CVE Database

113799+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58479
4.3 MEDIUM

Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58478
4.3 MEDIUM

Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58477
4.3 MEDIUM

Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58476
4.2 MEDIUM

Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.

Dec 2, 2025
CVE-2025-58475
5.6 MEDIUM

Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Dec 2, 2025
CVE-2025-55129
5.4 MEDIUM

HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via …

Dec 2, 2025
CVE-2025-21080
6.2 MEDIUM

Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.

Dec 2, 2025
CVE-2025-21072
5.7 MEDIUM

Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Dec 2, 2025
CVE-2025-66448
7.1 HIGH

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a …

Dec 1, 2025
CVE-2025-66415
5.4 MEDIUM

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could …

Dec 1, 2025
CVE-2025-66412
5.4 MEDIUM

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored …

Dec 1, 2025
CVE-2025-66410
9.1 CRITICAL

Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, …

Dec 1, 2025
CVE-2025-66405
9.8 CRITICAL

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in …

Dec 1, 2025
CVE-2025-66403
4.6 MEDIUM

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 2.2.3, a stored cross-site scripting (XSS) vulnerability exists in …

Dec 1, 2025
CVE-2025-66401
9.8 CRITICAL

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical Command Injection …

Dec 1, 2025
CVE-2025-66400
5.3 MEDIUM

mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using …

Dec 1, 2025
CVE-2025-66313
7.2 HIGH

ChurchCRM is an open-source church management system. In ChurchCRM 6.2.0 and earlier, there is a time-based blind SQL injection in the handling of the 1FieldSec …

Dec 1, 2025
CVE-2025-66312
5.4 MEDIUM

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior …

Dec 1, 2025
CVE-2025-66311
5.4 MEDIUM

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior …

Dec 1, 2025
CVE-2025-66310
5.4 MEDIUM

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior …

Dec 1, 2025
CVE-2025-66309
6.1 MEDIUM

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior …

Dec 1, 2025
CVE-2025-66308
5.4 MEDIUM

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior …

Dec 1, 2025
CVE-2025-66307
6.5 MEDIUM

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior …

Dec 1, 2025
CVE-2025-66306
4.3 MEDIUM

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which …

Dec 1, 2025
CVE-2025-66305
4.9 MEDIUM

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the "Languages" submenu of the Grav admin …

Dec 1, 2025
CVE-2025-66304
6.2 MEDIUM

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view …

Dec 1, 2025
CVE-2025-66303
4.9 MEDIUM

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of …

Dec 1, 2025
CVE-2025-66302
6.8 MEDIUM

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges …

Dec 1, 2025
CVE-2025-66301
9.6 CRITICAL

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an …

Dec 1, 2025
CVE-2025-66300
8.5 HIGH

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" …

Dec 1, 2025
CVE-2025-66299
8.8 HIGH

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with …

Dec 1, 2025
CVE-2025-66298
7.5 HIGH

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration …

Dec 1, 2025
CVE-2025-65622
5.4 MEDIUM

Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.

Dec 1, 2025
CVE-2025-66297
8.8 HIGH

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS …

Dec 1, 2025
CVE-2025-66296
8.8 HIGH

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness …

Dec 1, 2025
CVE-2025-66295
8.8 HIGH

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI …

Dec 1, 2025
CVE-2025-66294
8.8 HIGH

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions …

Dec 1, 2025
CVE-2025-66206
6.8 MEDIUM

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein some files from the …

Dec 1, 2025
CVE-2025-66205
7.1 HIGH

Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to error-based SQL injection due to lack of …

Dec 1, 2025
CVE-2025-65840
8.8 HIGH

PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

Dec 1, 2025
CVE-2025-65621
5.4 MEDIUM

Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.

Dec 1, 2025
CVE-2025-58044
6.1 MEDIUM

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// endpoint uses the …

Dec 1, 2025
CVE-2025-55749
7.5 HIGH

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), …

Dec 1, 2025
CVE-2025-65838
7.5 HIGH

PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.

Dec 1, 2025
CVE-2025-65836
9.1 CRITICAL

PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

Dec 1, 2025
CVE-2025-63317
5.4 MEDIUM

Todoist v8896 is vulnerable to Cross Site Scripting (XSS) in /api/v1/uploads. Uploaded SVG files have no sanitization applied, so embedded JavaScript executes when a user …

Dec 1, 2025
CVE-2025-51683
9.8 CRITICAL

A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server …

Dec 1, 2025
CVE-2025-51682
9.8 CRITICAL

mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to administrative features. Additionally, they …

Dec 1, 2025
CVE-2025-12756
4.3 MEDIUM

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which …

Dec 1, 2025
CVE-2025-65407
6.5 MEDIUM

A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG …

Dec 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.