CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-4464

FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails …

Nov 12, 2025
CVE-2021-4463

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is …

Nov 12, 2025
CVE-2017-20211

UCanCode E-XD++ Visualization Enterprise Suite contains an untrusted pointer dereference vulnerability via the TKDRAWCAD.TKDrawCADCtrl.1 ActiveX control. This is because it exposes a RotateShape method that …

Nov 12, 2025
CVE-2016-15055

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts …

Nov 12, 2025
CVE-2011-10034

AUTOMGEN versions up to and including 8.0.0.7 (also referenced as 8.022) contain a vulnerability in that project file handling frees an object and subsequently dereferences …

Nov 12, 2025
CVE-2025-64186
8.7 HIGH

Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verification logic in versions of `evervault-go` prior to 1.3.2 that …

Nov 12, 2025
CVE-2025-64170
3.8 LOW

sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user …

Nov 12, 2025
CVE-2025-63396
3.3 LOW

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a …

Nov 12, 2025
CVE-2025-46608
9.1 CRITICAL

Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, …

Nov 12, 2025
CVE-2025-36223
5.4 MEDIUM

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an …

Nov 12, 2025
CVE-2025-13063
7.3 HIGH

A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. The attack may …

Nov 12, 2025
CVE-2025-13061
6.3 MEDIUM

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Performing manipulation results in unrestricted upload. …

Nov 12, 2025
CVE-2025-8485
7.3 HIGH

An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation …

Nov 12, 2025
CVE-2025-8421
6.6 MEDIUM

An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect …

Nov 12, 2025
CVE-2025-64117
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1761813675 and Tuleap Enterprise Edition …

Nov 12, 2025
CVE-2025-46428
8.8 HIGH

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged …

Nov 12, 2025
CVE-2025-46427
8.8 HIGH

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged …

Nov 12, 2025
CVE-2025-27368
4.3 MEDIUM

IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points …

Nov 12, 2025
CVE-2025-13060
7.3 HIGH

A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown function of the file /view_survey.php. Such manipulation of the …

Nov 12, 2025
CVE-2025-13059
6.3 MEDIUM

A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career.php. This manipulation of …

Nov 12, 2025
CVE-2025-13058
3.5 LOW

A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler. The …

Nov 12, 2025
CVE-2025-12048
7.5 HIGH

An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote code execution or …

Nov 12, 2025
CVE-2025-12047
5.3 MEDIUM

A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the …

Nov 12, 2025
CVE-2025-10495
7.5 HIGH

A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, …

Nov 12, 2025
CVE-2024-48829
6.7 MEDIUM

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A high privileged attacker with local …

Nov 12, 2025
CVE-2025-64099

Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_supported" parameter is activated, it is possible, thanks to …

Nov 12, 2025
CVE-2025-63929
7.5 HIGH

A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple threads enqueue elements concurrently via IEC10X_PrioEnQueue, the function may dereference …

Nov 12, 2025
CVE-2025-63927
4.0 MEDIUM

A heap-use-after-free vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). During multi-threaded client execution, the function Iec10x_Scheduled can access memory that has already been …

Nov 12, 2025
CVE-2025-63679
7.5 HIGH

free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.

Nov 12, 2025
CVE-2025-61667

The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65.0 through …

Nov 12, 2025
CVE-2025-60646
6.1 MEDIUM

A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitrary web scripts or HTML via injecting a …

Nov 12, 2025
CVE-2025-57812
3.7 LOW

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be …

Nov 12, 2025
CVE-2025-57310
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admin.php?p=ads&c=1 allowing attackers to execute arbitrary code.

Nov 12, 2025
CVE-2025-56385
9.8 CRITICAL

A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is …

Nov 12, 2025
CVE-2025-13057
6.3 MEDIUM

A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_student. The manipulation of the …

Nov 12, 2025
CVE-2024-47866
7.5 HIGH

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object …

Nov 12, 2025
CVE-2024-45301
5.3 MEDIUM

Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access …

Nov 12, 2025
CVE-2025-65002
7.5 HIGH

Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is exactly 16 characters.

Nov 12, 2025
CVE-2025-65001
8.2 HIGH

Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and availability.

Nov 12, 2025
CVE-2025-63811
7.5 HIGH

An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token …

Nov 12, 2025
CVE-2025-60645
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.

Nov 12, 2025
CVE-2025-25236
5.3 MEDIUM

Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and …

Nov 12, 2025
CVE-2025-20379
3.5 LOW

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503.5 and 10.1.2507.1, a low-privileged user that …

Nov 12, 2025
CVE-2025-20378
3.1 LOW

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.121, an unauthenticated attacker could craft a …

Nov 12, 2025
CVE-2025-63419
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to …

Nov 12, 2025
CVE-2025-59491
6.1 MEDIUM

Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.

Nov 12, 2025
CVE-2025-59089
5.9 MEDIUM

If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact that kdcproxy does …

Nov 12, 2025
CVE-2025-59088
8.6 HIGH

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records …

Nov 12, 2025
CVE-2025-52331
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the computer username, generated …

Nov 12, 2025
CVE-2025-2843
8.8 HIGH

A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue …

Nov 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.