CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-56747
6.5 MEDIUM

Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functions …

Oct 14, 2025
CVE-2025-54892
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules) allows Stored XSS …

Oct 14, 2025
CVE-2025-54891
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Resource access configuration modules) allows Stored XSS …

Oct 14, 2025
CVE-2025-54889
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps manufacturer configuration modules) allows Stored XSS …

Oct 14, 2025
CVE-2025-27906
5.3 MEDIUM

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using an application URL. Application files and folders …

Oct 14, 2025
CVE-2025-10986
4.7 MEDIUM

Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write …

Oct 14, 2025
CVE-2025-10985
7.2 HIGH

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to …

Oct 14, 2025
CVE-2025-10243
7.2 HIGH

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to …

Oct 14, 2025
CVE-2025-10242
7.2 HIGH

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to …

Oct 14, 2025
CVE-2025-0033
6.0 MEDIUM

Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss …

Oct 14, 2025
CVE-2024-44088
6.1 MEDIUM

Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a specially-crafted …

Oct 14, 2025
CVE-2025-47856
7.2 HIGH

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and …

Oct 14, 2025
CVE-2025-33044
7.8 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local …

Oct 14, 2025
CVE-2025-22833
7.3 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by local accessing. Successful exploitation of …

Oct 14, 2025
CVE-2025-22832
7.8 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data …

Oct 14, 2025
CVE-2025-22831
7.8 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data …

Oct 14, 2025
CVE-2025-9178

A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP communication using crafted payloads. The security issue …

Oct 14, 2025
CVE-2025-9177

A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the web …

Oct 14, 2025
CVE-2025-9124

A denial-of-service security issue in the affected product. The security issue stems from a fault occurring when a crafted CIP unconnected explicit message is sent. …

Oct 14, 2025
CVE-2025-9068
7.8 HIGH

A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows …

Oct 14, 2025
CVE-2025-9067
7.8 HIGH

A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair …

Oct 14, 2025
CVE-2025-9066

A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in …

Oct 14, 2025
CVE-2025-9064
9.1 CRITICAL

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file …

Oct 14, 2025
CVE-2025-9063
9.8 CRITICAL

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView …

Oct 14, 2025
CVE-2025-7330
6.5 MEDIUM

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This …

Oct 14, 2025
CVE-2025-7329
4.8 MEDIUM

A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or …

Oct 14, 2025
CVE-2025-7328
9.8 CRITICAL

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result …

Oct 14, 2025
CVE-2025-11721
9.8 CRITICAL

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this …

Oct 14, 2025
CVE-2025-11720
8.1 HIGH

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied …

Oct 14, 2025
CVE-2025-11719
9.8 CRITICAL

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. …

Oct 14, 2025
CVE-2025-11718
6.5 MEDIUM

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in …

Oct 14, 2025
CVE-2025-11717
9.1 CRITICAL

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last …

Oct 14, 2025
CVE-2025-11716
6.5 MEDIUM

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and …

Oct 14, 2025
CVE-2025-11715
8.8 HIGH

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption …

Oct 14, 2025
CVE-2025-11714
8.8 HIGH

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence …

Oct 14, 2025
CVE-2025-11713
8.1 HIGH

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not …

Oct 14, 2025
CVE-2025-11712
6.1 MEDIUM

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served …

Oct 14, 2025
CVE-2025-11711
6.5 MEDIUM

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, …

Oct 14, 2025
CVE-2025-11710
9.8 CRITICAL

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. …

Oct 14, 2025
CVE-2025-11709
9.8 CRITICAL

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability …

Oct 14, 2025
CVE-2025-11708
9.8 CRITICAL

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

Oct 14, 2025
CVE-2025-11498
6.1 MEDIUM

An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling …

Oct 14, 2025
CVE-2025-10610
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure allows …

Oct 14, 2025
CVE-2025-9437

A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability …

Oct 14, 2025
CVE-2025-40812
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The …

Oct 14, 2025
CVE-2025-40811
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The …

Oct 14, 2025
CVE-2025-40810
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The …

Oct 14, 2025
CVE-2025-40809
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The …

Oct 14, 2025
CVE-2025-40774
4.4 MEDIUM

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are …

Oct 14, 2025
CVE-2025-40773
3.5 LOW

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks …

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.