CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-44014
8.8 HIGH

An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Oct 3, 2025
CVE-2025-44012
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-44011
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44010
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44009
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44008
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-61593
7.1 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its …

Oct 3, 2025
CVE-2025-61592
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current working …

Oct 3, 2025
CVE-2025-52653
7.6 HIGH

HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the execution of unauthorized scripts, potentially resulting in …

Oct 3, 2025
CVE-2025-46817
7.0 HIGH

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua …

Oct 3, 2025
CVE-2025-44007
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-44006
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-33040
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-33039
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-33034
6.5 MEDIUM

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Oct 3, 2025
CVE-2024-56804
8.8 HIGH

An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, they can then exploit the vulnerability …

Oct 3, 2025
CVE-2025-61591
8.8 HIGH

Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, …

Oct 3, 2025
CVE-2025-61590
7.5 HIGH

Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual Studio …

Oct 3, 2025
CVE-2025-56551
8.2 HIGH

An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate login interface with arbitrary attacker-controlled content via supplying …

Oct 3, 2025
CVE-2021-42193
6.1 MEDIUM

nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload …

Oct 3, 2025
CVE-2025-60787
7.2 HIGH

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, …

Oct 3, 2025
CVE-2025-57423
6.5 MEDIUM

A SQL injection vulnerability was discovered in the /articles endpoint of MyClub 0.5, affecting the query parameters Content, GroupName, PersonName, lastUpdate, pool, and title. Due …

Oct 3, 2025
CVE-2025-55972
7.5 HIGH

A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood …

Oct 3, 2025
CVE-2025-55971
4.7 MEDIUM

TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability via the …

Oct 3, 2025
CVE-2025-34226

OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be …

Oct 3, 2025
CVE-2025-10729

The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might …

Oct 3, 2025
CVE-2025-10728

When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS

Oct 3, 2025
CVE-2025-60454
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the image management module, specifically in the …

Oct 3, 2025
CVE-2025-60453
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the column management module, specifically in the …

Oct 3, 2025
CVE-2025-60452
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the download management module, specifically in the …

Oct 3, 2025
CVE-2025-60451
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG …

Oct 3, 2025
CVE-2025-60450
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG …

Oct 3, 2025
CVE-2025-60449
4.9 MEDIUM

An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This security flaw …

Oct 3, 2025
CVE-2025-60448
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in …

Oct 3, 2025
CVE-2025-60447
5.9 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/setting.php?action=mail, …

Oct 3, 2025
CVE-2025-60445
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exists due to insufficient validation of SVG file uploads in …

Oct 3, 2025
CVE-2025-59489
7.4 HIGH

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. …

Oct 3, 2025
CVE-2025-10609
5.9 MEDIUM

Use of Hard-coded Credentials vulnerability in Logo Software Inc. TigerWings ERP allows Read Sensitive Constants Within an Executable.This issue affects TigerWings ERP: from 01.01.00 before …

Oct 3, 2025
CVE-2025-9945
4.3 MEDIUM

The Optimize More! – CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due …

Oct 3, 2025
CVE-2025-9897
4.3 MEDIUM

The AP Background plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. This is due to missing …

Oct 3, 2025
CVE-2025-9895
4.3 MEDIUM

The Notification Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing …

Oct 3, 2025
CVE-2025-9892
5.3 MEDIUM

The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to …

Oct 3, 2025
CVE-2025-9889
4.3 MEDIUM

The ContentMX Content Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.6. This is due to …

Oct 3, 2025
CVE-2025-9885
4.3 MEDIUM

The MPWizard – Create Mercado Pago Payment Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. …

Oct 3, 2025
CVE-2025-9884
6.1 MEDIUM

The Mobile Site Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to …

Oct 3, 2025
CVE-2025-9876
6.4 MEDIUM

The Ird Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irdslider' shortcode in all versions up to, and including, 1.0.2 …

Oct 3, 2025
CVE-2025-9875
6.4 MEDIUM

The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticket_spot' shortcode in all versions up to, and …

Oct 3, 2025
CVE-2025-9859
6.4 MEDIUM

The Fintelligence Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fintelligence-calculator' shortcode in all versions up to, and including, 1.0.3 …

Oct 3, 2025
CVE-2025-9858
6.4 MEDIUM

The Auto Bulb Finder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abf_vehicle' shortcode in all versions up to, …

Oct 3, 2025
CVE-2025-9854
6.4 MEDIUM

The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'asmp-switcher' shortcode in all versions up to, and …

Oct 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.