CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-61847

Rejected reason: Not used

Oct 3, 2025
CVE-2025-59300
7.8 HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute …

Oct 3, 2025
CVE-2025-59299
7.8 HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute …

Oct 3, 2025
CVE-2025-59298
7.8 HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute …

Oct 3, 2025
CVE-2025-59297
7.8 HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute …

Oct 3, 2025
CVE-2025-11241
6.4 MEDIUM

The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to …

Oct 3, 2025
CVE-2025-10895

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Oct 2, 2025
CVE-2025-61668

Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, …

Oct 2, 2025
CVE-2025-61666

Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 …

Oct 2, 2025
CVE-2025-61600
7.5 HIGH

Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerability in the IMAP protocol parser which allows remote …

Oct 2, 2025
CVE-2025-61665
7.5 HIGH

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in …

Oct 2, 2025
CVE-2025-61606
6.1 MEDIUM

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the …

Oct 2, 2025
CVE-2025-61605
9.8 CRITICAL

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL Injection vulnerability which was identified …

Oct 2, 2025
CVE-2025-54089
3.4 LOW

CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another …

Oct 2, 2025
CVE-2025-54088
6.1 MEDIUM

CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. …

Oct 2, 2025
CVE-2025-61604
7.1 HIGH

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-Site Request Forgery (CSRF) vulnerability. The …

Oct 2, 2025
CVE-2025-61603
9.8 CRITICAL

WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically …

Oct 2, 2025
CVE-2025-61595

MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce the tx …

Oct 2, 2025
CVE-2025-54087
2.6 LOW

CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request …

Oct 2, 2025
CVE-2025-54086
3.3 LOW

CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file …

Oct 2, 2025
CVE-2025-10653
8.6 HIGH

An unauthenticated debug port may allow access to the device file system.

Oct 2, 2025
CVE-2025-59835

LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/files/documents …

Oct 2, 2025
CVE-2025-54315
7.1 HIGH

The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.

Oct 2, 2025
CVE-2025-49090
7.1 HIGH

The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.

Oct 2, 2025
CVE-2025-32942
7.2 HIGH

SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.

Oct 2, 2025
CVE-2025-56019
6.5 MEDIUM

An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to connect via Bluetooth Low Energy (BLE) without …

Oct 2, 2025
CVE-2025-60663
7.5 HIGH

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.

Oct 2, 2025
CVE-2025-60661
5.3 MEDIUM

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.

Oct 2, 2025
CVE-2025-59409
7.5 HIGH

Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.

Oct 2, 2025
CVE-2025-59407
9.8 CRITICAL

The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a …

Oct 2, 2025
CVE-2025-59406
6.2 MEDIUM

The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a …

Oct 2, 2025
CVE-2025-59405
7.5 HIGH

The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a …

Oct 2, 2025
CVE-2025-59403
9.8 CRITICAL

The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo …

Oct 2, 2025
CVE-2025-34210
5.5 MEDIUM

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number of sensitive credentials (database passwords, MySQL root password, SaaS keys, …

Oct 2, 2025
CVE-2025-34208
7.5 HIGH

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store user passwords using unsalted SHA-512 hashes with a fall-back to unsalted SHA-1. The …

Oct 2, 2025
CVE-2025-60662
7.5 HIGH

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.

Oct 2, 2025
CVE-2025-60660
7.5 HIGH

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.

Oct 2, 2025
CVE-2025-57305
6.5 MEDIUM

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

Oct 2, 2025
CVE-2025-56162
6.5 MEDIUM

YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), …

Oct 2, 2025
CVE-2025-56161
7.5 HIGH

YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field …

Oct 2, 2025
CVE-2025-56154
6.1 MEDIUM

htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before …

Oct 2, 2025
CVE-2025-61096
6.5 MEDIUM

PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.

Oct 2, 2025
CVE-2025-61087
6.1 MEDIUM

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.

Oct 2, 2025
CVE-2025-60782
5.4 MEDIUM

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject …

Oct 2, 2025
CVE-2025-59774
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59773
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59772
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59771
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59770
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025
CVE-2025-59769
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them …

Oct 2, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.