CVE Database

112325+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-14004
4.7 MEDIUM

A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add of the component Email …

Dec 4, 2025
CVE-2025-40215

In the Linux kernel, the following vulnerability has been resolved: xfrm: delete x->tunnel as we delete x The ipcomp fallback tunnels currently get deleted (from …

Dec 4, 2025
CVE-2025-40214

In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a …

Dec 4, 2025
CVE-2025-11222
6.1 MEDIUM

Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating …

Dec 4, 2025
CVE-2025-41080
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser …

Dec 4, 2025
CVE-2025-41079
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser …

Dec 4, 2025
CVE-2025-14010
5.5 MEDIUM

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible …

Dec 4, 2025
CVE-2025-12826
4.8 MEDIUM

The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to …

Dec 4, 2025
CVE-2025-12782
4.3 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.9.4. This is …

Dec 4, 2025
CVE-2025-13513
6.1 MEDIUM

The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.8 due …

Dec 4, 2025
CVE-2025-11727
7.2 HIGH

The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Dec 4, 2025
CVE-2025-11379
5.3 MEDIUM

The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due …

Dec 4, 2025
CVE-2025-62173

## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API

Dec 4, 2025
CVE-2025-66404
6.4 MEDIUM

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue …

Dec 3, 2025
CVE-2025-66293
7.1 HIGH

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an …

Dec 3, 2025
CVE-2025-65868
7.5 HIGH

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

Dec 3, 2025
CVE-2025-64055
9.8 CRITICAL

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file …

Dec 3, 2025
CVE-2025-66489
9.8 CRITICAL

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP …

Dec 3, 2025
CVE-2025-66453
7.5 HIGH

Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float …

Dec 3, 2025
CVE-2025-66411
7.8 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in …

Dec 3, 2025
CVE-2025-66406
5.0 MEDIUM

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH …

Dec 3, 2025
CVE-2025-65345
6.5 MEDIUM

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the …

Dec 3, 2025
CVE-2025-65097
6.5 MEDIUM

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, …

Dec 3, 2025
CVE-2025-65096
4.3 MEDIUM

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, …

Dec 3, 2025
CVE-2025-65027
7.6 HIGH

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file …

Dec 3, 2025
CVE-2025-61727
6.5 MEDIUM

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that …

Dec 3, 2025
CVE-2025-50361
5.1 MEDIUM

Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function main.cpp, which can lead to potential information …

Dec 3, 2025
CVE-2025-13086
7.5 HIGH

Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a …

Dec 3, 2025
CVE-2025-12385

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, …

Dec 3, 2025
CVE-2025-66222
9.6 CRITICAL

DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer …

Dec 3, 2025
CVE-2025-66220
5.0 MEDIUM

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an …

Dec 3, 2025
CVE-2025-66208
9.8 CRITICAL

Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to …

Dec 3, 2025
CVE-2025-66032
9.8 CRITICAL

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and short CLI flags, it …

Dec 3, 2025
CVE-2025-63402
5.5 MEDIUM

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on …

Dec 3, 2025
CVE-2025-63401
5.5 MEDIUM

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

Dec 3, 2025
CVE-2025-50360
8.4 HIGH

A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2bb7. Malicious execution of a pepper source file(.pr) could lead to arbitrary code …

Dec 3, 2025
CVE-2025-33211
7.5 HIGH

NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input. A successful exploit of …

Dec 3, 2025
CVE-2025-33208
8.8 HIGH

NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploit of this …

Dec 3, 2025
CVE-2025-33201
7.5 HIGH

NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large …

Dec 3, 2025
CVE-2025-13992
4.7 MEDIUM

Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML …

Dec 3, 2025
CVE-2025-12819
7.5 HIGH

Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path …

Dec 3, 2025
CVE-2025-12084
5.3 MEDIUM

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when …

Dec 3, 2025
CVE-2024-3884
7.5 HIGH

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form …

Dec 3, 2025
CVE-2025-66478

Rejected reason: This CVE is a duplicate of CVE-2025-55182.

Dec 3, 2025
CVE-2025-64763
3.7 LOW

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, …

Dec 3, 2025
CVE-2025-64527
6.5 MEDIUM

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes when JWT authentication is configured with the remote JWKS fetching, …

Dec 3, 2025
CVE-2025-64443
9.6 CRITICAL

MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming …

Dec 3, 2025
CVE-2025-66431
7.8 HIGH

WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker …

Dec 3, 2025
CVE-2025-65843
7.7 HIGH

Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application follows symbolic links placed inside …

Dec 3, 2025
CVE-2025-65842
5.1 MEDIUM

The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local …

Dec 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.