CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-41244
7.8 HIGH KEV

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with …

Sep 29, 2025
CVE-2024-57412
7.5 HIGH

An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets.

Sep 29, 2025
CVE-2025-41246
7.6 HIGH

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on …

Sep 29, 2025
CVE-2025-11155

The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, …

Sep 29, 2025
CVE-2025-57516
8.2 HIGH

OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat …

Sep 29, 2025
CVE-2025-56449
8.2 HIGH

A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA …

Sep 29, 2025
CVE-2025-55795
3.5 LOW

The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user …

Sep 29, 2025
CVE-2025-36352
6.4 MEDIUM

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in …

Sep 29, 2025
CVE-2025-36351
4.3 MEDIUM

IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.

Sep 29, 2025
CVE-2025-57428
6.5 MEDIUM

Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port …

Sep 29, 2025
CVE-2024-13150
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software and Consulting Services fayton.Pro ERP allows SQL Injection.This issue …

Sep 29, 2025
CVE-2025-9648

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP …

Sep 29, 2025
CVE-2025-8868
9.8 CRITICAL

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the …

Sep 29, 2025
CVE-2025-6724
8.8 HIGH

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple …

Sep 29, 2025
CVE-2025-11150

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 29, 2025
CVE-2025-11147
5.4 MEDIUM

Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be executed in “/html/<filename>.html”.

Sep 29, 2025
CVE-2025-11146
5.4 MEDIUM

Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is …

Sep 29, 2025
CVE-2025-10346
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10345
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10344
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10343
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10342
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10341
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-48006
9.1 CRITICAL

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on …

Sep 29, 2025
CVE-2024-5200
4.8 MEDIUM

The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Sep 29, 2025
CVE-2025-11141
4.7 MEDIUM

A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue is the function listAction of the file /itbox_pi/branch_passw.php?a=list. Performing …

Sep 29, 2025
CVE-2025-10504
6.1 MEDIUM

Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

Sep 29, 2025
CVE-2025-11140
7.3 HIGH

A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation …

Sep 29, 2025
CVE-2025-11139
6.3 MEDIUM

A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function uploadStudioFile of the component com.artery.form.services.FormStudioUpdater. This manipulation of the argument …

Sep 29, 2025
CVE-2025-11138
6.3 MEDIUM

A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command …

Sep 29, 2025
CVE-2025-11137
3.5 LOW

A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File Renaming Handler. The manipulation leads …

Sep 29, 2025
CVE-2025-11136
4.7 MEDIUM

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component …

Sep 29, 2025
CVE-2025-11135
7.3 HIGH

A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The affected element is the function loadLanguage of the file classes/class.database.php of the component Cookie …

Sep 29, 2025
CVE-2025-9904
5.3 MEDIUM

Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer …

Sep 29, 2025
CVE-2025-9903
5.9 MEDIUM

Out-of-bounds write vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver …

Sep 29, 2025
CVE-2025-7698
5.9 MEDIUM

Out-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver …

Sep 29, 2025
CVE-2025-11134
2.4 LOW

A security vulnerability has been detected in Cudy TR1200 1.16.3-20230804-164635. Impacted is an unknown function of the file /cgi-bin/luci/admin/network/wireless/config/ of the component Wireless Settings Page. …

Sep 29, 2025
CVE-2025-11130
8.4 HIGH

A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the function shouldAcceptNewConnection of the file HelpTool/HelperTool.m of the component XPC …

Sep 29, 2025
CVE-2025-11126
9.8 CRITICAL

A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The manipulation results in hard-coded credentials. …

Sep 29, 2025
CVE-2025-11125
4.3 MEDIUM

A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. Affected by this vulnerability is an unknown functionality of the file /connection_error.php of …

Sep 29, 2025
CVE-2025-11124
3.5 LOW

A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument …

Sep 28, 2025
CVE-2025-11123
8.8 HIGH

A flaw has been found in Tenda AC18 15.03.05.19. This impacts an unknown function of the file /goform/saveAutoQos. This manipulation of the argument enable causes …

Sep 28, 2025
CVE-2025-11122
8.8 HIGH

A vulnerability was detected in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in …

Sep 28, 2025
CVE-2025-11121
6.3 MEDIUM

A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the …

Sep 28, 2025
CVE-2025-11120
8.8 HIGH

A weakness has been identified in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /goform/SetServerConfig. Executing manipulation can lead to …

Sep 28, 2025
CVE-2025-11119
4.3 MEDIUM

A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST …

Sep 28, 2025
CVE-2025-11118
7.3 HIGH

A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of the file /adminLogin.php. Such manipulation of the argument …

Sep 28, 2025
CVE-2025-11117
8.8 HIGH

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formWrlExtraGet of the file /goform/GstDhcpSetSer. This manipulation of the argument dips causes …

Sep 28, 2025
CVE-2025-11116
7.3 HIGH

A vulnerability was found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.home.php. The manipulation of the argument faculty …

Sep 28, 2025
CVE-2025-11115
7.3 HIGH

A vulnerability has been found in code-projects Simple Scheduling System 1.0. Affected by this issue is some unknown functionality of the file /addtime.php. The manipulation …

Sep 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.