CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9449
7.8 HIGH

A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute …

Sep 17, 2025
CVE-2025-9447
7.8 HIGH

An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary …

Sep 17, 2025
CVE-2025-9216
8.8 HIGH

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to …

Sep 17, 2025
CVE-2025-9215
6.5 MEDIUM

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions …

Sep 17, 2025
CVE-2025-9203
6.4 MEDIUM

The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitle_ssize', 'track_title', and 'track_artist_name' parameters in version 1.0.5. …

Sep 17, 2025
CVE-2025-10058
8.1 HIGH

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation …

Sep 17, 2025
CVE-2025-10057
8.8 HIGH

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and …

Sep 17, 2025
CVE-2025-10042
5.9 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to …

Sep 17, 2025
CVE-2025-9818
6.7 MEDIUM

A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided by OMRON SOCIAL SOLUTIONS Co., Ltd., where the executable file …

Sep 17, 2025
CVE-2025-59518
8.0 HIGH

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during …

Sep 17, 2025
CVE-2025-59307
6.7 MEDIUM

RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory …

Sep 17, 2025
CVE-2025-58116
7.2 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, an …

Sep 17, 2025
CVE-2025-55075
4.9 MEDIUM

Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker.

Sep 17, 2025
CVE-2025-10589
8.8 HIGH

The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute …

Sep 17, 2025
CVE-2025-10584
3.5 LOW

A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_cad.php. Such manipulation of the argument nm_anotacao/descricao …

Sep 17, 2025
CVE-2025-10188
5.4 MEDIUM

The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This …

Sep 17, 2025
CVE-2025-10125
6.4 MEDIUM

The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shortcode in all versions up to, and including, 1.4 …

Sep 17, 2025
CVE-2025-9891
4.3 MEDIUM

The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This …

Sep 17, 2025
CVE-2025-9851
6.4 MEDIUM

The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar' shortcode in all versions up to, and including, 4.1.0 due …

Sep 17, 2025
CVE-2025-9629
4.3 MEDIUM

The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing …

Sep 17, 2025
CVE-2025-8394
6.4 MEDIUM

The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_productive_breadcrumb shortcode in all versions up to, and including, 1.1.23 …

Sep 17, 2025
CVE-2025-8153

Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 …

Sep 17, 2025
CVE-2025-10166
6.4 MEDIUM

The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter' shortcode in all versions up to, and including, …

Sep 17, 2025
CVE-2025-10143
7.5 HIGH

The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0 via the 'catch_dark_mode' shortcode. …

Sep 17, 2025
CVE-2025-10050
6.6 MEDIUM

The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the …

Sep 17, 2025
CVE-2025-43804
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject …

Sep 16, 2025
CVE-2025-37131
4.9 MEDIUM

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, …

Sep 16, 2025
CVE-2025-37130
6.5 MEDIUM

A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow …

Sep 16, 2025
CVE-2025-37129
6.7 MEDIUM

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could …

Sep 16, 2025
CVE-2025-37128
6.8 MEDIUM

A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful …

Sep 16, 2025
CVE-2025-37127
7.2 HIGH

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful …

Sep 16, 2025
CVE-2025-37126
7.2 HIGH

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the …

Sep 16, 2025
CVE-2025-37125
7.5 HIGH

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading …

Sep 16, 2025
CVE-2025-37124
8.6 HIGH

A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitation could allow an attacker …

Sep 16, 2025
CVE-2025-37123
8.8 HIGH

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of …

Sep 16, 2025
CVE-2025-9708
6.8 MEDIUM

A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying …

Sep 16, 2025
CVE-2025-43805
5.3 MEDIUM

Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not …

Sep 16, 2025
CVE-2025-10566
4.3 MEDIUM

A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=users. The …

Sep 16, 2025
CVE-2025-54391
9.1 CRITICAL

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypass Two-Factor Authentication (2FA) protection. The …

Sep 16, 2025
CVE-2025-10565
7.3 HIGH

A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_receiving. Executing …

Sep 16, 2025
CVE-2025-10564
7.3 HIGH

A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?action=delete_category. Performing manipulation of the …

Sep 16, 2025
CVE-2025-57631
9.8 CRITICAL

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

Sep 16, 2025
CVE-2025-56264
7.5 HIGH

The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.

Sep 16, 2025
CVE-2025-56263
8.8 HIGH

by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbitrary files. Users can upload files of any size and type.

Sep 16, 2025
CVE-2025-34187
8.8 HIGH

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts …

Sep 16, 2025
CVE-2025-34186
9.8 CRITICAL

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing …

Sep 16, 2025
CVE-2025-34185
7.5 HIGH

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from …

Sep 16, 2025
CVE-2025-34184
9.8 CRITICAL

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands …

Sep 16, 2025
CVE-2025-34183
7.5 HIGH

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from …

Sep 16, 2025
CVE-2025-10563
7.3 HIGH

A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_category. Such manipulation of …

Sep 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.