CVE Database

114866+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-42922
9.9 CRITICAL

SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. …

Sep 9, 2025
CVE-2025-42920
6.1 MEDIUM

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publicly …

Sep 9, 2025
CVE-2025-42918
4.3 MEDIUM

SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in …

Sep 9, 2025
CVE-2025-42917
6.5 MEDIUM

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has …

Sep 9, 2025
CVE-2025-42916
8.1 HIGH

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables …

Sep 9, 2025
CVE-2025-42915
5.4 MEDIUM

Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be …

Sep 9, 2025
CVE-2025-42914
3.1 LOW

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform …

Sep 9, 2025
CVE-2025-42913
3.1 LOW

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform …

Sep 9, 2025
CVE-2025-42912
6.5 MEDIUM

SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has …

Sep 9, 2025
CVE-2025-42911
5.0 MEDIUM

SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system …

Sep 9, 2025
CVE-2025-10121
6.3 MEDIUM

A flaw has been found in uverif up to 3.2. This affects the function addbatch of the file /admin/kami_list. This manipulation of the argument note …

Sep 9, 2025
CVE-2025-10120
8.8 HIGH

A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the …

Sep 9, 2025
CVE-2025-10118
7.3 HIGH

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the …

Sep 9, 2025
CVE-2025-10117
3.5 LOW

A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add …

Sep 9, 2025
CVE-2025-10116
7.3 HIGH

A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The …

Sep 9, 2025
CVE-2025-43774

Rejected reason: This CVE ID is rejected. The reported vulnerability was found to be present only in a feature that was under development and protected …

Sep 9, 2025
CVE-2025-10115
7.3 HIGH

A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes …

Sep 9, 2025
CVE-2025-10114
7.3 HIGH

A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the …

Sep 9, 2025
CVE-2025-58757
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in …

Sep 9, 2025
CVE-2025-58756
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, …

Sep 9, 2025
CVE-2025-58755
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compressed files. …

Sep 9, 2025
CVE-2025-43763
6.5 MEDIUM

A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through …

Sep 9, 2025
CVE-2025-10113
7.3 HIGH

A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of …

Sep 9, 2025
CVE-2025-10112
7.3 HIGH

A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation …

Sep 9, 2025
CVE-2025-58752
5.3 MEDIUM

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless …

Sep 8, 2025
CVE-2025-58751
5.3 MEDIUM

Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public …

Sep 8, 2025
CVE-2025-58746
9.0 CRITICAL

The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to …

Sep 8, 2025
CVE-2025-58745
9.9 CRITICAL

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only …

Sep 8, 2025
CVE-2025-58454
8.2 HIGH

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior inthe endpoint /WeGIA/html/memorando/listar_despachos.php, in the …

Sep 8, 2025
CVE-2025-58453
8.2 HIGH

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior in the endpoint /WeGIA/html/memorando/exibe_anexo.php, in …

Sep 8, 2025
CVE-2025-58452
6.1 MEDIUM

WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the listar_despachos.php endpoint of the WeGIA application prior …

Sep 8, 2025
CVE-2025-1761
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Sep 8, 2025
CVE-2025-10111
7.3 HIGH

A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The …

Sep 8, 2025
CVE-2025-10110
6.3 MEDIUM

A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads …

Sep 8, 2025
CVE-2025-10109
7.3 HIGH

A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the …

Sep 8, 2025
CVE-2025-58451

Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially exponential worst-case complexity. This could cause excessive CPU usage …

Sep 8, 2025
CVE-2025-58450

pREST (PostgreSQL REST), is an API that delivers an application on top of a Postgres database. SQL injection is possible in versions prior to 2.0.0-rc3. …

Sep 8, 2025
CVE-2025-58449

Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage …

Sep 8, 2025
CVE-2025-58444

The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector …

Sep 8, 2025
CVE-2025-58365

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, the blog application in XWiki …

Sep 8, 2025
CVE-2025-57817
7.2 HIGH

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not …

Sep 8, 2025
CVE-2025-57816
7.5 HIGH

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, …

Sep 8, 2025
CVE-2025-57815
6.5 MEDIUM

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for …

Sep 8, 2025
CVE-2025-57766
4.8 MEDIUM

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating …

Sep 8, 2025
CVE-2025-10108
7.3 HIGH

A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument …

Sep 8, 2025
CVE-2025-10106
6.3 MEDIUM

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.1. This affects an unknown part of the file /cms/collect/search. Such manipulation of the argument …

Sep 8, 2025
CVE-2025-52288
7.5 HIGH

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) component, in Open5GS thru 2.7.5 allowing attackers to cause a …

Sep 8, 2025
CVE-2025-10105
6.3 MEDIUM

A flaw has been found in yanyutao0402 ChanCMS up to 3.3.1. Affected by this issue is some unknown functionality of the file /cms/article/search. This manipulation …

Sep 8, 2025
CVE-2025-54994

@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13, the MCP Server is written in a way that is …

Sep 8, 2025
CVE-2025-53838
5.4 MEDIUM

LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discovered in versions prior to 2.1.9 that allows an …

Sep 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.