CVE Database

113799+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54307
8.8 HIGH

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offline/bundle/upload/ endpoints allow low-privilege users to upload ZIP files …

Dec 4, 2025
CVE-2025-54306
7.2 HIGH

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemming …

Dec 4, 2025
CVE-2025-54305
7.8 HIGH

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as …

Dec 4, 2025
CVE-2025-54304
9.8 CRITICAL

An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The …

Dec 4, 2025
CVE-2025-54303
9.8 CRITICAL

The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user …

Dec 4, 2025
CVE-2025-53963
9.8 CRITICAL

An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The …

Dec 4, 2025
CVE-2025-40221

In the Linux kernel, the following vulnerability has been resolved: media: pci: mg4b: fix uninitialized iio scan data Fix potential leak of uninitialized stack data …

Dec 4, 2025
CVE-2025-40220

In the Linux kernel, the following vulnerability has been resolved: fuse: fix livelock in synchronous file put from fuseblk workers I observed a hang when …

Dec 4, 2025
CVE-2025-40219

In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Fix race between SR-IOV enable/disable and hotplug Commit 05703271c3cd ("PCI/IOV: Add PCI rescan-remove locking …

Dec 4, 2025
CVE-2025-40218

In the Linux kernel, the following vulnerability has been resolved: mm/damon/vaddr: do not repeat pte_offset_map_lock() until success DAMON's virtual address space operation set implementation (vaddr) …

Dec 4, 2025
CVE-2025-40217

In the Linux kernel, the following vulnerability has been resolved: pidfs: validate extensible ioctls Validate extensible ioctls stricter than we do now.

Dec 4, 2025
CVE-2025-40216

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment There is no guaranteed alignment for user pointers, …

Dec 4, 2025
CVE-2025-2848
6.3 MEDIUM

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

Dec 4, 2025
CVE-2025-29846
7.2 HIGH

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

Dec 4, 2025
CVE-2025-29845
4.3 MEDIUM

A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.

Dec 4, 2025
CVE-2025-29844
4.3 MEDIUM

A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.

Dec 4, 2025
CVE-2025-29843
5.4 MEDIUM

A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.

Dec 4, 2025
CVE-2025-14008
4.7 MEDIUM

A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec220c7e.php?c=api&m=test_site_domain of the component Project Domain …

Dec 4, 2025
CVE-2025-14007
2.0 LOW

A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mobile of the component Domain Name Binding …

Dec 4, 2025
CVE-2025-14006
3.5 LOW

A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=1 of …

Dec 4, 2025
CVE-2024-5401
4.3 MEDIUM

Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller …

Dec 4, 2025
CVE-2024-45539
7.5 HIGH

Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers …

Dec 4, 2025
CVE-2024-45538
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows …

Dec 4, 2025
CVE-2025-14005
2.4 LOW

A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=0 of the …

Dec 4, 2025
CVE-2025-14004
4.7 MEDIUM

A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add of the component Email …

Dec 4, 2025
CVE-2025-40215

In the Linux kernel, the following vulnerability has been resolved: xfrm: delete x->tunnel as we delete x The ipcomp fallback tunnels currently get deleted (from …

Dec 4, 2025
CVE-2025-40214

In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a …

Dec 4, 2025
CVE-2025-11222
6.1 MEDIUM

Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating …

Dec 4, 2025
CVE-2025-41080
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser …

Dec 4, 2025
CVE-2025-41079
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser …

Dec 4, 2025
CVE-2025-14010
5.5 MEDIUM

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible …

Dec 4, 2025
CVE-2025-12826
4.8 MEDIUM

The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to …

Dec 4, 2025
CVE-2025-12782
4.3 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.9.4. This is …

Dec 4, 2025
CVE-2025-13513
6.1 MEDIUM

The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.8 due …

Dec 4, 2025
CVE-2025-11727
7.2 HIGH

The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Dec 4, 2025
CVE-2025-11379
5.3 MEDIUM

The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due …

Dec 4, 2025
CVE-2025-62173

## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API

Dec 4, 2025
CVE-2025-66404
6.4 MEDIUM

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue …

Dec 3, 2025
CVE-2025-66293
7.1 HIGH

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an …

Dec 3, 2025
CVE-2025-65868
7.5 HIGH

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

Dec 3, 2025
CVE-2025-64055
9.8 CRITICAL

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file …

Dec 3, 2025
CVE-2025-66489
9.8 CRITICAL

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP …

Dec 3, 2025
CVE-2025-66453
7.5 HIGH

Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float …

Dec 3, 2025
CVE-2025-66411
7.8 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in …

Dec 3, 2025
CVE-2025-66406
5.0 MEDIUM

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH …

Dec 3, 2025
CVE-2025-65345
6.5 MEDIUM

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the …

Dec 3, 2025
CVE-2025-65097
6.5 MEDIUM

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, …

Dec 3, 2025
CVE-2025-65096
4.3 MEDIUM

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, …

Dec 3, 2025
CVE-2025-65027
7.6 HIGH

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file …

Dec 3, 2025
CVE-2025-61727
6.5 MEDIUM

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that …

Dec 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.