CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12082
7.5 HIGH

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.

Oct 30, 2025
CVE-2025-10931
3.8 LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analytics allows Cross-Site Scripting (XSS).This issue affects Umami Analytics: from 0.0.0 …

Oct 30, 2025
CVE-2025-10930
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Currency allows Cross Site Request Forgery.This issue affects Currency: from 0.0.0 before 3.5.0.

Oct 30, 2025
CVE-2025-10929
5.3 MEDIUM

Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2.

Oct 30, 2025
CVE-2025-10928
6.3 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Access code allows Brute Force.This issue affects Access code: from 0.0.0 before 2.0.5.

Oct 30, 2025
CVE-2025-10927
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Plausible tracking allows Cross-Site Scripting (XSS).This issue affects Plausible tracking: from 0.0.0 …

Oct 30, 2025
CVE-2025-10926
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field allows Cross-Site Scripting (XSS).This issue affects JSON Field: from 0.0.0 …

Oct 30, 2025
CVE-2025-61725
7.5 HIGH

The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.

Oct 29, 2025
CVE-2025-61724
5.3 MEDIUM

The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can …

Oct 29, 2025
CVE-2025-61723
7.5 HIGH

The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM …

Oct 29, 2025
CVE-2025-58189
5.3 MEDIUM

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Oct 29, 2025
CVE-2025-58188
7.5 HIGH

Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. …

Oct 29, 2025
CVE-2025-58187
7.5 HIGH

Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the …

Oct 29, 2025
CVE-2025-58186
5.3 MEDIUM

Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a …

Oct 29, 2025
CVE-2025-58185
5.3 MEDIUM

Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.

Oct 29, 2025
CVE-2025-58183
4.3 MEDIUM

tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive …

Oct 29, 2025
CVE-2025-54549
5.9 MEDIUM

Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

Oct 29, 2025
CVE-2025-54548
4.3 MEDIUM

On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)

Oct 29, 2025
CVE-2025-54547
5.3 MEDIUM

On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform …

Oct 29, 2025
CVE-2025-54546
7.5 HIGH

On affected platforms, restricted users could use SSH port forwarding to access host-internal services

Oct 29, 2025
CVE-2025-54545
7.8 HIGH

On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges.

Oct 29, 2025
CVE-2025-47912
5.3 MEDIUM

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits …

Oct 29, 2025
CVE-2025-11428

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Oct 29, 2025
CVE-2025-61959
5.3 MEDIUM

Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, …

Oct 29, 2025
CVE-2025-54459
7.5 HIGH

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live …

Oct 29, 2025
CVE-2025-9871
7.8 HIGH

Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse …

Oct 29, 2025
CVE-2025-9870
7.8 HIGH

Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. …

Oct 29, 2025
CVE-2025-9869
7.8 HIGH

Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse …

Oct 29, 2025
CVE-2025-60320
6.7 MEDIUM

memoQ 10.1.13.ef1b2b52aae and earlier contains an unquoted service path vulnerability in the memoQ Auto Update Service (memoQauhlp101). The affected service is installed with a path …

Oct 29, 2025
CVE-2025-11466
4.9 MEDIUM

Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is required to …

Oct 29, 2025
CVE-2025-11465
7.8 HIGH

Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. …

Oct 29, 2025
CVE-2025-11464
7.8 HIGH

Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Oct 29, 2025
CVE-2025-11463
7.8 HIGH

Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum …

Oct 29, 2025
CVE-2025-11203
3.5 LOW

LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LiteLLM. Authentication is required to …

Oct 29, 2025
CVE-2025-11202
9.8 CRITICAL

win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of win-cli-mcp-server. Authentication is not …

Oct 29, 2025
CVE-2025-11201
9.8 CRITICAL

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow …

Oct 29, 2025
CVE-2025-11200
9.8 CRITICAL

MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to …

Oct 29, 2025
CVE-2025-10934
7.8 HIGH

GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. …

Oct 29, 2025
CVE-2025-10925
7.8 HIGH

GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. …

Oct 29, 2025
CVE-2025-10924
7.8 HIGH

GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User …

Oct 29, 2025
CVE-2025-10923
7.8 HIGH

GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User …

Oct 29, 2025
CVE-2025-10922
7.8 HIGH

GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. …

Oct 29, 2025
CVE-2025-10921
7.8 HIGH

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. …

Oct 29, 2025
CVE-2025-10920
7.8 HIGH

GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User …

Oct 29, 2025
CVE-2025-64104
7.3 HIGH

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Prior to 2.0.11, LangGraph's SQLite store …

Oct 29, 2025
CVE-2025-64103
9.8 CRITICAL

Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or requireMFAForLocalUsers. If a …

Oct 29, 2025
CVE-2025-64102
9.8 CRITICAL

Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an online brute-force attack on OTP, TOTP, and passwords. …

Oct 29, 2025
CVE-2025-64101
8.1 HIGH

Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, a potential vulnerability exists in ZITADEL's password reset mechanism. ZITADEL utilizes the Forwarded …

Oct 29, 2025
CVE-2025-61876
5.0 MEDIUM

Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user with low privileges to enumerate and access …

Oct 29, 2025
CVE-2018-25120
9.8 CRITICAL

D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test functionality. The web maintenance …

Oct 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.