CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-39839
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix OOB read/write in network-coding decode batadv_nc_skb_decode_packet() trusts coded_len and checks only against skb->len. …

Sep 19, 2025
CVE-2025-39838
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL pointer dereference in UTF16 conversion There can be a NULL pointer dereference …

Sep 19, 2025
CVE-2025-39837
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: Fix racy registrations asus_wmi_register_driver() may be called from multiple drivers concurrently, which can …

Sep 19, 2025
CVE-2025-10718
5.3 MEDIUM

A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The …

Sep 19, 2025
CVE-2025-8664
6.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management allows Cross-Site …

Sep 19, 2025
CVE-2025-8532
6.4 MEDIUM

Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing.This issue affects …

Sep 19, 2025
CVE-2025-57528
7.7 HIGH

An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to cause a denial of service via the funcname, funcpara1, funcpara2 parameters to the formSetCfm …

Sep 19, 2025
CVE-2025-10717
5.3 MEDIUM

A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of …

Sep 19, 2025
CVE-2025-10716
5.3 MEDIUM

A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file …

Sep 19, 2025
CVE-2025-58114
4.8 MEDIUM

Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension:CognitiveProcessDesigner) allows Cross-Site Scripting (XSS).This issue affects BlueSpice: from 5 through 5.1.1.

Sep 19, 2025
CVE-2025-57880
5.4 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

Sep 19, 2025
CVE-2025-48007
6.4 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

Sep 19, 2025
CVE-2025-46703
6.4 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

Sep 19, 2025
CVE-2025-10715
5.3 MEDIUM

A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an unknown function of …

Sep 19, 2025
CVE-2025-10712
7.3 HIGH

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This issue affects some unknown processing of the file /index.php/Login/login. Performing manipulation of …

Sep 19, 2025
CVE-2025-7665
8.1 HIGH

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofirebase_form_options' function in …

Sep 19, 2025
CVE-2025-10711
4.3 MEDIUM

A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown code of the file /index.php/sysmanage/Login. Such manipulation of …

Sep 19, 2025
CVE-2025-10710
4.3 MEDIUM

A flaw has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This affects an unknown part of the file /index.php. This manipulation of …

Sep 19, 2025
CVE-2025-9969
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web Design Real Estate Packages allows Content Spoofing, CAPEC - …

Sep 19, 2025
CVE-2025-10709
5.3 MEDIUM

A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is some unknown functionality of the file /history/historyDownload.do;otheruserLogin.do;getfile. The manipulation …

Sep 19, 2025
CVE-2025-10708
5.3 MEDIUM

A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this vulnerability is an unknown functionality of the file /history/historyDownload.do;usrlogout.do. …

Sep 19, 2025
CVE-2025-10707
6.3 MEDIUM

A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper …

Sep 19, 2025
CVE-2025-10468
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus allows Path Traversal.This issue affects CityPlus: before 24.29375.

Sep 19, 2025
CVE-2025-8531
6.8 MEDIUM

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, Q06UDVCPU, Q13UDVCPU, Q26UDVCPU, Q04UDPVCPU, Q06UDPVCPU, Q13UDPVCPU, and Q26UDPVCPU with the …

Sep 19, 2025
CVE-2025-10719
4.3 MEDIUM

Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability, allowing remote attackers with regular privilege to modify a specific parameter to access other …

Sep 19, 2025
CVE-2025-10630
4.3 MEDIUM

Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards …

Sep 19, 2025
CVE-2025-9906
7.3 HIGH

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .keras model archive that, …

Sep 19, 2025
CVE-2025-9905
7.3 HIGH

The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .h5/.hdf5 model archive that, …

Sep 19, 2025
CVE-2025-10647
8.8 HIGH

The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_download_pdf_media function in …

Sep 19, 2025
CVE-2025-7702
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust …

Sep 19, 2025
CVE-2025-7403
7.6 HIGH

Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes are attacker-controlled, enabling precise memory corruption.

Sep 19, 2025
CVE-2025-5948
9.8 CRITICAL

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is …

Sep 19, 2025
CVE-2025-10458
7.6 HIGH

Parameters are not validated or sanitized, and are later used in various internal operations.

Sep 19, 2025
CVE-2025-10457
4.3 MEDIUM

The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiated a connection request. …

Sep 19, 2025
CVE-2025-10456
7.1 HIGH

A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a …

Sep 19, 2025
CVE-2025-5955
8.1 HIGH

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to …

Sep 19, 2025
CVE-2025-10146
6.1 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due …

Sep 19, 2025
CVE-2025-8487
5.4 MEDIUM

The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action …

Sep 19, 2025
CVE-2025-59717
5.4 MEDIUM

In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead …

Sep 19, 2025
CVE-2025-7937
7.2 HIGH

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially …

Sep 19, 2025
CVE-2025-59715
4.8 MEDIUM

SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.

Sep 19, 2025
CVE-2025-59714
6.5 MEDIUM

In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.

Sep 19, 2025
CVE-2025-59713
6.8 MEDIUM

Snipe-IT before 8.1.18 allows unsafe deserialization.

Sep 19, 2025
CVE-2025-59712
6.4 MEDIUM

Snipe-IT before 8.1.18 allows XSS.

Sep 19, 2025
CVE-2025-59678

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59677

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59676

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59675

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59674

Rejected reason: Not used

Sep 19, 2025
CVE-2025-59673

Rejected reason: Not used

Sep 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.