CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40991
5.4 MEDIUM

Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to …

Oct 2, 2025
CVE-2025-40990
5.4 MEDIUM

Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_bug/create/xxx", affecting to …

Oct 2, 2025
CVE-2025-40989
5.4 MEDIUM

Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to …

Oct 2, 2025
CVE-2025-61735
7.3 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's …

Oct 2, 2025
CVE-2025-61734
7.5 HIGH

Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is …

Oct 2, 2025
CVE-2025-61733
7.5 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to …

Oct 2, 2025
CVE-2025-54468
4.7 MEDIUM

A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher …

Oct 2, 2025
CVE-2025-54292
4.6 MEDIUM

Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via …

Oct 2, 2025
CVE-2025-54291
5.3 MEDIUM

Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing …

Oct 2, 2025
CVE-2025-54290
5.3 MEDIUM

Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via …

Oct 2, 2025
CVE-2025-54289
8.1 HIGH

Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute …

Oct 2, 2025
CVE-2025-54288
6.8 MEDIUM

Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to …

Oct 2, 2025
CVE-2025-54287
6.5 MEDIUM

Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the …

Oct 2, 2025
CVE-2025-54286
8.8 HIGH

Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user …

Oct 2, 2025
CVE-2025-40646
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of …

Oct 2, 2025
CVE-2025-40645

Exposure of sensitive information in Viday. This vulnerability could allow an unauthenticated attacker to obtain sensitive information about customers by sending an HTTP GET request …

Oct 2, 2025
CVE-2025-9697
9.8 CRITICAL

The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Oct 2, 2025
CVE-2025-9587
8.6 HIGH

The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via …

Oct 2, 2025
CVE-2025-61692
7.8 HIGH

VT STUDIO versions 8.53 and prior contain a use after free vulnerability. If the product uses a specially crafted file, arbitrary code may be executed …

Oct 2, 2025
CVE-2025-61691
7.8 HIGH

VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on …

Oct 2, 2025
CVE-2025-61690
7.8 HIGH

KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on …

Oct 2, 2025
CVE-2025-58777
7.8 HIGH

VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specially crafted file, arbitrary code may be …

Oct 2, 2025
CVE-2025-58776
7.8 HIGH

KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed …

Oct 2, 2025
CVE-2025-58775
7.8 HIGH

KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the …

Oct 2, 2025
CVE-2025-11221
8.8 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTONE ChangeFlow allows Path Traversal, …

Oct 2, 2025
CVE-2025-11182
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check vulnerability in GTONE ChangeFlow allows Path Traversal.This issue …

Oct 2, 2025
CVE-2025-11020
8.8 HIGH

An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of File with Dangerous Type vulnerability …

Oct 2, 2025
CVE-2025-61855

Rejected reason: Not used

Oct 2, 2025
CVE-2025-61854

Rejected reason: Not used

Oct 2, 2025
CVE-2025-61853

Rejected reason: Not used

Oct 2, 2025
CVE-2025-61852

Rejected reason: Not used

Oct 2, 2025
CVE-2025-61851

Rejected reason: Not used

Oct 2, 2025
CVE-2025-61850

Rejected reason: Not used

Oct 2, 2025
CVE-2025-61849

Rejected reason: Not used

Oct 2, 2025
CVE-2025-61588

RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the …

Oct 2, 2025
CVE-2025-61583
4.3 MEDIUM

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability …

Oct 1, 2025
CVE-2025-61582
7.5 HIGH

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability …

Oct 1, 2025
CVE-2025-61587
6.1 MEDIUM

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is …

Oct 1, 2025
CVE-2025-59951
9.1 CRITICAL

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, …

Oct 1, 2025
CVE-2025-54811
7.1 HIGH

OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a crash when the …

Oct 1, 2025
CVE-2025-23355
6.7 MEDIUM

NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL highjacking attack. A successful exploit of …

Oct 1, 2025
CVE-2025-23297
7.8 HIGH

NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in …

Oct 1, 2025
CVE-2025-59538
7.5 HIGH

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. For versions 2.9.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.6 and 3.0.17, when the webhook.azuredevops.username …

Oct 1, 2025
CVE-2025-59537
7.5 HIGH

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are …

Oct 1, 2025
CVE-2025-59531
7.5 HIGH

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions 1.2.0 through 1.8.7, 2.0.0-rc1 through 2.14.19, 3.0.0-rc1 through 3.2.0-rc1, 3.1.7 and 3.0.18 are …

Oct 1, 2025
CVE-2025-59337
6.8 MEDIUM

Discourse is an open-source community discussion platform. In versions 3.5.0 and below, malicious meta-commands could be embedded in a backup dump and executed during restore. …

Oct 1, 2025
CVE-2025-59150
7.5 HIGH

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Version 8.0.0's usage of …

Oct 1, 2025
CVE-2025-57389
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to execute arbitrary Javascript in the context of a …

Oct 1, 2025
CVE-2025-61189
6.3 MEDIUM

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted …

Oct 1, 2025
CVE-2025-61188
6.3 MEDIUM

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system …

Oct 1, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.