CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59981
6.1 MEDIUM

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in …

Oct 9, 2025
CVE-2025-59980
6.5 MEDIUM

An Authentication Bypass by Primary Weakness in the FTP server of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to get limited read-write access …

Oct 9, 2025
CVE-2025-59978
9.0 CRITICAL

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly …

Oct 9, 2025
CVE-2025-11549
8.8 HIGH

A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request …

Oct 9, 2025
CVE-2025-11371
7.5 HIGH KEV

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system …

Oct 9, 2025
CVE-2017-20203

NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a …

Oct 9, 2025
CVE-2025-61577
7.5 HIGH

D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the dir_setWanWifi function. This vulnerability allows attackers to cause a Denial …

Oct 9, 2025
CVE-2025-61532
6.1 MEDIUM

Cross Site Scripting vulnerability in SVX Portal v.2.7A to execute arbitrary code via the TG parameter on last_heard_page.php component

Oct 9, 2025
CVE-2025-60302
6.1 MEDIUM

code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code …

Oct 9, 2025
CVE-2025-60265
6.5 MEDIUM

In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in user/list is not securely filtered, resulting in a SQL injection …

Oct 9, 2025
CVE-2025-59976
6.5 MEDIUM

An arbitrary file download vulnerability in the web interface of Juniper Networks Junos Space allows a network-based authenticated attacker using a crafted GET method to …

Oct 9, 2025
CVE-2025-59975
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based attacker flooding the device with inbound …

Oct 9, 2025
CVE-2025-59974
8.4 HIGH

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into …

Oct 9, 2025
CVE-2025-59968
8.6 HIGH

A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web …

Oct 9, 2025
CVE-2025-59967
6.5 MEDIUM

A NULL Pointer Dereference vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved on ACX7024, ACX7024X, ACX7100-32C, ACX7100-48L, ACX7348, ACX7509 devices …

Oct 9, 2025
CVE-2025-59964
7.5 HIGH

A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4700 devices allows an unauthenticated, network-based attacker …

Oct 9, 2025
CVE-2025-59962
5.3 MEDIUM

An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured …

Oct 9, 2025
CVE-2025-59958
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on PTX Series allows …

Oct 9, 2025
CVE-2025-59957
6.8 MEDIUM

An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series and QFX5000 Series allows an unauthenticated attacker …

Oct 9, 2025
CVE-2025-56426
6.5 MEDIUM

An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to …

Oct 9, 2025
CVE-2025-52961
6.5 MEDIUM

An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivity Fault Management Manager (cfmman) of Juniper Networks Junos OS Evolved …

Oct 9, 2025
CVE-2025-52960
5.9 MEDIUM

A Buffer Copy without Checking Size of Input vulnerability in the Session Initialization Protocol (SIP) ALG of Juniper Networks Junos OS on MX Series and …

Oct 9, 2025
CVE-2025-11198
7.4 HIGH

A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allows an unauthenticated, network-based attacker to replace legitimate vSRX images with …

Oct 9, 2025
CVE-2025-10284
9.6 CRITICAL

BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code …

Oct 9, 2025
CVE-2025-10283
9.6 CRITICAL

BBOT's gitdumper module could be abused to execute commands through a malicious git repository.

Oct 9, 2025
CVE-2025-10282
4.7 MEDIUM

BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.

Oct 9, 2025
CVE-2025-10281
4.7 MEDIUM

BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL.

Oct 9, 2025
CVE-2025-56683
9.6 CRITICAL

A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to execute arbitrary code via injecting arbitrary Javascript into a crafted …

Oct 9, 2025
CVE-2025-45095
7.3 HIGH

Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unquoted service path vulnerability. An attacker with …

Oct 9, 2025
CVE-2025-39664
6.5 MEDIUM

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file …

Oct 9, 2025
CVE-2025-32919
7.8 HIGH

Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 …

Oct 9, 2025
CVE-2025-32916
4.3 MEDIUM

Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to …

Oct 9, 2025
CVE-2025-62228
8.8 HIGH

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through …

Oct 9, 2025
CVE-2025-36225
4.3 MEDIUM

IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.

Oct 9, 2025
CVE-2025-36171
4.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive …

Oct 9, 2025
CVE-2025-11561
8.8 HIGH

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos …

Oct 9, 2025
CVE-2023-37401
5.3 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.

Oct 9, 2025
CVE-2025-39963
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix incorrect io_kiocb reference in io_link_skb In io_link_skb function, there is a bug where …

Oct 9, 2025
CVE-2025-39962
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix untrusted unsigned subtract Fix the following Smatch static checker warning: net/rxrpc/rxgk_app.c:65 rxgk_yfs_decode_ticket() warn: …

Oct 9, 2025
CVE-2025-39961
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase page table level The AMD IOMMU host page table …

Oct 9, 2025
CVE-2025-39960
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: gpiolib: acpi: initialize acpi_gpio_info struct Since commit 7c010d463372 ("gpiolib: acpi: Make sure we fill struct …

Oct 9, 2025
CVE-2025-10240
8.8 HIGH

A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a malicious link provided by an attacker …

Oct 9, 2025
CVE-2025-10239
7.2 HIGH

In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privileges and access to the management interface to …

Oct 9, 2025
CVE-2025-9371
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versions up to, and including, 28.1.6 due to …

Oct 9, 2025
CVE-2025-2934
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 …

Oct 9, 2025
CVE-2025-11340
7.7 HIGH

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed …

Oct 9, 2025
CVE-2025-10249
6.5 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in …

Oct 9, 2025
CVE-2025-10004
7.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make …

Oct 9, 2025
CVE-2025-39959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix incorrect retrival of acp_chip_info Use dev_get_drvdata(dev->parent) instead of dev_get_platdata(dev) to correctly …

Oct 9, 2025
CVE-2025-39958
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Make attach succeed when the device was surprise removed When a PCI device is …

Oct 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.