CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13242
7.3 HIGH

A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processing of the file /register.php. The manipulation leads to …

Nov 16, 2025
CVE-2025-13241
7.3 HIGH

A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument …

Nov 16, 2025
CVE-2025-13240
7.3 HIGH

A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s …

Nov 16, 2025
CVE-2025-13239
4.3 MEDIUM

A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of …

Nov 16, 2025
CVE-2025-13238
6.3 MEDIUM

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the …

Nov 16, 2025
CVE-2025-13237
7.3 HIGH

A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the …

Nov 16, 2025
CVE-2025-12482
7.5 HIGH

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up …

Nov 16, 2025
CVE-2025-13236
6.3 MEDIUM

A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID …

Nov 16, 2025
CVE-2025-13235
7.3 HIGH

A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the file /admin/login.php. Executing manipulation of the argument user_email …

Nov 16, 2025
CVE-2025-13234
6.3 MEDIUM

A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the …

Nov 16, 2025
CVE-2025-13233
7.3 HIGH

A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /index.php?q=single-item. Such manipulation of …

Nov 16, 2025
CVE-2025-13232
3.5 LOW

A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Download Aliases. This manipulation causes …

Nov 16, 2025
CVE-2025-2448

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 15, 2025
CVE-2025-13221
5.3 MEDIUM

A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument …

Nov 15, 2025
CVE-2025-13210
4.7 MEDIUM

A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the …

Nov 15, 2025
CVE-2025-13209
6.3 MEDIUM

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument …

Nov 15, 2025
CVE-2025-13208
6.3 MEDIUM

A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The …

Nov 15, 2025
CVE-2025-13203
7.3 HIGH

A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code of the file /addmem.php. Executing manipulation of the …

Nov 15, 2025
CVE-2025-13202
3.5 LOW

A security flaw has been discovered in code-projects Simple Cafe Ordering System 1.0. This affects an unknown part of the file /add_to_cart. Performing manipulation of …

Nov 15, 2025
CVE-2025-13201
7.3 HIGH

A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation …

Nov 15, 2025
CVE-2025-13200
5.3 MEDIUM

A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of information through …

Nov 15, 2025
CVE-2025-13199
5.3 MEDIUM

A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username …

Nov 15, 2025
CVE-2025-13198
4.7 MEDIUM

A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the …

Nov 15, 2025
CVE-2025-12983
3.5 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have …

Nov 15, 2025
CVE-2025-7736
3.1 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have …

Nov 15, 2025
CVE-2025-7000
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific …

Nov 15, 2025
CVE-2025-6945
3.5 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have …

Nov 15, 2025
CVE-2025-6171
5.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have …

Nov 15, 2025
CVE-2025-2615
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have …

Nov 15, 2025
CVE-2025-11990
3.1 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated …

Nov 15, 2025
CVE-2025-11865
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain …

Nov 15, 2025
CVE-2025-13191
8.8 HIGH

A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the file /soap.cgi. This manipulation causes stack-based buffer overflow. It …

Nov 15, 2025
CVE-2025-13190
8.8 HIGH

A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the file /portal/__ajax_exporer.sgi. The manipulation of the argument en results …

Nov 15, 2025
CVE-2025-12849
5.3 MEDIUM

The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin …

Nov 15, 2025
CVE-2025-8994
6.5 MEDIUM

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL …

Nov 15, 2025
CVE-2025-13189
8.8 HIGH

A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena.cgi. The manipulation of the argument SERVER_ID/HTTP_SID leads …

Nov 15, 2025
CVE-2025-12847
4.3 MEDIUM

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media …

Nov 15, 2025
CVE-2025-12494
4.3 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in …

Nov 15, 2025
CVE-2025-65072

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65071

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65070

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65069

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65068

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65067

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65066

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65065

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65064

Rejected reason: Not used

Nov 15, 2025
CVE-2025-12182
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up …

Nov 15, 2025
CVE-2025-9317
8.4 HIGH

The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' …

Nov 15, 2025
CVE-2025-8386
6.9 MEDIUM

The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting …

Nov 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.