CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11475
7.3 HIGH

A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing a …

Oct 8, 2025
CVE-2025-11474
6.3 MEDIUM

A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_booking.php. Performing …

Oct 8, 2025
CVE-2025-11473
7.3 HIGH

A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /edit_curr.php. Such manipulation of …

Oct 8, 2025
CVE-2025-11472
7.3 HIGH

A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the file /edit_room.php. This manipulation of …

Oct 8, 2025
CVE-2025-11471
7.3 HIGH

A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function of the file /edit_customer.php. The manipulation of the …

Oct 8, 2025
CVE-2025-10649
6.5 MEDIUM

The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and including, 2.11.21 due to insufficient …

Oct 8, 2025
CVE-2025-10353

File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a …

Oct 8, 2025
CVE-2025-10352

Vulnerability in the melis-core module of Melis Technology's Melis Platform, which, if exploited, allows an unauthenticated attacker to create an administrator account via a request …

Oct 8, 2025
CVE-2025-10351

SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and …

Oct 8, 2025
CVE-2025-11470
4.7 MEDIUM

A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted element is an unknown function of the …

Oct 8, 2025
CVE-2025-11469
6.3 MEDIUM

A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /pages/save_customer.php. Executing …

Oct 8, 2025
CVE-2025-11445
6.3 MEDIUM

A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing …

Oct 8, 2025
CVE-2025-11444
8.8 HIGH

A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the component HTTP …

Oct 8, 2025
CVE-2025-11443
3.7 LOW

A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forgotten Password …

Oct 8, 2025
CVE-2025-11442
4.3 MEDIUM

A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3. The impacted element is an unknown function of the component API Endpoint. The …

Oct 8, 2025
CVE-2025-48464
4.7 MEDIUM

Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email …

Oct 8, 2025
CVE-2025-11441
3.7 LOW

A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the component HTTP Header Handler. The manipulation …

Oct 8, 2025
CVE-2025-11440
4.3 MEDIUM

A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Executing manipulation can lead to improper …

Oct 8, 2025
CVE-2025-11439
4.3 MEDIUM

A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/integrations. Performing manipulation results in missing …

Oct 8, 2025
CVE-2025-11438
6.3 MEDIUM

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. …

Oct 8, 2025
CVE-2025-11437
2.4 LOW

A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the component Form Editor. …

Oct 8, 2025
CVE-2025-11436
6.3 MEDIUM

A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulation results …

Oct 8, 2025
CVE-2025-11435
4.3 MEDIUM

A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /show/submissions. The …

Oct 8, 2025
CVE-2025-11171
5.3 MEDIUM

The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This …

Oct 8, 2025
CVE-2025-10635
7.7 HIGH

The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and …

Oct 8, 2025
CVE-2025-11434
7.3 HIGH

A weakness has been identified in itsourcecode Student Transcript Processing System 1.0. Affected is an unknown function of the file /login.php. Executing a manipulation of …

Oct 8, 2025
CVE-2025-11433
3.5 LOW

A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/controller.php?action=reset of the component Query …

Oct 8, 2025
CVE-2025-11432
7.3 HIGH

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid …

Oct 8, 2025
CVE-2025-11204
7.2 HIGH

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to SQL Injection in all versions up to, …

Oct 8, 2025
CVE-2025-11431
6.3 MEDIUM

A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. The impacted element is an unknown function of the file /transaction.php. This manipulation …

Oct 8, 2025
CVE-2025-11430
7.3 HIGH

A vulnerability was found in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /cart.php. The manipulation of the …

Oct 8, 2025
CVE-2025-10587
9.8 CRITICAL

The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to …

Oct 8, 2025
CVE-2025-10494
8.1 HIGH

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when …

Oct 8, 2025
CVE-2025-11426
6.3 MEDIUM

A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_book.php. …

Oct 8, 2025
CVE-2025-11425
2.4 LOW

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /edit_admin.php. The manipulation of the argument …

Oct 8, 2025
CVE-2025-61787
8.1 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch …

Oct 8, 2025
CVE-2025-11424
7.3 HIGH

A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. This impacts an unknown function of the file /login.php. Executing manipulation of the …

Oct 8, 2025
CVE-2025-11423
9.8 CRITICAL

A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results …

Oct 8, 2025
CVE-2025-11422
7.3 HIGH

A vulnerability has been found in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unknown function of the file /admin/login.php. Such …

Oct 8, 2025
CVE-2025-11421
3.5 LOW

A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin/candidates_edit.php. This manipulation of the …

Oct 8, 2025
CVE-2025-61786
3.3 LOW

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.stat` and `Deno.FsFile.prototype.statSync` are not limited by the permission model …

Oct 8, 2025
CVE-2025-61785
3.3 LOW

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.utime` and `Deno.FsFile.prototype.utimeSync` are not limited by the permission model …

Oct 8, 2025
CVE-2025-48981
8.6 HIGH

An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol …

Oct 8, 2025
CVE-2025-11420
7.3 HIGH

A vulnerability was detected in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/edit_order_details.php. The manipulation of the argument order_id results …

Oct 8, 2025
CVE-2025-11418
9.8 CRITICAL

A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component …

Oct 8, 2025
CVE-2025-61999
4.3 MEDIUM

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload JavaScript or other content embedded in an SVG image used as a logo. Injected content …

Oct 8, 2025
CVE-2025-61998
4.3 MEDIUM

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within the Technical Support Hyperlink Manager. Injected content …

Oct 8, 2025
CVE-2025-61997
4.3 MEDIUM

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Enterprise Banner image upload field. Injected content …

Oct 8, 2025
CVE-2025-61996
4.3 MEDIUM

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Template. Injected content is executed in the …

Oct 8, 2025
CVE-2025-11417
6.3 MEDIUM

A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unknown code of the file /admin/voters_add.php. Executing manipulation of …

Oct 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.