CVE Database

46976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-15106
6.3 MEDIUM

A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the file server/src/routes/auth.ts of the component …

Dec 27, 2025
CVE-2025-68927
6.1 MEDIUM

Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding …

Dec 27, 2025
CVE-2025-68148
4.3 MEDIUM

FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy modifying to …

Dec 27, 2025
CVE-2025-66737
4.3 MEDIUM

Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function …

Dec 26, 2025
CVE-2024-42718
6.5 MEDIUM

A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.

Dec 26, 2025
CVE-2025-67013
6.5 MEDIUM

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms …

Dec 26, 2025
CVE-2024-29720
5.5 MEDIUM

An issue in Terra Informatica Software, Inc Sciter v.4.4.7.0 allows a local attacker to obtain sensitive information via the adopt component of the Sciter video …

Dec 26, 2025
CVE-2025-67349
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigating to the "Add Page" function, the application …

Dec 26, 2025
CVE-2025-66947
6.5 MEDIUM

SQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter. An attacker can trigger controlled delays using SQL SLEEP() to …

Dec 26, 2025
CVE-2025-65885
5.1 MEDIUM

An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia …

Dec 26, 2025
CVE-2025-36230
5.4 MEDIUM

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be …

Dec 26, 2025
CVE-2025-36192
6.7 MEDIUM

IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user …

Dec 26, 2025
CVE-2025-14687
4.3 MEDIUM

IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

Dec 26, 2025
CVE-2025-1721
5.9 MEDIUM

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Dec 26, 2025
CVE-2025-59888
6.7 MEDIUM

Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to …

Dec 26, 2025
CVE-2025-8075
5.4 MEDIUM

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format …

Dec 26, 2025
CVE-2025-68946
5.4 MEDIUM

In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.

Dec 26, 2025
CVE-2025-52599
6.5 MEDIUM

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered Inadequate of permission management for camera …

Dec 26, 2025
CVE-2025-68945
5.8 MEDIUM

In Gitea before 1.21.2, an anonymous user can visit a private user's project.

Dec 26, 2025
CVE-2025-68944
5.0 MEDIUM

Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

Dec 26, 2025
CVE-2025-68943
5.3 MEDIUM

Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

Dec 26, 2025
CVE-2025-68942
5.4 MEDIUM

Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

Dec 26, 2025
CVE-2025-68941
4.9 MEDIUM

Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

Dec 26, 2025
CVE-2025-15098
6.3 MEDIUM

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the …

Dec 26, 2025
CVE-2025-68938
4.3 MEDIUM

Gitea before 1.25.2 mishandles authorization for deletion of releases.

Dec 26, 2025
CVE-2025-15094
4.3 MEDIUM

A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component …

Dec 26, 2025
CVE-2025-15093
4.3 MEDIUM

A security flaw has been discovered in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The affected element is an unknown function of the file src/main/java/com/flycms/web/system/IndexAdminController.java of the …

Dec 26, 2025
CVE-2025-14913
5.3 MEDIUM

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to an incorrect …

Dec 26, 2025
CVE-2025-15088
6.3 MEDIUM

A vulnerability was detected in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is the function postilService.loadPostils of the file /je/postil/postil/loadPostil. Performing a manipulation …

Dec 25, 2025
CVE-2025-15087
4.3 MEDIUM

A security vulnerability has been detected in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function submitOrderPayment of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java. Such manipulation of the argument orderSn …

Dec 25, 2025
CVE-2025-15086
4.3 MEDIUM

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation causes improper access controls. The …

Dec 25, 2025
CVE-2025-68936
6.4 MEDIUM

ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.

Dec 25, 2025
CVE-2025-68935
6.4 MEDIUM

ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.

Dec 25, 2025
CVE-2025-15085
4.3 MEDIUM

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balance Handler. The …

Dec 25, 2025
CVE-2025-15082
5.3 MEDIUM

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management …

Dec 25, 2025
CVE-2025-15081
6.3 MEDIUM

A vulnerability has been found in JD Cloud BE6500 4.4.1.r4308. This issue affects the function sub_4780 of the file /jdcapi. Such manipulation of the argument …

Dec 25, 2025
CVE-2025-66378
5.9 MEDIUM

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams traversing a Proxy …

Dec 25, 2025
CVE-2025-49088
5.9 MEDIUM

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in …

Dec 25, 2025
CVE-2025-68919
5.6 MEDIUM

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority …

Dec 24, 2025
CVE-2025-68917
6.4 MEDIUM

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

Dec 24, 2025
CVE-2025-68915
5.5 MEDIUM

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.

Dec 24, 2025
CVE-2025-68914
6.5 MEDIUM

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.

Dec 24, 2025
CVE-2019-25257
6.5 MEDIUM

LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these …

Dec 24, 2025
CVE-2019-25256
6.5 MEDIUM

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers to access arbitrary system files through unvalidated 'ID' parameters. Attackers …

Dec 24, 2025
CVE-2019-25255
4.3 MEDIUM

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can …

Dec 24, 2025
CVE-2019-25252
4.3 MEDIUM

Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft malicious …

Dec 24, 2025
CVE-2019-25251
6.5 MEDIUM

Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers …

Dec 24, 2025
CVE-2019-25250
5.3 MEDIUM

Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can …

Dec 24, 2025
CVE-2019-25247
5.3 MEDIUM

Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers …

Dec 24, 2025
CVE-2019-25244
5.3 MEDIUM

Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site …

Dec 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.