CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11331
4.7 MEDIUM

A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the component Website Name …

Oct 6, 2025
CVE-2025-11330
6.3 MEDIUM

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/sales-reports-detail.php. Such manipulation …

Oct 6, 2025
CVE-2025-0609
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Logo Software Inc. Logo Cloud allows Cross-Site Scripting (XSS).This issue affects …

Oct 6, 2025
CVE-2025-0608
5.5 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Logo Software Inc. Logo Cloud allows Phishing, Forceful Browsing.This issue affects Logo Cloud: before 2025.R6.

Oct 6, 2025
CVE-2025-0607
4.3 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing.This issue affects Logo Cloud: before 2.57.

Oct 6, 2025
CVE-2025-11329
7.3 HIGH

A flaw has been found in code-projects Online Course Registration 1.0. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument …

Oct 6, 2025
CVE-2025-11328
8.8 HIGH

A vulnerability was detected in Tenda AC18 15.03.05.19(6318). This issue affects some unknown processing of the file /goform/SetDDNSCfg. The manipulation of the argument ddnsEn results …

Oct 6, 2025
CVE-2025-0606
6.0 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing, Resource Leak Exposure.This issue affects Logo Cloud: before 0.67.

Oct 6, 2025
CVE-2025-59734

It is possible to cause an use-after-free write in SANM decoding with a carefully crafted animation using subversion <2. When a STOR chunk is present, …

Oct 6, 2025
CVE-2025-59733

When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that all image channels have the same pixel type (and …

Oct 6, 2025
CVE-2025-59732

When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8. If …

Oct 6, 2025
CVE-2025-59731

When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to …

Oct 6, 2025
CVE-2025-59730

When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded …

Oct 6, 2025
CVE-2025-59729

When parsing the header for a DHAV file, there's an integer underflow in offset calculation that leads to reading the duration from before the start …

Oct 6, 2025
CVE-2025-59728

When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call …

Oct 6, 2025
CVE-2025-11327
8.8 HIGH

A security vulnerability has been detected in Tenda AC18 15.03.05.19(6318). This vulnerability affects unknown code of the file /goform/SetUpnpCfg. The manipulation of the argument upnpEn …

Oct 6, 2025
CVE-2025-11326
8.8 HIGH

A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet. Executing a manipulation of the argument wifi_chkHz …

Oct 6, 2025
CVE-2025-9914
4.3 MEDIUM

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to …

Oct 6, 2025
CVE-2025-9913
4.5 MEDIUM

JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

Oct 6, 2025
CVE-2025-58591
6.5 MEDIUM

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive …

Oct 6, 2025
CVE-2025-58590
6.5 MEDIUM

It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.

Oct 6, 2025
CVE-2025-58589
2.7 LOW

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as …

Oct 6, 2025
CVE-2025-58587
6.5 MEDIUM

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to …

Oct 6, 2025
CVE-2025-58586
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Oct 6, 2025
CVE-2025-58585
5.3 MEDIUM

Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.

Oct 6, 2025
CVE-2025-58584
5.3 MEDIUM

In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such …

Oct 6, 2025
CVE-2025-58583
5.3 MEDIUM

The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

Oct 6, 2025
CVE-2025-58582
5.3 MEDIUM

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated …

Oct 6, 2025
CVE-2025-58581
4.3 MEDIUM

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as …

Oct 6, 2025
CVE-2025-58580
6.5 MEDIUM

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated …

Oct 6, 2025
CVE-2025-58579
5.3 MEDIUM

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user …

Oct 6, 2025
CVE-2025-58578
3.8 LOW

A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, …

Oct 6, 2025
CVE-2025-11325
8.8 HIGH

A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the file /goform/fast_setting_pppoe_set. Performing a manipulation …

Oct 6, 2025
CVE-2025-11324
8.8 HIGH

A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the file /goform/setNotUpgrade. Such manipulation of the argument …

Oct 6, 2025
CVE-2025-9710
6.3 MEDIUM

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality …

Oct 6, 2025
CVE-2025-9703
4.3 MEDIUM

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the …

Oct 6, 2025
CVE-2025-57781
7.8 HIGH

The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. …

Oct 6, 2025
CVE-2025-11323
8.8 HIGH

A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected is the function strcpy of the file /goform/formUserStatusRemark. This manipulation of the argument Username …

Oct 6, 2025
CVE-2025-11322
3.7 LOW

A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component …

Oct 6, 2025
CVE-2025-11321
4.3 MEDIUM

A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performing manipulation of the …

Oct 6, 2025
CVE-2025-11320
6.3 MEDIUM

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the …

Oct 6, 2025
CVE-2025-11319
6.3 MEDIUM

A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16e87b965024097. This issue affects some unknown processing of the file /delete.php. This manipulation of the …

Oct 6, 2025
CVE-2025-11318
7.3 HIGH

A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability affects unknown code of the file uploadWxFile.do. The …

Oct 6, 2025
CVE-2025-11317
7.3 HIGH

A vulnerability was identified in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This affects the function findRolePage of the file findSingConfigPage.do. The manipulation of …

Oct 6, 2025
CVE-2025-11316
7.3 HIGH

A vulnerability was determined in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this issue is the function findCategoryPage of the file findCategoryPage.do. …

Oct 6, 2025
CVE-2025-50538
8.2 HIGH

Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.

Oct 6, 2025
CVE-2025-29192
8.2 HIGH

Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.

Oct 6, 2025
CVE-2025-11315
7.3 HIGH

A vulnerability was found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this vulnerability is the function findUserPage of the file findUserPage.do. …

Oct 6, 2025
CVE-2025-11314
7.3 HIGH

A vulnerability has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected is the function findRolePage of the file findSingConfigPage.do. Such manipulation …

Oct 6, 2025
CVE-2025-11313
7.3 HIGH

A flaw has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This impacts the function findRolePage of the file findRolePage.do. This manipulation …

Oct 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.