CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-41039
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41038
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41037
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41036
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41035
6.5 MEDIUM

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions …

Sep 4, 2025
CVE-2025-41034
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2025-41033
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2025-41032
9.8 CRITICAL

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through …

Sep 4, 2025
CVE-2024-34598
7.7 HIGH

Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store.

Sep 4, 2025
CVE-2022-39888
4.3 MEDIUM

Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.

Sep 4, 2025
CVE-2025-9942
6.3 MEDIUM

A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulation leads to …

Sep 4, 2025
CVE-2025-9941
6.3 MEDIUM

A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the …

Sep 4, 2025
CVE-2025-9940
3.5 LOW

A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /feature.php. Performing manipulation of the argument …

Sep 4, 2025
CVE-2025-9939
3.5 LOW

A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /propertyview.php. Such …

Sep 4, 2025
CVE-2025-9938
8.8 HIGH

A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the file /yyxz.asp. This manipulation of the argument …

Sep 4, 2025
CVE-2025-9937
5.4 MEDIUM

A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulation results in improper authorization. …

Sep 4, 2025
CVE-2025-9936
4.3 MEDIUM

A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The …

Sep 4, 2025
CVE-2025-9935
7.3 HIGH

A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_4159F8 of the file /web_cste/cgi-bin/cstecgi.cgi. Executing manipulation can lead to command injection. …

Sep 4, 2025
CVE-2025-9934
6.3 MEDIUM

A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in …

Sep 4, 2025
CVE-2025-9933
7.3 HIGH

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such …

Sep 4, 2025
CVE-2025-9932
7.3 HIGH

A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This …

Sep 4, 2025
CVE-2025-9931
4.3 MEDIUM

A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation …

Sep 4, 2025
CVE-2025-9930
7.3 HIGH

A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulation of …

Sep 4, 2025
CVE-2025-9929
2.4 LOW

A weakness has been identified in code-projects Responsive Blog Site 1.0. This affects an unknown function of the file blogs_view.php. Executing manipulation of the argument …

Sep 4, 2025
CVE-2025-9616
5.3 MEDIUM

The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or …

Sep 4, 2025
CVE-2025-9519
7.2 HIGH

The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 via the plugin's shortcodes. This …

Sep 4, 2025
CVE-2025-9518
7.2 HIGH

The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on the 'debug_path' parameter in all versions …

Sep 4, 2025
CVE-2025-9517
7.2 HIGH

The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This …

Sep 4, 2025
CVE-2025-9516
4.9 MEDIUM

The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This …

Sep 4, 2025
CVE-2025-9467

When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. Users of …

Sep 4, 2025
CVE-2025-6984
7.5 HIGH

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. …

Sep 4, 2025
CVE-2025-6085
7.2 HIGH

The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions …

Sep 4, 2025
CVE-2025-58701

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58700

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58699

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58698

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58697

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58696

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58695

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58694

Rejected reason: Not used

Sep 4, 2025
CVE-2025-58358
7.5 HIGH

Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain a command injection vulnerability, caused by the unsanitized …

Sep 4, 2025
CVE-2025-58357
9.6 CRITICAL

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 contains a vulnerability in the chat page's script gadgets that …

Sep 4, 2025
CVE-2025-58355
7.7 HIGH

Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled …

Sep 4, 2025
CVE-2025-58171

Rejected reason: This CVE is a duplicate of another CVE.

Sep 4, 2025
CVE-2025-58064

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a …

Sep 4, 2025
CVE-2025-58057
7.5 HIGH

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, …

Sep 4, 2025
CVE-2025-43772

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not …

Sep 4, 2025
CVE-2025-36909
5.3 MEDIUM

Information disclosure

Sep 4, 2025
CVE-2025-36908
6.7 MEDIUM

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36907
7.3 HIGH

In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.