CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-57319
7.5 HIGH

fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedRestore function of fast-redact version 3.5.0 and before …

Sep 24, 2025
CVE-2025-57318
7.5 HIGH

A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject properties on Object.prototype via supplying a crafted payload, …

Sep 24, 2025
CVE-2025-59828
9.8 CRITICAL

Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-executed …

Sep 24, 2025
CVE-2025-59824
5.4 MEDIUM

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escape. Omni …

Sep 24, 2025
CVE-2025-57329
7.5 HIGH

web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability in the attachToObject function of web3-core-method version 1.10.4 …

Sep 24, 2025
CVE-2025-57328
7.5 HIGH

toggle-array is a package designed to enables a property on the object at the specified index, while disabling the property on all other objects. A …

Sep 24, 2025
CVE-2025-57327
7.5 HIGH

spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config function of spmrc version 1.2.0 …

Sep 24, 2025
CVE-2025-57326
7.5 HIGH

A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, …

Sep 24, 2025
CVE-2025-57325
7.5 HIGH

rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes advanced error tracking features and an intuitive interface …

Sep 24, 2025
CVE-2025-57323
7.5 HIGH

mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vulnerability in the mp.addEventHandler function of mpregular version …

Sep 24, 2025
CVE-2025-57321
9.8 CRITICAL

A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 allows attackers to inject properties on Object.prototype via supplying a crafted payload, …

Sep 24, 2025
CVE-2025-59525
6.1 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded …

Sep 24, 2025
CVE-2025-59251
7.6 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 24, 2025
CVE-2025-57351
6.5 MEDIUM

A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation of user-provided keys in the assign function allows attackers …

Sep 24, 2025
CVE-2025-57349
7.5 HIGH

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message key …

Sep 24, 2025
CVE-2025-57348
6.5 MEDIUM

The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties …

Sep 24, 2025
CVE-2025-57347
9.8 CRITICAL

A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConflict function, which fails to properly sanitize user-supplied input during …

Sep 24, 2025
CVE-2025-57330
7.5 HIGH

The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows …

Sep 24, 2025
CVE-2025-55322
7.3 HIGH

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.

Sep 24, 2025
CVE-2025-55178
5.3 MEDIUM

Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.

Sep 24, 2025
CVE-2025-59524
6.1 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in the …

Sep 24, 2025
CVE-2025-59343

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable …

Sep 24, 2025
CVE-2025-59305
7.6 HIGH

Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to …

Sep 24, 2025
CVE-2025-57354
6.5 MEDIUM

A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user-controlled input in translation key processing. The affected …

Sep 24, 2025
CVE-2025-57353
5.3 MEDIUM

The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the …

Sep 24, 2025
CVE-2025-57352
5.3 MEDIUM

A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious …

Sep 24, 2025
CVE-2025-57350
8.6 HIGH

The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10. …

Sep 24, 2025
CVE-2025-56241
7.5 HIGH

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows …

Sep 24, 2025
CVE-2025-52907
8.8 HIGH

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Sep 24, 2025
CVE-2025-52906
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through …

Sep 24, 2025
CVE-2025-48869
7.5 HIGH

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing …

Sep 24, 2025
CVE-2025-48867
4.8 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin …

Sep 24, 2025
CVE-2025-20352
7.7 HIGH KEV

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, …

Sep 24, 2025
CVE-2025-20338
6.0 MEDIUM

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root …

Sep 24, 2025
CVE-2025-20327
7.7 HIGH

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service …

Sep 24, 2025
CVE-2025-20316
5.3 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an …

Sep 24, 2025
CVE-2025-20315
8.6 HIGH

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device …

Sep 24, 2025
CVE-2025-20314
6.7 MEDIUM

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an …

Sep 24, 2025
CVE-2025-20313
6.7 MEDIUM

Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to …

Sep 24, 2025
CVE-2025-20312
7.7 HIGH

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial …

Sep 24, 2025
CVE-2025-20311
7.4 HIGH

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker …

Sep 24, 2025
CVE-2025-20293
5.3 MEDIUM

A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an …

Sep 24, 2025
CVE-2025-20240
6.1 MEDIUM

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack …

Sep 24, 2025
CVE-2025-20160
8.1 HIGH

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to …

Sep 24, 2025
CVE-2025-20149
6.5 MEDIUM

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device …

Sep 24, 2025
CVE-2025-56816
8.8 HIGH

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to the config/jdbc-driver-ext.yml path. …

Sep 24, 2025
CVE-2025-56815
7.1 HIGH

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to save the uploaded file to a …

Sep 24, 2025
CVE-2025-20365
4.3 MEDIUM

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 …

Sep 24, 2025
CVE-2025-20364
4.3 MEDIUM

A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless …

Sep 24, 2025
CVE-2025-20339
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass …

Sep 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.