CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53360
4.3 MEDIUM

pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior …

Nov 18, 2025
CVE-2025-48839
6.6 MEDIUM

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all …

Nov 18, 2025
CVE-2025-47761
7.8 HIGH

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local …

Nov 18, 2025
CVE-2025-46776
6.4 MEDIUM

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all …

Nov 18, 2025
CVE-2025-46775
5.5 MEDIUM

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions …

Nov 18, 2025
CVE-2025-46373
7.8 HIGH

A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to …

Nov 18, 2025
CVE-2025-46215
5.3 MEDIUM

An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions …

Nov 18, 2025
CVE-2025-34324
7.8 HIGH

GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The manifest contains package URLs and SHA-256 hashes but is …

Nov 18, 2025
CVE-2025-33184
7.8 HIGH

NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successful exploit of …

Nov 18, 2025
CVE-2025-33183
7.8 HIGH

NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successful exploit of …

Nov 18, 2025
CVE-2025-13083
3.7 LOW

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Drupal core: …

Nov 18, 2025
CVE-2025-13082
4.3 MEDIUM

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 …

Nov 18, 2025
CVE-2025-13081
5.9 MEDIUM

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 …

Nov 18, 2025
CVE-2025-13080
5.3 MEDIUM

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 …

Nov 18, 2025
CVE-2025-12761
3.5 LOW

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple multi step form allows Cross-Site Scripting (XSS).This issue affects Simple multi …

Nov 18, 2025
CVE-2025-12760
5.4 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6.

Nov 18, 2025
CVE-2025-9977

Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an …

Nov 18, 2025
CVE-2025-64996
4.4 MEDIUM

In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local …

Nov 18, 2025
CVE-2025-63800
7.5 HIGH

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing …

Nov 18, 2025
CVE-2025-63604
6.5 MEDIUM

A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input validation in the execute_query method. The vulnerability stems from …

Nov 18, 2025
CVE-2025-63603
6.5 MEDIUM

A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_eval() function (src/mcp_server_ds/server.py:108). The function uses Python's exec() to execute …

Nov 18, 2025
CVE-2025-63602
7.3 HIGH

A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an …

Nov 18, 2025
CVE-2025-63408
7.8 HIGH

Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a …

Nov 18, 2025
CVE-2025-58122
5.4 MEDIUM

Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized …

Nov 18, 2025
CVE-2025-58121
5.4 MEDIUM

Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or …

Nov 18, 2025
CVE-2025-55074
3.0 LOW

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users …

Nov 18, 2025
CVE-2025-12383
7.4 HIGH

In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, …

Nov 18, 2025
CVE-2025-9312
9.8 CRITICAL

A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due …

Nov 18, 2025
CVE-2025-8084
6.8 MEDIUM

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This …

Nov 18, 2025
CVE-2025-63892
6.8 MEDIUM

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms …

Nov 18, 2025
CVE-2025-63883
5.4 MEDIUM

A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client-side JavaScript reads attacker-controlled input (for example, values derived from the URL or …

Nov 18, 2025
CVE-2025-59117
4.8 MEDIUM

Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu/admin/content/pages/edit/. This vulnerability can be exploited by a privileged …

Nov 18, 2025
CVE-2025-59116
5.3 MEDIUM

Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow an attacker to determine if the …

Nov 18, 2025
CVE-2025-59115
5.4 MEDIUM

Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation. Malicious attacker can inject arbitrary …

Nov 18, 2025
CVE-2025-59114
6.5 MEDIUM

Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft special website, which when visited by the victim, will …

Nov 18, 2025
CVE-2025-59113
7.5 HIGH

Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows …

Nov 18, 2025
CVE-2025-59112
6.5 MEDIUM

Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft special website, which when visited by the victim, will …

Nov 18, 2025
CVE-2025-59111
6.5 MEDIUM

Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET request which allows privileged users to delete …

Nov 18, 2025
CVE-2025-59110
6.5 MEDIUM

Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechanism can be bypassed by using CSRF token of other …

Nov 18, 2025
CVE-2025-55179
5.4 MEDIUM

Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have …

Nov 18, 2025
CVE-2025-13349
3.5 LOW

A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown processing of the file /grades.php of the component …

Nov 18, 2025
CVE-2025-13347
6.3 MEDIUM

A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the …

Nov 18, 2025
CVE-2025-13346
6.3 MEDIUM

A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the file /ajax.php?action=save_station. Performing manipulation of the argument …

Nov 18, 2025
CVE-2025-12545
5.3 MEDIUM

The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Information Exposure in all …

Nov 18, 2025
CVE-2025-12376
6.4 MEDIUM

The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, …

Nov 18, 2025
CVE-2025-10158
4.3 MEDIUM

A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based buffer, via …

Nov 18, 2025
CVE-2025-6670
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin …

Nov 18, 2025
CVE-2025-41350
5.4 MEDIUM

Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack …

Nov 18, 2025
CVE-2025-41349
5.4 MEDIUM

Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack …

Nov 18, 2025
CVE-2025-41348
9.8 CRITICAL

SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete databases by sendng a POST …

Nov 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.