CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10659
9.8 CRITICAL

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that improperly handles user-supplied input. This vulnerability occurs …

Sep 30, 2025
CVE-2024-55017
7.5 HIGH

Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept authorization codes and gain …

Sep 30, 2025
CVE-2025-56132
7.3 HIGH

LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email …

Sep 30, 2025
CVE-2025-43827
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, …

Sep 30, 2025
CVE-2025-57254
6.5 MEDIUM

An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allows remote attackers to execute arbitrary SQL queries via the …

Sep 30, 2025
CVE-2025-56675
3.5 LOW

The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.

Sep 30, 2025
CVE-2025-56513
9.8 CRITICAL

NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to the …

Sep 30, 2025
CVE-2025-56200
6.1 MEDIUM

A URL validation bypass vulnerability exists in validator.js through version 13.15.15. The isURL() function uses '://' as a delimiter to parse protocols, while browsers use …

Sep 30, 2025
CVE-2025-23293
8.7 HIGH

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability …

Sep 30, 2025
CVE-2025-23292
4.6 MEDIUM

NVIDIA Delegated Licensing Service for all appliance platforms contains a SQL injection vulnerability where an User/Attacker may cause an authorized action. A successful exploit of …

Sep 30, 2025
CVE-2025-23291
2.4 LOW

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability …

Sep 30, 2025
CVE-2025-11195
3.3 LOW

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration …

Sep 30, 2025
CVE-2025-10725
9.9 CRITICAL

A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist …

Sep 30, 2025
CVE-2025-56520
5.3 MEDIUM

Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720.

Sep 30, 2025
CVE-2025-56207
6.5 MEDIUM

A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Ethereum ERC721 Non-Fungible Token (NFT) project, allows …

Sep 30, 2025
CVE-2025-6034
7.8 HIGH

There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor in NI Circuit Design Suite. This vulnerability …

Sep 30, 2025
CVE-2025-6033
7.8 HIGH

There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in NI Circuit Design Suite. This vulnerability …

Sep 30, 2025
CVE-2025-56676
5.4 MEDIUM

TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary password or reset token issued to one user can be …

Sep 30, 2025
CVE-2025-56572
7.5 HIGH

An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.

Sep 30, 2025
CVE-2025-56571
7.5 HIGH

Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive …

Sep 30, 2025
CVE-2025-56018
6.1 MEDIUM

SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category Management via the category name field.

Sep 30, 2025
CVE-2025-55797
6.5 MEDIUM

An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is …

Sep 30, 2025
CVE-2025-54477
5.3 MEDIUM

Improper handling of authentication requests lead to a user enumeration vector in the passkey authentication method.

Sep 30, 2025
CVE-2025-54476

Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.

Sep 30, 2025
CVE-2025-7779
8.8 HIGH

Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42389, Acronis True Image for …

Sep 30, 2025
CVE-2025-7493
9.1 CRITICAL

A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE-2025-4404, where it fails to validate the …

Sep 30, 2025
CVE-2025-57852
6.4 MEDIUM

A container privilege escalation flaw was found in KServe ModelMesh container images. This issue stems from the /etc/passwd file being created with group-writable permissions during …

Sep 30, 2025
CVE-2025-56301
7.5 HIGH

An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowing attackers to corrupt exception handling and privilege state transitions via a flawed interaction between …

Sep 30, 2025
CVE-2025-28016
4.8 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows …

Sep 30, 2025
CVE-2025-11178
7.3 HIGH

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42386, Acronis True Image for Western …

Sep 30, 2025
CVE-2025-9232
5.9 MEDIUM

Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the …

Sep 30, 2025
CVE-2025-9231
6.5 MEDIUM

Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM …

Sep 30, 2025
CVE-2025-9230
7.5 HIGH

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds …

Sep 30, 2025
CVE-2025-52050
6.5 MEDIUM

In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by …

Sep 30, 2025
CVE-2025-52049
6.5 MEDIUM

In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by …

Sep 30, 2025
CVE-2025-52047
6.5 MEDIUM

In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by …

Sep 30, 2025
CVE-2025-52043
6.5 MEDIUM

In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which allows an attacker to extract all information from databases by …

Sep 30, 2025
CVE-2025-34217
9.8 CRITICAL

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/.ssh/authorized_keys' and …

Sep 30, 2025
CVE-2025-11153
7.5 HIGH

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.

Sep 30, 2025
CVE-2025-11152
8.6 HIGH

Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.0.3.

Sep 30, 2025
CVE-2025-10859
4.0 MEDIUM

Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after …

Sep 30, 2025
CVE-2025-10217

A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in …

Sep 30, 2025
CVE-2025-9993
8.1 HIGH

The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via …

Sep 30, 2025
CVE-2025-9991
8.1 HIGH

The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' …

Sep 30, 2025
CVE-2025-9948
4.3 MEDIUM

The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to …

Sep 30, 2025
CVE-2025-9946
6.1 MEDIUM

The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is …

Sep 30, 2025
CVE-2025-9852
6.4 MEDIUM

The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-schedule' shortcode in all versions up to, and including, …

Sep 30, 2025
CVE-2025-9762
9.8 CRITICAL

The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the save_attachments function in all …

Sep 30, 2025
CVE-2025-8877
7.5 HIGH

The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in all versions up to, and including, 2.28.2 due to insufficient …

Sep 30, 2025
CVE-2025-8777
6.4 MEDIUM

The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all versions up to, and including, 2.2 due to …

Sep 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.