CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12463
9.8 CRITICAL

An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on …

Nov 3, 2025
CVE-2025-11953
9.8 CRITICAL KEV

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that …

Nov 3, 2025
CVE-2025-10280
7.1 HIGH

IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions …

Nov 3, 2025
CVE-2025-63453
9.8 CRITICAL

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php.

Nov 3, 2025
CVE-2025-63452
9.4 CRITICAL

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.

Nov 3, 2025
CVE-2025-63451
9.8 CRITICAL

Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.

Nov 3, 2025
CVE-2025-63450
5.4 MEDIUM

Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.

Nov 3, 2025
CVE-2025-63449
5.4 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.

Nov 3, 2025
CVE-2025-63448
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.

Nov 3, 2025
CVE-2025-63447
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.

Nov 3, 2025
CVE-2025-63446
6.1 MEDIUM

Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php.

Nov 3, 2025
CVE-2025-60785
8.8 HIGH

A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a crafted …

Nov 3, 2025
CVE-2025-60503
8.7 HIGH

A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper …

Nov 3, 2025
CVE-2025-36093
4.8 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in …

Nov 3, 2025
CVE-2025-36092
6.5 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper …

Nov 3, 2025
CVE-2025-36091
4.3 MEDIUM

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due …

Nov 3, 2025
CVE-2025-11761
7.8 HIGH

A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. …

Nov 3, 2025
CVE-2025-8900
9.8 CRITICAL

The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. This is due to the plugin allowing …

Nov 3, 2025
CVE-2025-63443
5.4 MEDIUM

School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.

Nov 3, 2025
CVE-2025-63442
4.6 MEDIUM

Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. The system fails to properly sanitize user input, …

Nov 3, 2025
CVE-2025-60892
6.8 MEDIUM

An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub …

Nov 3, 2025
CVE-2025-45663
6.5 MEDIUM

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

Nov 3, 2025
CVE-2025-29699
6.5 MEDIUM

NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.

Nov 3, 2025
CVE-2024-51317
6.5 MEDIUM

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

Nov 3, 2025
CVE-2025-64294
5.3 MEDIUM

Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through …

Nov 3, 2025
CVE-2025-40107

In the Linux kernel, the following vulnerability has been resolved: can: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled This …

Nov 3, 2025
CVE-2025-12626
4.3 MEDIUM

A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the …

Nov 3, 2025
CVE-2025-0987
9.9 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection.This issue affects CVLand: from 2.1.0 through 20251103. NOTE: The vendor …

Nov 3, 2025
CVE-2025-48397
7.1 HIGH

The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch …

Nov 3, 2025
CVE-2025-48396
8.3 HIGH

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the …

Nov 3, 2025
CVE-2025-12623
3.1 LOW

A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this issue is some unknown functionality of the file fuint-application/src/main/java/com/fuint/module/clientApi/controller/ClientSignController.java of the component …

Nov 3, 2025
CVE-2025-12622
8.8 HIGH

A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument …

Nov 3, 2025
CVE-2025-12619
8.8 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in …

Nov 3, 2025
CVE-2025-12618
8.8 HIGH

A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads …

Nov 3, 2025
CVE-2025-12503
6.5 MEDIUM

EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database …

Nov 3, 2025
CVE-2025-12617
7.3 HIGH

A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument …

Nov 3, 2025
CVE-2025-12616
3.7 LOW

A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in …

Nov 3, 2025
CVE-2025-12615
5.0 MEDIUM

A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of …

Nov 3, 2025
CVE-2025-12614
4.7 MEDIUM

A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of …

Nov 3, 2025
CVE-2025-12612
6.3 MEDIUM

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The …

Nov 3, 2025
CVE-2025-12611
8.8 HIGH

A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads …

Nov 3, 2025
CVE-2025-12610
4.7 MEDIUM

A vulnerability was determined in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/view-progress-report.php. Executing a manipulation of the argument …

Nov 3, 2025
CVE-2025-12609
4.7 MEDIUM

A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing a manipulation …

Nov 3, 2025
CVE-2025-12608
7.3 HIGH

A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing …

Nov 3, 2025
CVE-2025-12607
7.3 HIGH

A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument …

Nov 3, 2025
CVE-2025-12606
7.3 HIGH

A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the …

Nov 3, 2025
CVE-2025-12605
7.3 HIGH

A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument …

Nov 2, 2025
CVE-2025-12604
7.3 HIGH

A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the …

Nov 2, 2025
CVE-2025-12598
4.7 MEDIUM

A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. …

Nov 2, 2025
CVE-2025-12597
4.7 MEDIUM

A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing …

Nov 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.