CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5539

The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass …

Nov 27, 2025
CVE-2025-66040
3.6 LOW

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback …

Nov 27, 2025
CVE-2025-66035

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there …

Nov 26, 2025
CVE-2025-66031
7.5 HIGH

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables …

Nov 26, 2025
CVE-2025-66030
5.3 MEDIUM

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables …

Nov 26, 2025
CVE-2025-64344
7.5 HIGH

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 …

Nov 26, 2025
CVE-2025-64335
7.5 HIGH

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 …

Nov 26, 2025
CVE-2025-64334
7.5 HIGH

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 …

Nov 26, 2025
CVE-2025-64333
7.5 HIGH

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 …

Nov 26, 2025
CVE-2025-64332
7.5 HIGH

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 …

Nov 26, 2025
CVE-2025-64331
7.5 HIGH

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 …

Nov 26, 2025
CVE-2025-64330
7.5 HIGH

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 …

Nov 26, 2025
CVE-2025-62593

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE …

Nov 26, 2025
CVE-2025-40934
9.3 CRITICAL

XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the XML document …

Nov 26, 2025
CVE-2020-36874

ACE SECURITY WIP-90113 HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint permits remote download of a compressed configuration backup …

Nov 26, 2025
CVE-2020-36873

Astak CM-818T3 2.4GHz wireless security surveillance cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint permits remote download of a compressed …

Nov 26, 2025
CVE-2020-36872

BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The server fails …

Nov 26, 2025
CVE-2020-36871

ESCAM QD-900 WIFI HD cameras contain an unauthenticated configuration disclosure vulnerability in the /web/cgi-bin/hi3510/backup.cgi endpoint. The endpoint allows remote download of a compressed configuration backup …

Nov 26, 2025
CVE-2019-25227

Tellion HN-2204AP routers contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/system_config_file management endpoint. The endpoint allows remote retrieval of a compressed configuration archive without …

Nov 26, 2025
CVE-2019-25226

Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/sys_system_config management endpoint. The endpoint allows remote retrieval of a compressed …

Nov 26, 2025
CVE-2025-65202
8.0 HIGH

TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which …

Nov 26, 2025
CVE-2025-7449
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-6195
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-65670
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpoints by manipulating course IDs in URLs, resulting in unauthorized …

Nov 26, 2025
CVE-2025-65278
7.5 HIGH

An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers to gain sensitive information including plaintext usernames and passwords.

Nov 26, 2025
CVE-2025-65276
9.8 CRITICAL

An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru commit 5919decaff2681dc250e934814fc3a35f6093ee5 (2021-07-02). Due to missing authentication checks on /admin_index.php, an …

Nov 26, 2025
CVE-2025-50433
9.8 CRITICAL

An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

Nov 26, 2025
CVE-2025-13611
2.0 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated …

Nov 26, 2025
CVE-2025-12653
6.5 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that under specific …

Nov 26, 2025
CVE-2025-12571
7.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have …

Nov 26, 2025
CVE-2025-66028
8.2 HIGH

OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During …

Nov 26, 2025
CVE-2025-65966
8.1 HIGH

OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request …

Nov 26, 2025
CVE-2025-65681
3.3 LOW

An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper …

Nov 26, 2025
CVE-2025-65676
5.4 MEDIUM

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images.

Nov 26, 2025
CVE-2025-65675
5.4 MEDIUM

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures.

Nov 26, 2025
CVE-2025-65672
7.5 HIGH

Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.

Nov 26, 2025
CVE-2025-65669
9.1 CRITICAL

An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing …

Nov 26, 2025
CVE-2025-26155
9.8 CRITICAL

NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.

Nov 26, 2025
CVE-2021-4472
6.5 MEDIUM

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files …

Nov 26, 2025
CVE-2025-64130
9.8 CRITICAL

Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.

Nov 26, 2025
CVE-2025-64129
7.6 HIGH

Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the device.

Nov 26, 2025
CVE-2025-64128
10.0 CRITICAL

An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to …

Nov 26, 2025
CVE-2025-64127
10.0 CRITICAL

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without …

Nov 26, 2025
CVE-2025-64126
10.0 CRITICAL

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a …

Nov 26, 2025
CVE-2025-55471
7.5 HIGH

Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.

Nov 26, 2025
CVE-2025-55469
9.8 CRITICAL

Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

Nov 26, 2025
CVE-2025-2486
8.8 HIGH

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. …

Nov 26, 2025
CVE-2025-20373
2.7 LOW

In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition …

Nov 26, 2025
CVE-2025-13084
7.6 HIGH

The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. This endpoint requires an …

Nov 26, 2025
CVE-2025-11461
8.8 HIGH

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.

Nov 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.