CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11896

In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stack overflow.

Oct 16, 2025
CVE-2025-11864
7.3 HIGH

A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply of the file /src/cluster.ts of the component Outbound …

Oct 16, 2025
CVE-2024-42192
5.5 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.

Oct 16, 2025
CVE-2025-61554
5.5 MEDIUM

A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of …

Oct 16, 2025
CVE-2025-60358
5.5 MEDIUM

radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

Oct 16, 2025
CVE-2025-62428

Drawing-Captcha APP provides interactive, engaging verification for Web-Based Applications. The vulnerability is a Host Header Injection in the /register and /confirm-email endpoints. It allows an …

Oct 16, 2025
CVE-2025-62427

The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request Forgery (SSRF) flaw within the URL resolution mechanism …

Oct 16, 2025
CVE-2025-62425
8.3 HIGH

MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 …

Oct 16, 2025
CVE-2025-62423
6.7 MEDIUM

ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admin Area’s …

Oct 16, 2025
CVE-2025-62418
6.9 MEDIUM

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to …

Oct 16, 2025
CVE-2025-62417
7.8 HIGH

Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) …

Oct 16, 2025
CVE-2025-62416
5.1 MEDIUM

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by …

Oct 16, 2025
CVE-2025-62415
6.9 MEDIUM

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to …

Oct 16, 2025
CVE-2025-62414
6.9 MEDIUM

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting …

Oct 16, 2025
CVE-2025-61553
8.2 HIGH

An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial …

Oct 16, 2025
CVE-2025-61514
6.5 MEDIUM

An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.

Oct 16, 2025
CVE-2025-60855
5.1 MEDIUM

Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution …

Oct 16, 2025
CVE-2025-34255
5.3 MEDIUM

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether …

Oct 16, 2025
CVE-2025-34254
5.3 MEDIUM

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the …

Oct 16, 2025
CVE-2025-34253
5.4 MEDIUM

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the …

Oct 16, 2025
CVE-2025-11853
6.3 MEDIUM

A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Executing …

Oct 16, 2025
CVE-2025-11852
5.3 MEDIUM

A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the component ONVIF Service. Performing …

Oct 16, 2025
CVE-2025-11493
8.8 HIGH

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a …

Oct 16, 2025
CVE-2025-11492
9.6 CRITICAL

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle …

Oct 16, 2025
CVE-2025-62586
9.8 CRITICAL

OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress version 11.13.2.0.

Oct 16, 2025
CVE-2025-62413
6.1 MEDIUM

MQTTX is an MQTT 5.0 desktop client and MQTT testing tool. A Cross-Site Scripting (XSS) vulnerability was introduced in MQTTX v1.12.0 due to improper handling …

Oct 16, 2025
CVE-2025-62412
3.8 LOW

LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can …

Oct 16, 2025
CVE-2025-62411
5.5 MEDIUM

LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When …

Oct 16, 2025
CVE-2025-62409
7.5 HIGH

Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large requests and responses can potentially trigger TCP …

Oct 16, 2025
CVE-2025-62407
6.1 MEDIUM

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, …

Oct 16, 2025
CVE-2025-61924
3.8 LOW

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking …

Oct 16, 2025
CVE-2025-61923
4.1 MEDIUM

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on …

Oct 16, 2025
CVE-2025-61922
9.1 CRITICAL

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation …

Oct 16, 2025
CVE-2025-61909
4.4 MEDIUM

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) …

Oct 16, 2025
CVE-2025-61908
6.5 MEDIUM

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference …

Oct 16, 2025
CVE-2025-61907
6.5 MEDIUM

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access …

Oct 16, 2025
CVE-2025-61330
6.5 MEDIUM

A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment manufacturer H3C. The vulnerability stems from the use of …

Oct 16, 2025
CVE-2025-60641
6.5 MEDIUM

The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexcel'])), where $_POST['mexcel'] is user-controlled input. This input is decoded from base64 …

Oct 16, 2025
CVE-2025-60639
6.5 MEDIUM

Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).

Oct 16, 2025
CVE-2025-34519
7.5 HIGH

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying …

Oct 16, 2025
CVE-2025-34518
7.5 HIGH

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia …

Oct 16, 2025
CVE-2025-34517
7.5 HIGH

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia …

Oct 16, 2025
CVE-2025-34516
9.8 CRITICAL

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia …

Oct 16, 2025
CVE-2025-34515
9.8 CRITICAL

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in sync_project.sh that allows an attacker to escalate privileges to …

Oct 16, 2025
CVE-2025-34514
8.8 HIGH

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an …

Oct 16, 2025
CVE-2025-34513
9.8 CRITICAL

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. …

Oct 16, 2025
CVE-2025-34512
6.1 MEDIUM

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary …

Oct 16, 2025
CVE-2025-61789
5.3 MEDIUM

Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use …

Oct 16, 2025
CVE-2025-58051
6.5 MEDIUM

Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able …

Oct 16, 2025
CVE-2025-56700
5.4 MEDIUM

Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged user …

Oct 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.