CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13564
5.4 MEDIUM

A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the …

Nov 23, 2025
CVE-2025-54515

The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set …

Nov 23, 2025
CVE-2025-13562
7.3 HIGH

A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument service leads …

Nov 23, 2025
CVE-2025-13561
7.3 HIGH

A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username …

Nov 23, 2025
CVE-2025-48507

The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access …

Nov 23, 2025
CVE-2025-13560
7.3 HIGH

A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email …

Nov 23, 2025
CVE-2025-13557
7.3 HIGH

A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation …

Nov 23, 2025
CVE-2024-21923
7.3 HIGH

Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

Nov 23, 2025
CVE-2024-21922
7.3 HIGH

A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Nov 23, 2025
CVE-2025-13556
7.3 HIGH

A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a …

Nov 23, 2025
CVE-2025-13555
7.3 HIGH

A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing …

Nov 23, 2025
CVE-2025-13554
7.3 HIGH

A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. …

Nov 23, 2025
CVE-2025-13553
8.8 HIGH

A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes …

Nov 23, 2025
CVE-2025-13552
8.8 HIGH

A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation …

Nov 23, 2025
CVE-2025-13551
8.8 HIGH

A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the …

Nov 23, 2025
CVE-2025-13550
8.8 HIGH

A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url …

Nov 23, 2025
CVE-2025-13549
8.8 HIGH

A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNtp. Performing manipulation of the argument submit-url results …

Nov 23, 2025
CVE-2025-13548
8.8 HIGH

A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument …

Nov 23, 2025
CVE-2025-13547
8.8 HIGH

A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument …

Nov 23, 2025
CVE-2025-13546
6.3 MEDIUM

A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component …

Nov 23, 2025
CVE-2025-13545
4.7 MEDIUM

A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The …

Nov 23, 2025
CVE-2025-13544
6.3 MEDIUM

A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to …

Nov 23, 2025
CVE-2025-13197

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 22, 2025
CVE-2025-12561

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 22, 2025
CVE-2025-12541

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 22, 2025
CVE-2025-13526
7.5 HIGH

The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.8 via the …

Nov 22, 2025
CVE-2025-13318
5.3 MEDIUM

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to …

Nov 22, 2025
CVE-2025-13136
4.3 MEDIUM

The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' …

Nov 22, 2025
CVE-2025-13384
7.5 HIGH

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due …

Nov 22, 2025
CVE-2025-13317
5.3 MEDIUM

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the …

Nov 22, 2025
CVE-2025-12877
5.3 MEDIUM

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability …

Nov 22, 2025
CVE-2025-12752
5.3 MEDIUM

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is …

Nov 22, 2025
CVE-2025-11186
6.4 MEDIUM

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookies_accepted shortcode in all …

Nov 22, 2025
CVE-2025-12889
5.4 MEDIUM

With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.

Nov 22, 2025
CVE-2025-65947

thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resource leaks when querying thread …

Nov 21, 2025
CVE-2025-65946
8.1 HIGH

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error in validation it was …

Nov 21, 2025
CVE-2025-12888
7.5 HIGH

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. …

Nov 21, 2025
CVE-2025-12678

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 21, 2025
CVE-2025-11936
5.3 MEDIUM

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by …

Nov 21, 2025
CVE-2025-11934
2.7 LOW

Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm …

Nov 21, 2025
CVE-2025-11933
6.5 MEDIUM

Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially …

Nov 21, 2025
CVE-2025-11932
4.3 MEDIUM

The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder

Nov 21, 2025
CVE-2025-11931
8.2 HIGH

Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used …

Nov 21, 2025
CVE-2025-65111
5.3 MEDIUM

SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: …

Nov 21, 2025
CVE-2025-65109

Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users …

Nov 21, 2025
CVE-2025-65108
10.0 CRITICAL

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that …

Nov 21, 2025
CVE-2025-65107
6.5 MEDIUM

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO …

Nov 21, 2025
CVE-2025-65106

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in …

Nov 21, 2025
CVE-2025-65102

PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the …

Nov 21, 2025
CVE-2025-65092

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the ESP32-P4 uses its hardware JPEG decoder, the …

Nov 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.