CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-56699
5.4 MEDIUM

SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary …

Oct 16, 2025
CVE-2025-53092
6.5 MEDIUM

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi …

Oct 16, 2025
CVE-2025-36128
7.5 HIGH

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout …

Oct 16, 2025
CVE-2025-25298
5.3 MEDIUM

Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password …

Oct 16, 2025
CVE-2025-9559
6.5 MEDIUM

Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be …

Oct 16, 2025
CVE-2025-62496
8.8 HIGH

A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an excessively large …

Oct 16, 2025
CVE-2025-62495
8.8 HIGH

An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size. * The regular …

Oct 16, 2025
CVE-2025-62494
8.8 HIGH

A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if the …

Oct 16, 2025
CVE-2025-62493
6.5 MEDIUM

A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required number of digits, which in …

Oct 16, 2025
CVE-2025-62492
6.5 MEDIUM

A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied. * The …

Oct 16, 2025
CVE-2025-62491
8.8 HIGH

A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promises (ts->rejected_promise_list). * The function …

Oct 16, 2025
CVE-2025-62490
8.8 HIGH

In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a …

Oct 16, 2025
CVE-2025-55035
6.1 MEDIUM

Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication …

Oct 16, 2025
CVE-2025-11851
3.5 LOW

A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set_alias.cgi. Such manipulation of the argument …

Oct 16, 2025
CVE-2025-11842
6.3 MEDIUM

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handler. The …

Oct 16, 2025
CVE-2025-11840
3.3 LOW

A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead …

Oct 16, 2025
CVE-2024-56143
8.2 HIGH

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not …

Oct 16, 2025
CVE-2025-61543
7.1 HIGH

A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent …

Oct 16, 2025
CVE-2025-61541
7.1 HIGH

Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the …

Oct 16, 2025
CVE-2025-61540
6.5 MEDIUM

SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.

Oct 16, 2025
CVE-2025-61539
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.

Oct 16, 2025
CVE-2025-61536
8.2 HIGH

FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` …

Oct 16, 2025
CVE-2025-41254
4.3 MEDIUM

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: …

Oct 16, 2025
CVE-2025-41253
7.5 HIGH

The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An …

Oct 16, 2025
CVE-2025-36002
5.5 MEDIUM

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files …

Oct 16, 2025
CVE-2025-22381
8.2 HIGH

Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.

Oct 16, 2025
CVE-2025-54658
7.8 HIGH

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS 11.5.1 and 11.4.2 …

Oct 16, 2025
CVE-2025-53951
5.3 MEDIUM

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for Windows 11.5.1 and 11.4.2 …

Oct 16, 2025
CVE-2025-53950
5.5 MEDIUM

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 …

Oct 16, 2025
CVE-2025-46752
4.4 MEDIUM

A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the …

Oct 16, 2025
CVE-2025-11839
3.3 LOW

A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked …

Oct 16, 2025
CVE-2025-9955
5.7 MEDIUM

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs …

Oct 16, 2025
CVE-2025-9804
9.6 CRITICAL

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. …

Oct 16, 2025
CVE-2025-9152
9.8 CRITICAL

An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint. …

Oct 16, 2025
CVE-2025-10611
9.8 CRITICAL

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to …

Oct 16, 2025
CVE-2025-3930

Strapi uses JSON Web Tokens (JWT) for authentication. After logout or account deactivation, the JWT is not invalidated, which allows an attacker who has stolen …

Oct 16, 2025
CVE-2025-6338

There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This …

Oct 16, 2025
CVE-2025-58426
4.3 MEDIUM

desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applications.

Oct 16, 2025
CVE-2025-58079
4.3 MEDIUM

Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.

Oct 16, 2025
CVE-2025-55072
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-54859
4.8 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-54760
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-52583
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-24833
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-61581
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. People with access …

Oct 16, 2025
CVE-2025-58115
6.1 MEDIUM

ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be executed on the web browser of the user …

Oct 16, 2025
CVE-2025-58075
8.1 HIGH

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the …

Oct 16, 2025
CVE-2025-58073
8.1 HIGH

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the …

Oct 16, 2025
CVE-2025-54539
9.8 CRITICAL

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up …

Oct 16, 2025
CVE-2025-54499
3.1 LOW

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to …

Oct 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.