CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48043

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/authorizer/authorizer.ex and program routines 'Elixir.Ash.Policy.Authorizer':strict_filters/2. This issue affects ash: …

Oct 10, 2025
CVE-2025-60869
7.3 HIGH

Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An …

Oct 10, 2025
CVE-2025-60378
8.1 HIGH

Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in …

Oct 10, 2025
CVE-2025-8887
6.1 MEDIUM

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Forceful …

Oct 10, 2025
CVE-2025-8886
6.7 MEDIUM

Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect Authorization vulnerability in Usta Information Systems Inc. Aybs …

Oct 10, 2025
CVE-2025-61319
6.1 MEDIUM

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the …

Oct 10, 2025
CVE-2025-61152
6.5 MEDIUM

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged …

Oct 10, 2025
CVE-2025-60868
6.5 MEDIUM

The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded …

Oct 10, 2025
CVE-2025-62239
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 …

Oct 10, 2025
CVE-2025-62238
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 …

Oct 10, 2025
CVE-2025-62237
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, …

Oct 10, 2025
CVE-2025-7781
6.4 MEDIUM

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘cs_job_title’ parameter in all versions up …

Oct 10, 2025
CVE-2025-7374
5.4 MEDIUM

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This …

Oct 10, 2025
CVE-2025-11579
5.3 MEDIUM

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR …

Oct 10, 2025
CVE-2025-61864
7.8 HIGH

A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's …

Oct 10, 2025
CVE-2025-61863
7.8 HIGH

An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61862
7.8 HIGH

An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61861
7.8 HIGH

An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61860
7.8 HIGH

An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61859
7.8 HIGH

An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61858
7.8 HIGH

An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61857
7.8 HIGH

An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61856
7.8 HIGH

A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's …

Oct 10, 2025
CVE-2025-52635
3.7 LOW

A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-52625
3.7 LOW

A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose credentials, system identifiers, or internal file paths to …

Oct 10, 2025
CVE-2025-52624
5.4 MEDIUM

A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk …

Oct 10, 2025
CVE-2025-11190
5.4 MEDIUM

The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.

Oct 10, 2025
CVE-2025-11189
7.3 HIGH

The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.

Oct 10, 2025
CVE-2025-11188
7.3 HIGH

The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding …

Oct 10, 2025
CVE-2025-52650
8.2 HIGH

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

Oct 10, 2025
CVE-2025-52634
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

Oct 10, 2025
CVE-2025-52632
6.5 MEDIUM

A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-52630
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-41089

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input. To exploit the vulnerability, …

Oct 10, 2025
CVE-2025-41088

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input. To exploit the vulnerability, the …

Oct 10, 2025
CVE-2025-37727
5.7 MEDIUM

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API …

Oct 10, 2025
CVE-2025-30001
7.3 HIGH

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which …

Oct 10, 2025
CVE-2025-25018
8.7 HIGH

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

Oct 10, 2025
CVE-2025-25017
8.2 HIGH

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

Oct 10, 2025
CVE-2025-52655
3.1 LOW

Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code …

Oct 10, 2025
CVE-2025-40640
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of …

Oct 10, 2025
CVE-2025-62292
4.3 MEDIUM

In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, …

Oct 10, 2025
CVE-2025-21070
4.0 MEDIUM

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-21069
4.0 MEDIUM

Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21068
4.0 MEDIUM

Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21067
4.0 MEDIUM

Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21066
4.0 MEDIUM

Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21065
6.6 MEDIUM

Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

Oct 10, 2025
CVE-2025-21064
8.8 HIGH

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

Oct 10, 2025
CVE-2025-21063
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording …

Oct 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.