686
6.3 MEDIUM

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/AreaConhecimento/edit of the component …

Aug 30, 2025
CVE-2025-9685
6.3 MEDIUM

A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the component Listagem de áreas …

Aug 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.