CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9553
5.3 MEDIUM

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

Oct 10, 2025
CVE-2025-9552
5.3 MEDIUM

Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With Contrib Modules: *.*.

Oct 10, 2025
CVE-2025-9551
6.5 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.This issue affects Protected Pages: from 0.0.0 before 1.8.0, from 7.X-1.0 before …

Oct 10, 2025
CVE-2025-9550
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.10, …

Oct 10, 2025
CVE-2025-9549
6.5 MEDIUM

Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.

Oct 10, 2025
CVE-2025-8093
8.8 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.

Oct 10, 2025
CVE-2025-62162
7.5 HIGH

cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.11.4, parsing certain malformed CEL expressions can …

Oct 10, 2025
CVE-2025-62159

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider …

Oct 10, 2025
CVE-2025-52885

Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior …

Oct 10, 2025
CVE-2025-52647
6.1 MEDIUM

The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks.

Oct 10, 2025
CVE-2025-11626
5.5 MEDIUM

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

Oct 10, 2025
CVE-2025-61912
5.3 MEDIUM

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash …

Oct 10, 2025
CVE-2025-61911
6.5 MEDIUM

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to …

Oct 10, 2025
CVE-2025-11589
6.3 MEDIUM

A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/user-payment.php. Performing a manipulation of …

Oct 10, 2025
CVE-2025-11588
6.3 MEDIUM

A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /customer/index.php. Such manipulation of the argument fullname …

Oct 10, 2025
CVE-2025-11586
8.8 HIGH

A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based …

Oct 10, 2025
CVE-2025-11585
7.3 HIGH

A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the …

Oct 10, 2025
CVE-2025-11584
7.3 HIGH

A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation …

Oct 10, 2025
CVE-2025-62245
4.3 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update …

Oct 10, 2025
CVE-2025-62158
5.3 MEDIUM

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by …

Oct 10, 2025
CVE-2025-61930
8.1 HIGH

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change …

Oct 10, 2025
CVE-2025-61929
9.6 CRITICAL

Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation …

Oct 10, 2025
CVE-2025-61927

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower contains a security vulnerability that …

Oct 10, 2025
CVE-2025-61925
6.5 MEDIUM

Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any validation. It is …

Oct 10, 2025
CVE-2025-61921
7.5 HIGH

Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the …

Oct 10, 2025
CVE-2025-61920
7.5 HIGH

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature …

Oct 10, 2025
CVE-2025-61919
7.5 HIGH

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: …

Oct 10, 2025
CVE-2025-55903
8.3 HIGH

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate …

Oct 10, 2025
CVE-2025-11583
7.3 HIGH

A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjob.php. Executing manipulation of the …

Oct 10, 2025
CVE-2025-11582
7.3 HIGH

A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing of the file /registration.php. Performing manipulation of the …

Oct 10, 2025
CVE-2025-61505
6.5 MEDIUM

e107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in the `previous_steps` POST parameter using `unserialize(base64_decode())` …

Oct 10, 2025
CVE-2025-60880
8.3 HIGH

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing …

Oct 10, 2025
CVE-2025-11581
5.3 MEDIUM

A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such …

Oct 10, 2025
CVE-2025-60838
6.5 MEDIUM

An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

Oct 10, 2025
CVE-2025-60268
6.5 MEDIUM

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An …

Oct 10, 2025
CVE-2025-23309
8.2 HIGH

NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of service, escalation of privileges, code execution, and …

Oct 10, 2025
CVE-2025-23282
7.0 HIGH

NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit …

Oct 10, 2025
CVE-2025-23280
7.0 HIGH

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code …

Oct 10, 2025
CVE-2025-11618
4.3 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect …

Oct 10, 2025
CVE-2025-11617
5.4 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths …

Oct 10, 2025
CVE-2025-11616
5.4 MEDIUM

A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which …

Oct 10, 2025
CVE-2025-11580
5.3 MEDIUM

A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The …

Oct 10, 2025
CVE-2025-61780
5.8 MEDIUM

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running …

Oct 10, 2025
CVE-2025-61689

HTTP.jl is an HTTP client and server functionality for the Julia programming language. Prior to version 1.10.19, HTTP.jl did not validate header names/values for illegal …

Oct 10, 2025
CVE-2025-60308
4.1 MEDIUM

code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room function of the online hotel reservation system. …

Oct 10, 2025
CVE-2025-60306
9.9 CRITICAL

code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.

Oct 10, 2025
CVE-2025-60269
9.4 CRITICAL

JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.

Oct 10, 2025
CVE-2025-60307
9.8 CRITICAL

code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass …

Oct 10, 2025
CVE-2025-60305
8.8 HIGH

SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge …

Oct 10, 2025
CVE-2025-59530
7.5 HIGH

quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause …

Oct 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.