CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59461
7.6 HIGH

A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

Oct 27, 2025
CVE-2025-59460
7.5 HIGH

The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases …

Oct 27, 2025
CVE-2025-59459
5.5 MEDIUM

An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.

Oct 27, 2025
CVE-2025-12267
4.3 MEDIUM

A flaw has been found in abhicodebox ModernShop 20250922. This issue affects some unknown processing of the file /search. Executing manipulation of the argument q …

Oct 27, 2025
CVE-2025-12266
6.3 MEDIUM

A vulnerability was detected in Zytec Dalian Zhuoyun Technology Central Authentication Service up to 20251009. This vulnerability affects the function _empty of the file /index.php/auth/widget. …

Oct 27, 2025
CVE-2025-12265
8.8 HIGH

A weakness has been identified in Tenda CH22 1.0.0.1. Affected by this issue is the function fromVirtualSer of the file /goform/VirtualSer. This manipulation of the …

Oct 27, 2025
CVE-2025-12264
3.5 LOW

A security flaw has been discovered in Wisencode up to 20251012. Affected by this vulnerability is an unknown functionality of the file /support-ticket/create of the …

Oct 27, 2025
CVE-2025-12263
6.3 MEDIUM

A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /edit_judge.php. The manipulation of the argument …

Oct 27, 2025
CVE-2025-12262
6.3 MEDIUM

A vulnerability was determined in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /edit_criteria.php. Executing manipulation of the argument …

Oct 27, 2025
CVE-2025-8432
8.4 HIGH

Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue …

Oct 27, 2025
CVE-2025-46583
5.3 MEDIUM

There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service …

Oct 27, 2025
CVE-2025-12261
6.3 MEDIUM

A vulnerability was found in CodeAstro Gym Management System 1.0. This affects an unknown function of the file /admin/actions/remove-announcement.php. Performing a manipulation of the argument …

Oct 27, 2025
CVE-2025-12260
8.8 HIGH

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter …

Oct 27, 2025
CVE-2025-12259
8.8 HIGH

A flaw has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter …

Oct 27, 2025
CVE-2025-12258
8.8 HIGH

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. Impacted is the function setOpModeCfg of the file /cgi-bin/cstecgi.cg of the component POST Parameter Handler. The manipulation …

Oct 27, 2025
CVE-2025-12257
7.3 HIGH

A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some unknown processing of the file /view_result.php. The manipulation …

Oct 27, 2025
CVE-2025-12256
6.3 MEDIUM

A weakness has been identified in code-projects Online Event Judging System 1.0. This vulnerability affects unknown code of the file /edit_contestant.php. Executing manipulation of the …

Oct 27, 2025
CVE-2025-10561

Rejected reason: This CVE ID was assigned in error. The End-of-Life status of a component, by itself, does not constitute a vulnerability under the CVE …

Oct 27, 2025
CVE-2025-46582
7.7 HIGH

A private key disclosure vulnerability exists in ZTE's ZXMP M721 product. A low-privileged user can bypass authorization checks to view the device's communication private key, …

Oct 27, 2025
CVE-2025-12255
6.3 MEDIUM

A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown part of the file /add_contestant.php. Performing manipulation of …

Oct 27, 2025
CVE-2025-12254
6.3 MEDIUM

A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected by this issue is some unknown functionality of the file /add_judge.php. Such manipulation …

Oct 27, 2025
CVE-2025-12253
7.3 HIGH

A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/portal/get_expiredtime.php. This manipulation …

Oct 27, 2025
CVE-2025-12252
6.3 MEDIUM

A vulnerability was found in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /ajax/action.php. The manipulation of the argument …

Oct 27, 2025
CVE-2025-12251
3.5 LOW

A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI. The manipulation leads to cross …

Oct 27, 2025
CVE-2025-12250
4.7 MEDIUM

A flaw has been found in OpenWGA 7.11.12 Build 737. This affects an unknown function of the file WGA.File of the component TMLScript API. Executing …

Oct 27, 2025
CVE-2025-12080

On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SENDTO intents utilizing the sms:, smsto:, mms:, and …

Oct 27, 2025
CVE-2025-12249
6.3 MEDIUM

A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. The impacted element is an unknown function of the component Edit Ticket Page. Performing …

Oct 27, 2025
CVE-2025-12248
7.3 HIGH

A security vulnerability has been detected in CLTPHP 3.0. The affected element is an unknown function of the file /home/search.html. Such manipulation of the argument …

Oct 27, 2025
CVE-2025-12247
7.0 HIGH

A weakness has been identified in Hasleo Backup Suite up to 5.2. Impacted is an unknown function of the component HasleoImageMountService/HasleoBackupSuiteService. This manipulation causes unquoted …

Oct 27, 2025
CVE-2025-12246
4.3 MEDIUM

A security flaw has been discovered in chatwoot up to 4.7.0. This issue affects some unknown processing of the file app/javascript/shared/components/IframeLoader.vue of the component Admin …

Oct 27, 2025
CVE-2025-12245
5.3 MEDIUM

A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation …

Oct 27, 2025
CVE-2025-12244
4.3 MEDIUM

A vulnerability was determined in code-projects Simple E-Banking System 1.0. This affects an unknown part of the file /eBank/register.php. Executing manipulation of the argument Username …

Oct 27, 2025
CVE-2025-11682

Stored cross-site scripting (XSS) vulnerability in the LMT Dashboard of the Perx Customer Engagement & Loyalty Platform allows an authenticated attacker to execute arbitrary JavaScript …

Oct 27, 2025
CVE-2025-12243
6.3 MEDIUM

A vulnerability was found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the file clientdetails/welcome.php of the component …

Oct 27, 2025
CVE-2025-12242
6.3 MEDIUM

A vulnerability has been found in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/actions/check-attendance.php. Such manipulation …

Oct 27, 2025
CVE-2025-12241
8.8 HIGH

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This impacts the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter Handler. The manipulation …

Oct 27, 2025
CVE-2025-12240
8.8 HIGH

A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip …

Oct 27, 2025
CVE-2025-12239
8.8 HIGH

A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Executing manipulation can lead to …

Oct 27, 2025
CVE-2025-12238
6.3 MEDIUM

A security flaw has been discovered in code-projects Automated Voting System 1.0. The affected element is an unknown function of the file /admin/user.php. Performing manipulation …

Oct 27, 2025
CVE-2025-12237
7.3 HIGH

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /index.php. Such manipulation of the argument …

Oct 27, 2025
CVE-2025-12236
8.8 HIGH

A vulnerability was determined in Tenda CH22 1.0.0.1. This issue affects the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes …

Oct 27, 2025
CVE-2025-12235
8.0 HIGH

A vulnerability was found in Tenda CH22 1.0.0.1. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results …

Oct 27, 2025
CVE-2025-12234
8.8 HIGH

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads …

Oct 27, 2025
CVE-2025-12233
8.8 HIGH

A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of …

Oct 27, 2025
CVE-2025-12232
8.8 HIGH

A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the …

Oct 27, 2025
CVE-2025-12055
7.5 HIGH

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack …

Oct 27, 2025
CVE-2025-12231
2.4 LOW

A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense …

Oct 27, 2025
CVE-2025-12230
2.4 LOW

A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. …

Oct 27, 2025
CVE-2025-12229
2.4 LOW

A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles …

Oct 27, 2025
CVE-2025-12228
2.4 LOW

A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown function of the file /public/admin/users/create of the component Users …

Oct 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.