CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40772
7.4 HIGH

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker …

Oct 14, 2025
CVE-2025-40771
9.8 CRITICAL

A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP …

Oct 14, 2025
CVE-2025-40765
9.8 CRITICAL

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This …

Oct 14, 2025
CVE-2025-40755
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated …

Oct 14, 2025
CVE-2025-20724
5.5 MEDIUM

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Oct 14, 2025
CVE-2025-20723
7.8 HIGH

In gnss driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Oct 14, 2025
CVE-2025-20722
5.5 MEDIUM

In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a …

Oct 14, 2025
CVE-2025-20721
7.8 HIGH

In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Oct 14, 2025
CVE-2025-20720
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-20719
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-20718
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20717
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20716
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20715
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20714
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20713
7.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 14, 2025
CVE-2025-20712
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-20711
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-20710
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) escalation of …

Oct 14, 2025
CVE-2025-20709
8.8 HIGH

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation …

Oct 14, 2025
CVE-2025-10228
8.8 HIGH

Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking.This issue affects Agentis: before 4.44.

Oct 14, 2025
CVE-2011-20002
7.4 HIGH

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS …

Oct 14, 2025
CVE-2011-20001
7.5 HIGH

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS …

Oct 14, 2025
CVE-2025-46581
9.8 CRITICAL

ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

Oct 14, 2025
CVE-2025-41718
7.5 HIGH

A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote attacker to gain login credentials and access the Web-UI.

Oct 14, 2025
CVE-2025-41699
8.8 HIGH

An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting …

Oct 14, 2025
CVE-2025-55078
5.5 MEDIUM

In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory …

Oct 14, 2025
CVE-2025-41707
5.3 MEDIUM

The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a crafted websocket message to trigger the issue …

Oct 14, 2025
CVE-2025-41706
5.3 MEDIUM

The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET request with an over-long content-length to …

Oct 14, 2025
CVE-2025-41705
6.8 MEDIUM

An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.

Oct 14, 2025
CVE-2025-41704
5.3 MEDIUM

An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the core functionality.

Oct 14, 2025
CVE-2025-41703
7.5 HIGH

An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command.

Oct 14, 2025
CVE-2025-8594
3.8 LOW

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as …

Oct 14, 2025
CVE-2025-59889
8.6 HIGH

Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the …

Oct 14, 2025
CVE-2025-11731
3.1 LOW

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function …

Oct 14, 2025
CVE-2025-10732
4.3 MEDIUM

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and …

Oct 14, 2025
CVE-2025-10357
6.1 MEDIUM

The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the page, which could allow users with …

Oct 14, 2025
CVE-2025-42939
4.3 MEDIUM

SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any …

Oct 14, 2025
CVE-2025-42937
9.8 CRITICAL

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system …

Oct 14, 2025
CVE-2025-42910
9.0 CRITICAL

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include …

Oct 14, 2025
CVE-2025-42909
3.0 LOW

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances …

Oct 14, 2025
CVE-2025-42908
5.4 MEDIUM

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session …

Oct 14, 2025
CVE-2025-42906
5.3 MEDIUM

SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the …

Oct 14, 2025
CVE-2025-42903
4.3 MEDIUM

A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low …

Oct 14, 2025
CVE-2025-42902
5.3 MEDIUM

Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or …

Oct 14, 2025
CVE-2025-42901
5.4 MEDIUM

SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the …

Oct 14, 2025
CVE-2025-62392
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62391
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62390
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62389
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.