CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-55342
5.3 MEDIUM

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

Nov 5, 2025
CVE-2025-55341
6.5 MEDIUM

Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad.

Nov 5, 2025
CVE-2025-43418
4.6 MEDIUM

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and …

Nov 5, 2025
CVE-2025-31954
5.4 MEDIUM

HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive …

Nov 5, 2025
CVE-2025-12745
5.3 MEDIUM

A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The …

Nov 5, 2025
CVE-2025-11093
8.4 HIGH

An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with …

Nov 5, 2025
CVE-2023-43000
8.8 HIGH KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS …

Nov 5, 2025
CVE-2025-56231
9.1 CRITICAL

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

Nov 5, 2025
CVE-2025-10907
8.4 HIGH

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious …

Nov 5, 2025
CVE-2025-10713
6.5 MEDIUM

An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without …

Nov 5, 2025
CVE-2025-63248
7.5 HIGH

DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another questionnaire can enable the …

Nov 5, 2025
CVE-2025-59716
5.3 MEDIUM

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds …

Nov 5, 2025
CVE-2025-57244
5.4 MEDIUM

OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interface. The Name field accepts script tags and the …

Nov 5, 2025
CVE-2025-46424
6.7 MEDIUM

Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerability. A high privileged attacker could potentially exploit this …

Nov 5, 2025
CVE-2025-46366
6.7 MEDIUM

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation or access to the database …

Nov 5, 2025
CVE-2025-46365
5.3 MEDIUM

Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected …

Nov 5, 2025
CVE-2025-46364
9.1 CRITICAL

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain control of …

Nov 5, 2025
CVE-2025-45379
8.4 HIGH

Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell …

Nov 5, 2025
CVE-2025-45378
9.1 CRITICAL

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server …

Nov 5, 2025
CVE-2025-43990
7.3 HIGH

Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit …

Nov 5, 2025
CVE-2025-30479
8.4 HIGH

Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system.

Nov 5, 2025
CVE-2025-20377
4.3 MEDIUM

A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. …

Nov 5, 2025
CVE-2025-20376
6.5 MEDIUM

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is …

Nov 5, 2025
CVE-2025-20375
6.5 MEDIUM

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is …

Nov 5, 2025
CVE-2025-20374
4.9 MEDIUM

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. …

Nov 5, 2025
CVE-2025-20358
9.4 CRITICAL

A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain …

Nov 5, 2025
CVE-2025-20354
9.8 CRITICAL

A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and …

Nov 5, 2025
CVE-2025-20343
8.6 HIGH

A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote …

Nov 5, 2025
CVE-2025-20305
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This …

Nov 5, 2025
CVE-2025-20304
5.4 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-20303
5.4 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-20289
4.8 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-63601
9.9 CRITICAL

Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and …

Nov 5, 2025
CVE-2025-61304
9.8 CRITICAL

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.

Nov 5, 2025
CVE-2025-60753
5.5 MEDIUM

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause …

Nov 5, 2025
CVE-2025-57130
8.3 HIGH

An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By …

Nov 5, 2025
CVE-2025-64459
9.1 CRITICAL

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, …

Nov 5, 2025
CVE-2025-64458
7.5 HIGH

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a …

Nov 5, 2025
CVE-2025-61084
7.1 HIGH

MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An …

Nov 5, 2025
CVE-2025-52602
4.2 MEDIUM

HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may …

Nov 5, 2025
CVE-2025-47151
9.8 CRITICAL

A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary …

Nov 5, 2025
CVE-2025-46784
7.5 HIGH

A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, …

Nov 5, 2025
CVE-2025-46705
7.5 HIGH

A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to …

Nov 5, 2025
CVE-2025-46404
7.5 HIGH

A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of …

Nov 5, 2025
CVE-2025-3125
6.7 MEDIUM

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with …

Nov 5, 2025
CVE-2025-12497
8.1 HIGH

The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3.10 via …

Nov 5, 2025
CVE-2025-11745
6.4 MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' …

Nov 5, 2025
CVE-2025-58337
5.4 MEDIUM

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been …

Nov 5, 2025
CVE-2025-12469
4.3 MEDIUM

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up …

Nov 5, 2025
CVE-2025-12468
5.3 MEDIUM

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Nov 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.