CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64715
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference …

Nov 29, 2025
CVE-2025-13683
6.5 MEDIUM

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

Nov 28, 2025
CVE-2025-12183

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

Nov 28, 2025
CVE-2025-59792
5.3 MEDIUM

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade …

Nov 28, 2025
CVE-2025-59790
5.4 MEDIUM

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which …

Nov 28, 2025
CVE-2025-51736
6.3 MEDIUM

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-51735
7.5 HIGH

CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-51734
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-51733
5.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-12638
8.0 HIGH

Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerability arises because the function uses …

Nov 28, 2025
CVE-2025-11156

Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, a local, authenticated user …

Nov 28, 2025
CVE-2025-12143
6.1 MEDIUM

Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

Nov 28, 2025
CVE-2025-13771
6.5 MEDIUM

WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

Nov 28, 2025
CVE-2025-13770
6.5 MEDIUM

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Nov 28, 2025
CVE-2025-13769
6.5 MEDIUM

WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

Nov 28, 2025
CVE-2025-13768
7.5 HIGH

WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific …

Nov 28, 2025
CVE-2025-66386
4.1 MEDIUM

app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

Nov 28, 2025
CVE-2025-66385

UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit …

Nov 28, 2025
CVE-2025-66384
8.2 HIGH

app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.

Nov 28, 2025
CVE-2025-66382
2.9 LOW

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

Nov 28, 2025
CVE-2025-66372
2.8 LOW

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

Nov 28, 2025
CVE-2025-66371
5.0 MEDIUM

Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files from the filesystem and …

Nov 28, 2025
CVE-2025-66370
5.0 MEDIUM

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the …

Nov 28, 2025
CVE-2025-64312
4.9 MEDIUM

Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58311
5.8 MEDIUM

UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58308
7.3 HIGH

Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Nov 28, 2025
CVE-2025-58305
6.2 MEDIUM

Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58304
4.9 MEDIUM

Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58302
8.4 HIGH

Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-13737
4.3 MEDIUM

The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is …

Nov 28, 2025
CVE-2025-64315
4.4 MEDIUM

Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.

Nov 28, 2025
CVE-2025-64314
9.3 CRITICAL

Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability may affect confidentiality.

Nov 28, 2025
CVE-2025-64313
5.3 MEDIUM

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-64311
5.1 MEDIUM

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58316
7.3 HIGH

DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-58315
5.5 MEDIUM

Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58314
6.6 MEDIUM

Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58312
5.1 MEDIUM

Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-58310
8.0 HIGH

Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-58309
6.8 MEDIUM

Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

Nov 28, 2025
CVE-2025-58307
6.4 MEDIUM

UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-58303
8.4 HIGH

UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

Nov 28, 2025
CVE-2025-58294
6.2 MEDIUM

Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 28, 2025
CVE-2025-66361
6.5 MEDIUM

An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.

Nov 28, 2025
CVE-2025-66360
8.8 HIGH

An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This …

Nov 28, 2025
CVE-2025-66359
8.5 HIGH

An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting …

Nov 28, 2025
CVE-2025-13338

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 27, 2025
CVE-2025-3261

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 27, 2025
CVE-2025-12421
9.9 CRITICAL

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code …

Nov 27, 2025
CVE-2025-12559
4.3 MEDIUM

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to …

Nov 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.