CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-45378
9.1 CRITICAL

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into command shell of CloudLink server …

Nov 5, 2025
CVE-2025-43990
7.3 HIGH

Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit …

Nov 5, 2025
CVE-2025-30479
8.4 HIGH

Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system.

Nov 5, 2025
CVE-2025-20377
4.3 MEDIUM

A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. …

Nov 5, 2025
CVE-2025-20376
6.5 MEDIUM

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is …

Nov 5, 2025
CVE-2025-20375
6.5 MEDIUM

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is …

Nov 5, 2025
CVE-2025-20374
4.9 MEDIUM

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. …

Nov 5, 2025
CVE-2025-20358
9.4 CRITICAL

A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain …

Nov 5, 2025
CVE-2025-20354
9.8 CRITICAL

A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and …

Nov 5, 2025
CVE-2025-20343
8.6 HIGH

A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote …

Nov 5, 2025
CVE-2025-20305
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This …

Nov 5, 2025
CVE-2025-20304
5.4 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-20303
5.4 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-20289
4.8 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack …

Nov 5, 2025
CVE-2025-63601
9.9 CRITICAL

Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and …

Nov 5, 2025
CVE-2025-61304
9.8 CRITICAL

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.

Nov 5, 2025
CVE-2025-60753
5.5 MEDIUM

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause …

Nov 5, 2025
CVE-2025-57130
8.3 HIGH

An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By …

Nov 5, 2025
CVE-2025-64459
9.1 CRITICAL

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, …

Nov 5, 2025
CVE-2025-64458
7.5 HIGH

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a …

Nov 5, 2025
CVE-2025-61084
7.1 HIGH

MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An …

Nov 5, 2025
CVE-2025-52602
4.2 MEDIUM

HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may …

Nov 5, 2025
CVE-2025-47151
9.8 CRITICAL

A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary …

Nov 5, 2025
CVE-2025-46784
7.5 HIGH

A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, …

Nov 5, 2025
CVE-2025-46705
7.5 HIGH

A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to …

Nov 5, 2025
CVE-2025-46404
7.5 HIGH

A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of …

Nov 5, 2025
CVE-2025-3125
6.7 MEDIUM

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with …

Nov 5, 2025
CVE-2025-12497
8.1 HIGH

The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3.10 via …

Nov 5, 2025
CVE-2025-11745
6.4 MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field through the plugin's 'adinserter' …

Nov 5, 2025
CVE-2025-58337
5.4 MEDIUM

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been …

Nov 5, 2025
CVE-2025-12469
4.3 MEDIUM

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up …

Nov 5, 2025
CVE-2025-12468
5.3 MEDIUM

The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Nov 5, 2025
CVE-2025-12192
5.3 MEDIUM

The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided …

Nov 5, 2025
CVE-2025-11987
6.4 MEDIUM

The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 …

Nov 5, 2025
CVE-2025-11820
6.4 MEDIUM

The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widgets in all versions up to, …

Nov 5, 2025
CVE-2025-55108
10.0 CRITICAL

The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled …

Nov 5, 2025
CVE-2025-12677
5.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the register_api_route() function in …

Nov 5, 2025
CVE-2025-12676
5.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5. This is due to the plugin …

Nov 5, 2025
CVE-2025-12675
4.3 MEDIUM

The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all …

Nov 5, 2025
CVE-2025-12674
9.8 CRITICAL

The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in all versions …

Nov 5, 2025
CVE-2025-10622
8.0 HIGH

A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on …

Nov 5, 2025
CVE-2025-64151
6.7 MEDIUM

Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A user with the write permission on the root directory …

Nov 5, 2025
CVE-2025-62225
6.7 MEDIUM

Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A user with the write permission on the …

Nov 5, 2025
CVE-2025-12388
6.4 MEDIUM

The B Carousel Block – Responsive Image and Content Carousel plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, …

Nov 5, 2025
CVE-2025-12384
8.6 HIGH

The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up …

Nov 5, 2025
CVE-2025-12139
7.5 HIGH

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up …

Nov 5, 2025
CVE-2025-11917
6.4 MEDIUM

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() …

Nov 5, 2025
CVE-2025-11373
4.3 MEDIUM

The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for …

Nov 5, 2025
CVE-2025-6027
6.3 MEDIUM

The Ace User Management WordPress plugin through 2.0.3 does not properly validate that a password reset token is associated with the user who requested it, …

Nov 5, 2025
CVE-2025-21079
7.1 HIGH

Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. …

Nov 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.