CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60791
6.2 MEDIUM

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory after a …

Oct 27, 2025
CVE-2025-60425
8.6 HIGH

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session …

Oct 27, 2025
CVE-2025-60424
7.6 HIGH

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

Oct 27, 2025
CVE-2025-34133

Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated request that contains a …

Oct 27, 2025
CVE-2025-12294
4.7 MEDIUM

A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /delete_category.php. Performing manipulation of the …

Oct 27, 2025
CVE-2025-12293
7.3 HIGH

A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the file /category.php. Such manipulation of the argument …

Oct 27, 2025
CVE-2025-12292
7.3 HIGH

A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file /index.php. This manipulation of the argument Username …

Oct 27, 2025
CVE-2025-12291
4.7 MEDIUM

A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file /admin/index.php?add_product of the …

Oct 27, 2025
CVE-2025-10023
6.2 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules) allows Stored XSS by users …

Oct 27, 2025
CVE-2023-49440
8.8 HIGH

AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."

Oct 27, 2025
CVE-2023-37749
5.3 MEDIUM

Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.

Oct 27, 2025
CVE-2025-61482
7.2 HIGH

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authentication. By …

Oct 27, 2025
CVE-2025-52268
7.5 HIGH

StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to forge or decrypt valid login tokens.

Oct 27, 2025
CVE-2025-52264
8.0 HIGH

StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at download.cgi.

Oct 27, 2025
CVE-2025-36121
5.4 MEDIUM

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed …

Oct 27, 2025
CVE-2025-34292

Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the …

Oct 27, 2025
CVE-2025-26862

Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.

Oct 27, 2025
CVE-2025-12351
6.8 MEDIUM

Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to …

Oct 27, 2025
CVE-2025-12290
4.3 MEDIUM

A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality …

Oct 27, 2025
CVE-2025-12289
4.3 MEDIUM

A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality …

Oct 27, 2025
CVE-2025-12288
4.3 MEDIUM

A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User …

Oct 27, 2025
CVE-2025-12287
4.7 MEDIUM

A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the …

Oct 27, 2025
CVE-2025-9164

Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder …

Oct 27, 2025
CVE-2025-61481
10.0 CRITICAL

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute …

Oct 27, 2025
CVE-2025-60291
9.1 CRITICAL

An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and …

Oct 27, 2025
CVE-2025-52263
8.0 HIGH

An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-adjacent attackers to upload crafted firmware, leading to …

Oct 27, 2025
CVE-2025-50055
6.4 MEDIUM

Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) …

Oct 27, 2025
CVE-2025-12286
7.0 HIGH

A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. …

Oct 27, 2025
CVE-2025-12283
4.3 MEDIUM

A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results in authorization bypass. …

Oct 27, 2025
CVE-2025-12282
2.4 LOW

A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function of the file /admin/manage-users.php. The manipulation leads to …

Oct 27, 2025
CVE-2025-12281
2.4 LOW

A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executing manipulation can lead to cross …

Oct 27, 2025
CVE-2025-12280
2.4 LOW

A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Performing manipulation results in cross …

Oct 27, 2025
CVE-2025-41384
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include …

Oct 27, 2025
CVE-2025-41068
7.5 HIGH

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is achieved …

Oct 27, 2025
CVE-2025-41067
7.5 HIGH

Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request …

Oct 27, 2025
CVE-2025-12279
2.4 LOW

A vulnerability has been found in code-projects Client Details System 1.0. This vulnerability affects unknown code of the file /welcome.php. Such manipulation leads to cross …

Oct 27, 2025
CVE-2025-12277
7.3 HIGH

A flaw has been found in Abdullah-Hasan-Sajjad Online-School up to f09dda77b4c29aa083ff57f4b1eb991b98b68883. This affects an unknown part of the file /studentLogin.php. This manipulation of the argument …

Oct 27, 2025
CVE-2025-12276
4.3 MEDIUM

A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation results …

Oct 27, 2025
CVE-2025-12274
8.8 HIGH

A security vulnerability has been detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of …

Oct 27, 2025
CVE-2025-12273
8.8 HIGH

A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page …

Oct 27, 2025
CVE-2025-11248
3.2 LOW

ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could …

Oct 27, 2025
CVE-2025-41009

SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data from the database by …

Oct 27, 2025
CVE-2025-12272
8.8 HIGH

A security flaw has been discovered in Tenda CH22 1.0.0.1. This impacts the function fromAddressNat of the file /goform/addressNat. Performing a manipulation of the argument …

Oct 27, 2025
CVE-2025-12271
8.8 HIGH

A vulnerability was identified in Tenda CH22 1.0.0.1. This affects the function fromRouteStatic of the file /goform/RouteStatic. Such manipulation of the argument page leads to …

Oct 27, 2025
CVE-2025-12270
4.3 MEDIUM

A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file /api/v1/assignments/{assignment_id}/tasks/{task_id}/sub_file of the component Student Assignment …

Oct 27, 2025
CVE-2025-12269
3.5 LOW

A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unknown function of the file /dash/org/settings/previews of the component Account Setting …

Oct 27, 2025
CVE-2025-12268
6.3 MEDIUM

A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/courses/ of the component Course Thumbnail Handler. …

Oct 27, 2025
CVE-2025-11955

Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authentication step, the OCSP-enabled VPN client establishes the tunnel …

Oct 27, 2025
CVE-2025-59463
4.3 MEDIUM

An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.

Oct 27, 2025
CVE-2025-59462
6.5 MEDIUM

An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.

Oct 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.