CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25009
8.7 HIGH

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.

Oct 7, 2025
CVE-2025-11397
7.3 HIGH

A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. …

Oct 7, 2025
CVE-2021-22291
8.0 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects …

Oct 7, 2025
CVE-2025-40889
8.1 HIGH

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, …

Oct 7, 2025
CVE-2025-40888
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can …

Oct 7, 2025
CVE-2025-40887
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can …

Oct 7, 2025
CVE-2025-40886
7.5 HIGH

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can …

Oct 7, 2025
CVE-2025-40885
5.3 MEDIUM

A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges …

Oct 7, 2025
CVE-2025-40676

Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Research Infrastructure (BBMRI-ERIC). This vulnerability allows an attacker to access …

Oct 7, 2025
CVE-2025-40649

Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infrastructure (BBMRI-ERIC), consisting of a stored XSS due to a lack …

Oct 7, 2025
CVE-2025-3719
8.1 HIGH

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. …

Oct 7, 2025
CVE-2025-3718
7.9 HIGH

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with …

Oct 7, 2025
CVE-2025-11396
7.3 HIGH

A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument …

Oct 7, 2025
CVE-2025-11390
4.3 MEDIUM

A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of …

Oct 7, 2025
CVE-2025-11389
8.8 HIGH

A security flaw has been discovered in Tenda AC15 15.03.05.18. Affected is an unknown function of the file /goform/saveAutoQos. Performing a manipulation of the argument …

Oct 7, 2025
CVE-2025-0603
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection.This …

Oct 7, 2025
CVE-2025-11388
8.8 HIGH

A vulnerability was identified in Tenda AC15 15.03.05.18. This impacts an unknown function of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to …

Oct 7, 2025
CVE-2025-11387
8.8 HIGH

A vulnerability was determined in Tenda AC15 15.03.05.18. This affects an unknown function of the file /goform/fast_setting_pppoe_set. This manipulation of the argument Password causes stack-based …

Oct 7, 2025
CVE-2025-11386
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.18. The impacted element is an unknown function of the file /goform/SetDDNSCfg of the component POST Parameter Handler. …

Oct 7, 2025
CVE-2025-11385
8.8 HIGH

A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The affected element is the function sscanf of the file /goform/fast_setting_wifi_set. The manipulation of …

Oct 7, 2025
CVE-2025-11360
4.3 MEDIUM

A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the file api/src/app.js of the component API. …

Oct 7, 2025
CVE-2025-11359
6.3 MEDIUM

A security vulnerability has been detected in code-projects Simple Banking System 1.0. The affected element is an unknown function of the file /transfermoney.php. The manipulation …

Oct 7, 2025
CVE-2025-10645
5.3 MEDIUM

The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when …

Oct 7, 2025
CVE-2025-7400
6.4 MEDIUM

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featured Image custom fields in all versions …

Oct 7, 2025
CVE-2025-11358
6.3 MEDIUM

A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /removeuser.php. Executing manipulation of the argument …

Oct 7, 2025
CVE-2025-11357
6.3 MEDIUM

A security flaw has been discovered in code-projects Simple Banking System 1.0. This issue affects some unknown processing of the file /createuser.php. Performing manipulation of …

Oct 7, 2025
CVE-2025-11356
8.8 HIGH

A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of …

Oct 7, 2025
CVE-2025-11355
8.8 HIGH

A vulnerability has been found in UTT 1250GW up to v2v3.2.2-200710. Affected by this vulnerability is the function strcpy of the file /goform/aspChangeChannel. The manipulation …

Oct 7, 2025
CVE-2025-11354
6.3 MEDIUM

A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/addslideexec.php. Executing manipulation of the …

Oct 7, 2025
CVE-2025-11353
6.3 MEDIUM

A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of the file /admin/addgalleryexec.php. Performing manipulation of the argument …

Oct 7, 2025
CVE-2025-10162
7.5 HIGH

The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which …

Oct 7, 2025
CVE-2025-11362
7.5 HIGH

Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An …

Oct 7, 2025
CVE-2025-11352
6.3 MEDIUM

A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown function of the file /admin/addexec.php. Such manipulation of …

Oct 7, 2025
CVE-2025-11351
6.3 MEDIUM

A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/editpicexec.php. This manipulation …

Oct 7, 2025
CVE-2025-11350
7.3 HIGH

A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. The affected element is an unknown function of the file /bwdates-reports-details.php. …

Oct 7, 2025
CVE-2025-11349
7.3 HIGH

A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /search-visitor.php. The manipulation of the …

Oct 7, 2025
CVE-2025-11348
7.3 HIGH

A vulnerability was determined in Campcodes Online Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /index.php. Executing a manipulation …

Oct 7, 2025
CVE-2025-11347
7.3 HIGH

A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file add.php of the component …

Oct 7, 2025
CVE-2025-34251

Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge (adbd) as root and, …

Oct 7, 2025
CVE-2025-61774

PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote …

Oct 6, 2025
CVE-2025-61768

KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module …

Oct 6, 2025
CVE-2025-43824
5.4 MEDIUM

The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through …

Oct 6, 2025
CVE-2025-59452
5.8 MEDIUM

The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret …

Oct 6, 2025
CVE-2025-59451
3.5 LOW

The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.

Oct 6, 2025
CVE-2025-59450
4.3 MEDIUM

The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.

Oct 6, 2025
CVE-2025-59449
4.9 MEDIUM

The YoSmart YoLink MQTT broker through 2025-10-02 does not enforce sufficient authorization controls to prevent cross-account attacks, allowing an attacker to remotely operate affected devices …

Oct 6, 2025
CVE-2025-59448
4.7 MEDIUM

Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to communicate over the internet. An attacker with the ability to monitor network traffic …

Oct 6, 2025
CVE-2025-59447
2.2 LOW

The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can leverage this interface to read a …

Oct 6, 2025
CVE-2025-11346
6.3 MEDIUM

A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the …

Oct 6, 2025
CVE-2025-61985
3.6 LOW

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

Oct 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.