CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47856
9.8 CRITICAL

In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces …

Nov 24, 2025
CVE-2025-63498
6.1 MEDIUM

alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

Nov 24, 2025
CVE-2025-52538
8.0 HIGH

Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in loss of confidentiality or …

Nov 24, 2025
CVE-2025-48511
5.5 MEDIUM

Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of …

Nov 24, 2025
CVE-2025-48510
7.1 HIGH

Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability.

Nov 24, 2025
CVE-2025-36150
5.9 MEDIUM

IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Nov 24, 2025
CVE-2025-29933
5.5 MEDIUM

Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service

Nov 24, 2025
CVE-2025-0007
5.7 MEDIUM

Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user space to kernel space, potentially compromising confidentiality, integrity, …

Nov 24, 2025
CVE-2025-0003
7.3 HIGH

Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition potentially resulting in loss of confidentiality or availability

Nov 24, 2025
CVE-2024-14007

Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an authentication bypass in the NVMS-9000 …

Nov 24, 2025
CVE-2023-7330

Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and …

Nov 24, 2025
CVE-2018-25126

Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in …

Nov 24, 2025
CVE-2025-64048
6.1 MEDIUM

YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the …

Nov 24, 2025
CVE-2025-64047
6.1 MEDIUM

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.

Nov 24, 2025
CVE-2025-63914
6.5 MEDIUM

An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although …

Nov 24, 2025
CVE-2025-56400
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, affects the Tuya Smart and Smartlife mobile …

Nov 24, 2025
CVE-2025-52539
7.3 HIGH

A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced extensible interface (AXI), potentially …

Nov 24, 2025
CVE-2025-0005
7.3 HIGH

Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in crash or denial of …

Nov 24, 2025
CVE-2025-36112
5.3 MEDIUM

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could reveal sensitive server IP configuration information …

Nov 24, 2025
CVE-2025-13466

body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An attacker can send …

Nov 24, 2025
CVE-2025-13609
8.2 HIGH

A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module …

Nov 24, 2025
CVE-2025-63958
9.8 CRITICAL

MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, …

Nov 24, 2025
CVE-2025-63953
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Nov 24, 2025
CVE-2025-63952
5.7 MEDIUM

A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows attackers to arbitrarily create accounts via a crafted GET request.

Nov 24, 2025
CVE-2025-63435
4.3 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side endpoint responsible for serving update packages for the application does not …

Nov 24, 2025
CVE-2025-63434
8.8 HIGH

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without …

Nov 24, 2025
CVE-2025-63433
4.6 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt update metadata. The key is stored as a …

Nov 24, 2025
CVE-2025-63432
4.6 MEDIUM

Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fails to properly validate the TLS certificate from its update …

Nov 24, 2025
CVE-2025-60917
4.6 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the …

Nov 24, 2025
CVE-2025-60916
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the …

Nov 24, 2025
CVE-2025-60915
8.1 HIGH

An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted …

Nov 24, 2025
CVE-2025-60914
4.6 MEDIUM

Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo …

Nov 24, 2025
CVE-2025-60638
7.5 HIGH

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability …

Nov 24, 2025
CVE-2025-60633
6.5 MEDIUM

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.

Nov 24, 2025
CVE-2025-60632
6.5 MEDIUM

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl …

Nov 24, 2025
CVE-2025-56423
5.3 MEDIUM

An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error …

Nov 24, 2025
CVE-2025-56401
7.6 HIGH

ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.

Nov 24, 2025
CVE-2025-44018
8.3 HIGH

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. …

Nov 24, 2025
CVE-2025-40213

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete There is a BUG: KASAN: stack-out-of-bounds in …

Nov 24, 2025
CVE-2025-10555
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer on Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary …

Nov 24, 2025
CVE-2025-10554
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute …

Nov 24, 2025
CVE-2025-12978
5.4 MEDIUM

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows …

Nov 24, 2025
CVE-2025-12977
9.1 CRITICAL

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with network access or the ability to write records into …

Nov 24, 2025
CVE-2025-12972
5.3 MEDIUM

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted …

Nov 24, 2025
CVE-2025-12970
8.8 HIGH

The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating length. An attacker who can …

Nov 24, 2025
CVE-2025-12969
6.5 MEDIUM

Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to …

Nov 24, 2025
CVE-2025-11921

iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4.

Nov 24, 2025
CVE-2025-65998
7.5 HIGH

Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. …

Nov 24, 2025
CVE-2025-65503
5.5 MEDIUM

Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that …

Nov 24, 2025
CVE-2025-65502
4.3 MEDIUM

Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns …

Nov 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.