CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11507
7.3 HIGH

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation …

Oct 8, 2025
CVE-2025-11506
7.3 HIGH

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/search-appointment.php. The …

Oct 8, 2025
CVE-2025-11505
7.3 HIGH

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/new-appointment.php. The manipulation of the argument …

Oct 8, 2025
CVE-2017-20202

Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded …

Oct 8, 2025
CVE-2017-20201

CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry-point loader that diverts execution from __scrt_common_main_seh into a custom loader. That loader decodes …

Oct 8, 2025
CVE-2025-60311
8.8 HIGH

ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page

Oct 8, 2025
CVE-2025-11503
7.3 HIGH

A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing a manipulation of …

Oct 8, 2025
CVE-2025-11495
3.3 LOW

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation …

Oct 8, 2025
CVE-2025-11494
3.3 LOW

A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in …

Oct 8, 2025
CVE-2025-61524
7.2 HIGH

An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of …

Oct 8, 2025
CVE-2025-57457
8.8 HIGH

An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" …

Oct 8, 2025
CVE-2025-11491
6.3 MEDIUM

A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in …

Oct 8, 2025
CVE-2025-11490
6.3 MEDIUM

A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component …

Oct 8, 2025
CVE-2025-9868

Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate …

Oct 8, 2025
CVE-2025-61906
4.3 MEDIUM

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, in some situations, …

Oct 8, 2025
CVE-2025-61788
5.4 MEDIUM

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, the paella would …

Oct 8, 2025
CVE-2025-42706
6.5 MEDIUM

A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, …

Oct 8, 2025
CVE-2025-42701
5.6 MEDIUM

A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, …

Oct 8, 2025
CVE-2025-11489
4.5 MEDIUM

A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads …

Oct 8, 2025
CVE-2025-11488
7.3 HIGH

A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Executing manipulation can lead to …

Oct 8, 2025
CVE-2025-11487
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Farm Management System 1.0. Affected by this issue is some unknown functionality of the file /uploadProduct.php. Performing …

Oct 8, 2025
CVE-2025-9970
7.4 HIGH

Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.

Oct 8, 2025
CVE-2025-53967
8.0 HIGH

Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell …

Oct 8, 2025
CVE-2025-11486
6.3 MEDIUM

A vulnerability was identified in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /buyNow.php. Such manipulation of …

Oct 8, 2025
CVE-2025-11485
2.4 LOW

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user of the file /admin.php of the component Manage Users …

Oct 8, 2025
CVE-2025-11481
6.3 MEDIUM

A flaw has been found in varunsardana004 Blood-Bank-And-Donation-Management-System up to dc9e0393d826fbc85fad9755b5bc12cba1919df2. The impacted element is an unknown function of the file /donate_blood.php. Executing manipulation of …

Oct 8, 2025
CVE-2025-60318
6.1 MEDIUM

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields.

Oct 8, 2025
CVE-2025-5009

In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable public link that contained …

Oct 8, 2025
CVE-2025-59303
6.4 MEDIUM

HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in …

Oct 8, 2025
CVE-2025-36636
4.3 MEDIUM

In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized …

Oct 8, 2025
CVE-2025-61672

Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker …

Oct 8, 2025
CVE-2025-60834
6.5 MEDIUM

A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.

Oct 8, 2025
CVE-2025-60313
6.1 MEDIUM

Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field. This allows a remote attacker …

Oct 8, 2025
CVE-2025-43771
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 …

Oct 8, 2025
CVE-2025-43724
4.4 MEDIUM

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit …

Oct 8, 2025
CVE-2025-11480
7.3 HIGH

A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /register.php. Performing manipulation of the …

Oct 8, 2025
CVE-2025-11479
7.3 HIGH

A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the function insertReservation of the file function.php. Such manipulation of …

Oct 8, 2025
CVE-2025-61183
6.1 MEDIUM

Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the storeAvatar() method of UserBase.php

Oct 8, 2025
CVE-2025-60833
6.5 MEDIUM

An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data.

Oct 8, 2025
CVE-2025-60830
6.5 MEDIUM

redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.

Oct 8, 2025
CVE-2025-60828
6.5 MEDIUM

WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

Oct 8, 2025
CVE-2025-60314
5.4 MEDIUM

Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name …

Oct 8, 2025
CVE-2025-43830
6.1 MEDIUM

Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through …

Oct 8, 2025
CVE-2025-43829
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through …

Oct 8, 2025
CVE-2025-11478
6.3 MEDIUM

A weakness has been identified in SourceCodester Farm Management System 1.0. This issue affects some unknown processing of the file /myCart.php. This manipulation of the …

Oct 8, 2025
CVE-2025-11477
7.3 HIGH

A security flaw has been discovered in SourceCodester Wedding Reservation Management System 1.0. This vulnerability affects unknown code of the file /global.php. The manipulation of …

Oct 8, 2025
CVE-2025-11476
7.3 HIGH

A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument login_username …

Oct 8, 2025
CVE-2025-60299
5.4 MEDIUM

Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through …

Oct 8, 2025
CVE-2025-60298
5.4 MEDIUM

Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject …

Oct 8, 2025
CVE-2025-43821
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through …

Oct 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.