CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62505
3.0 LOW

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. …

Oct 17, 2025
CVE-2025-56320
5.4 MEDIUM

Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary …

Oct 17, 2025
CVE-2025-56316
9.8 CRITICAL

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized …

Oct 17, 2025
CVE-2025-56221
9.8 CRITICAL

A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.

Oct 17, 2025
CVE-2025-56218
9.8 CRITICAL

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Oct 17, 2025
CVE-2025-34282
9.1 CRITICAL

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG …

Oct 17, 2025
CVE-2025-34281
5.4 MEDIUM

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting …

Oct 17, 2025
CVE-2025-11909
6.3 MEDIUM

A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. Executing manipulation …

Oct 17, 2025
CVE-2025-11908
6.3 MEDIUM

A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing …

Oct 17, 2025
CVE-2024-31573
4.0 MEDIUM

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension …

Oct 17, 2025
CVE-2025-62430
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site scripting (XSS) in multiple video and photo …

Oct 17, 2025
CVE-2025-62424
6.7 MEDIUM

ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of …

Oct 17, 2025
CVE-2025-62422
8.8 HIGH

DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker …

Oct 17, 2025
CVE-2025-62421
5.4 MEDIUM

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scripting vulnerability exists due to improper file upload validation …

Oct 17, 2025
CVE-2025-62420
8.8 HIGH

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database connection handler. …

Oct 17, 2025
CVE-2025-62419
7.5 HIGH

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data …

Oct 17, 2025
CVE-2025-60514
6.5 MEDIUM

Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts.

Oct 17, 2025
CVE-2025-57164
6.5 MEDIUM

Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.

Oct 17, 2025
CVE-2025-62171
5.9 MEDIUM

ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer …

Oct 17, 2025
CVE-2025-62168
10.0 CRITICAL

Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows …

Oct 17, 2025
CVE-2025-8414

Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In …

Oct 17, 2025
CVE-2025-62356
7.5 HIGH

A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside …

Oct 17, 2025
CVE-2025-62353
9.8 CRITICAL

A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside …

Oct 17, 2025
CVE-2025-60279
9.6 CRITICAL

A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users to send arbitrary requests to internal services via the API. …

Oct 17, 2025
CVE-2025-59043
7.5 HIGH

OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than …

Oct 17, 2025
CVE-2025-58747
6.1 MEDIUM

Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects …

Oct 17, 2025
CVE-2025-57567
9.1 CRITICAL

A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). …

Oct 17, 2025
CVE-2025-49655
9.8 CRITICAL

Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded …

Oct 17, 2025
CVE-2025-26625

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with …

Oct 17, 2025
CVE-2025-11905
6.3 MEDIUM

A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code …

Oct 17, 2025
CVE-2025-60361
3.3 LOW

radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

Oct 17, 2025
CVE-2025-55085
7.5 HIGH

In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was …

Oct 17, 2025
CVE-2025-48087
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from …

Oct 17, 2025
CVE-2025-11904
6.3 MEDIUM

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument …

Oct 17, 2025
CVE-2025-60360
5.5 MEDIUM

radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.

Oct 17, 2025
CVE-2025-60359
5.5 MEDIUM

radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.

Oct 17, 2025
CVE-2025-48044

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program routines 'Elixir.Ash.Policy.Policy':expression/2. This issue affects ash: …

Oct 17, 2025
CVE-2025-11903
6.3 MEDIUM

A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a …

Oct 17, 2025
CVE-2025-11902
6.3 MEDIUM

A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/findField. Performing a manipulation …

Oct 17, 2025
CVE-2023-28815
9.8 CRITICAL

Some versions of Hikvision's iSecure Center Product contain insufficient parameter validation, resulting in a command injection vulnerability. Attackers may exploit this to gain platform privileges …

Oct 17, 2025
CVE-2023-28814
9.8 CRITICAL

Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to be uploaded, attackers …

Oct 17, 2025
CVE-2025-11895
4.3 MEDIUM

The Binary MLM Plan plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 5.0. This is due to …

Oct 17, 2025
CVE-2025-55100
9.1 CRITICAL

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio10_sam_parse_func() when parsing …

Oct 17, 2025
CVE-2025-55099
6.1 MEDIUM

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing …

Oct 17, 2025
CVE-2025-55098
6.1 MEDIUM

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_device_type_get() when parsing …

Oct 17, 2025
CVE-2025-55097
6.1 MEDIUM

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_streaming_sampling_get() when parsing …

Oct 17, 2025
CVE-2025-55096
6.1 MEDIUM

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_hid_report_descriptor_get() when parsing …

Oct 17, 2025
CVE-2025-55094
7.5 HIGH

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when …

Oct 17, 2025
CVE-2025-55087
7.5 HIGH

In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted …

Oct 17, 2025
CVE-2025-55093
5.3 MEDIUM

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when …

Oct 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.