CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59817
8.4 HIGH

This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full control …

Sep 25, 2025
CVE-2025-59816
7.3 HIGH

This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords …

Sep 25, 2025
CVE-2025-59815
8.4 HIGH

This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting shell access. Exploitation can …

Sep 25, 2025
CVE-2025-59814
8.8 HIGH

This vulnerability allows malicious actors to gain unauthorized access to the Zenitel ICX500 and ICX510 Gateway Billing Admin endpoint, enabling them to read the entire …

Sep 25, 2025
CVE-2025-57632
7.5 HIGH

libsmb2 6.2+ is vulnerable to Buffer Overflow. When processing SMB2 chained PDUs (NextCommand), libsmb2 repeatedly calls smb2_add_iovector() to append to a fixed-size iovec array without …

Sep 25, 2025
CVE-2025-43993
7.8 HIGH

Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unquoted Search Path or Element vulnerability. A low …

Sep 25, 2025
CVE-2025-43816
7.5 HIGH

A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, …

Sep 25, 2025
CVE-2025-10967
7.3 HIGH

A vulnerability was detected in MuFen-mker PHP-Usermm up to 37f2d24e51b04346dfc565b93fc2fc6b37bdaea9. This affects an unknown part of the file /chkuser.php. Performing manipulation of the argument Username …

Sep 25, 2025
CVE-2025-10965
6.3 MEDIUM

A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/components/deploy/relay/server.py. Such …

Sep 25, 2025
CVE-2025-10964
6.3 MEDIUM

A weakness has been identified in Wavlink NU516U1. Affected by this vulnerability is the function sub_401B30 of the file /cgi-bin/firewall.cgi. This manipulation of the argument …

Sep 25, 2025
CVE-2025-29157
6.5 MEDIUM

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing …

Sep 25, 2025
CVE-2025-29156
6.1 MEDIUM

Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet

Sep 25, 2025
CVE-2025-10963
6.3 MEDIUM

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. Affected is the function sub_4016F0 of the file /cgi-bin/firewall.cgi. The manipulation of the argument del_flag …

Sep 25, 2025
CVE-2025-10962
6.3 MEDIUM

A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This impacts the function sub_403198 of the file /cgi-bin/wireless.cgi of the component SetName Page. The manipulation of …

Sep 25, 2025
CVE-2025-60249
6.4 MEDIUM

vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and user.py, by a user on a vulnerability-lookup instance who can add bundles, comments, or sightings. A cross-site …

Sep 25, 2025
CVE-2025-57623
5.3 MEDIUM

A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.

Sep 25, 2025
CVE-2025-48707
7.5 HIGH

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which …

Sep 25, 2025
CVE-2025-29155
6.5 MEDIUM

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint

Sep 25, 2025
CVE-2025-10961
5.5 MEDIUM

A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-bin/wireless.cgi of the component Delete_Mac_list Page. Executing manipulation of …

Sep 25, 2025
CVE-2025-10960
6.3 MEDIUM

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. The impacted element is the function sub_402D1C of the file /cgi-bin/wireless.cgi of the component DeleteMac Page. Performing …

Sep 25, 2025
CVE-2025-10959
6.3 MEDIUM

A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. The affected element is the function sub_401778 of the file /cgi-bin/firewall.cgi. Such manipulation of the argument …

Sep 25, 2025
CVE-2025-10958
6.3 MEDIUM

A flaw has been found in Wavlink NU516U1 M16U1_V240425. Impacted is the function sub_403010 of the file /cgi-bin/wireless.cgi of the component AddMac Page. This manipulation …

Sep 25, 2025
CVE-2025-34227
8.8 HIGH

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query …

Sep 25, 2025
CVE-2025-10880
7.5 HIGH

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol …

Sep 25, 2025
CVE-2025-10879
5.3 MEDIUM

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to retrieve the current user's username without …

Sep 25, 2025
CVE-2025-60019
3.7 LOW

glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to …

Sep 25, 2025
CVE-2025-60018
4.8 MEDIUM

glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.

Sep 25, 2025
CVE-2025-59841
9.8 CRITICAL

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated …

Sep 25, 2025
CVE-2025-57446
7.5 HIGH

An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a denial of service (DoS) via a crafted …

Sep 25, 2025
CVE-2025-55560
7.5 HIGH

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense() and is compiled …

Sep 25, 2025
CVE-2025-55559
7.5 HIGH

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

Sep 25, 2025
CVE-2025-55558
7.5 HIGH

A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-torch.mv() and is compiled by Inductor, leading to a …

Sep 25, 2025
CVE-2025-55557
7.5 HIGH

A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service …

Sep 25, 2025
CVE-2025-55556
6.5 MEDIUM

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

Sep 25, 2025
CVE-2025-55554
5.3 MEDIUM

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

Sep 25, 2025
CVE-2025-55553
7.5 HIGH

A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).

Sep 25, 2025
CVE-2025-55552
7.5 HIGH

pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

Sep 25, 2025
CVE-2025-43943
6.7 MEDIUM

Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Sep 25, 2025
CVE-2025-33116
4.4 MEDIUM

IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Sep 25, 2025
CVE-2025-26333
5.9 MEDIUM

Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, …

Sep 25, 2025
CVE-2025-20363
9.0 CRITICAL

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, …

Sep 25, 2025
CVE-2025-20362
6.5 MEDIUM KEV

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software …

Sep 25, 2025
CVE-2025-20333
9.9 CRITICAL KEV

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could …

Sep 25, 2025
CVE-2025-10953
8.8 HIGH

A security vulnerability has been detected in UTT 1200GW and 1250GW up to 3.0.0-170831/3.2.2-200710. This vulnerability affects unknown code of the file /goform/formApMail. The manipulation …

Sep 25, 2025
CVE-2025-10952
5.3 MEDIUM

A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream_handler of the file ml_logger/server.py of …

Sep 25, 2025
CVE-2025-10911
5.5 MEDIUM

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

Sep 25, 2025
CVE-2024-48014
7.5 HIGH

Dell BSAFE Micro Edition Suite, versions prior to 5.0.2.3 contain an Out-of-bounds Write vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, …

Sep 25, 2025
CVE-2025-59838
5.4 MEDIUM

Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user input when loading a saved custom text results …

Sep 25, 2025
CVE-2025-59832
9.9 CRITICAL

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket …

Sep 25, 2025
CVE-2025-59830
7.5 HIGH

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &, while still splitting …

Sep 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.