CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-4643

Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token …

Aug 29, 2025
CVE-2025-8150
6.4 MEDIUM

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter and Countdown widgets in all versions up …

Aug 29, 2025
CVE-2024-13987
5.9 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Synology RADIUS Server allows remote authenticated users with administrator privileges to read or …

Aug 29, 2025
CVE-2025-54777
4.3 MEDIUM

Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Email certificate, it may cause a …

Aug 29, 2025
CVE-2025-9441
6.5 MEDIUM

The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all versions up to, and including, 1.2 …

Aug 29, 2025
CVE-2025-9374
4.3 MEDIUM

The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due …

Aug 29, 2025
CVE-2025-8619
6.4 MEDIUM

The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map Block URL in all versions up …

Aug 29, 2025
CVE-2025-8290
6.4 MEDIUM

The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.0.6 due …

Aug 29, 2025
CVE-2025-8147
4.3 MEDIUM

The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscache_activatePlugin() function in all versions up to, …

Aug 29, 2025
CVE-2025-53508
7.2 HIGH

Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed and sensitive information may …

Aug 29, 2025
CVE-2025-53507
6.5 MEDIUM

Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration information, such as admin password, may be disclosed. …

Aug 29, 2025
CVE-2025-9639
7.5 HIGH

The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

Aug 29, 2025
CVE-2025-9619
5.3 MEDIUM

A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of the file /basico/webservice/imprimir-danfe/id/. Performing manipulation …

Aug 29, 2025
CVE-2025-9610
7.3 HIGH

A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue affects some unknown processing of the file /create_account.php. This manipulation of the …

Aug 29, 2025
CVE-2025-9609
6.3 MEDIUM

A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulation results in improper authorization. …

Aug 29, 2025
CVE-2025-8861
9.8 CRITICAL

TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents.

Aug 29, 2025
CVE-2025-8858
7.5 HIGH

Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Aug 29, 2025
CVE-2025-8857
9.8 CRITICAL

Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source …

Aug 29, 2025
CVE-2025-9608
6.3 MEDIUM

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/view of the component Formula de …

Aug 29, 2025
CVE-2025-9607
6.3 MEDIUM

A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/TabelaArredondamento/view of the …

Aug 29, 2025
CVE-2025-9606
6.3 MEDIUM

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing manipulation of …

Aug 29, 2025
CVE-2025-9605
9.8 CRITICAL

A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the …

Aug 29, 2025
CVE-2025-58333

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58332

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58331

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58330

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58329

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58328

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58327

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58326

Rejected reason: Not used

Aug 29, 2025
CVE-2025-58323
7.7 HIGH

NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege …

Aug 29, 2025
CVE-2025-39247
8.6 HIGH

There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.

Aug 29, 2025
CVE-2025-39246
5.3 MEDIUM

There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via …

Aug 29, 2025
CVE-2025-39245
4.7 MEDIUM

There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.

Aug 29, 2025
CVE-2025-9604
3.7 LOW

A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backend/domain/plugin/encrypt/aes.go. The manipulation of the argument …

Aug 29, 2025
CVE-2025-9603
6.3 MEDIUM

A vulnerability was determined in Telesquare TLR-2005KSH 1.2.4. The affected element is an unknown function of the file /cgi-bin/internet.cgi?Command=lanCfg. Executing manipulation of the argument Hostname …

Aug 29, 2025
CVE-2025-9602
6.3 MEDIUM

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. …

Aug 29, 2025
CVE-2025-9601
7.3 HIGH

A vulnerability was detected in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /setting/employee_salary_setup.php. The manipulation of the argument ddlEmpName …

Aug 29, 2025
CVE-2025-9600
7.3 HIGH

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /setting/member_type_setup.php. The …

Aug 29, 2025
CVE-2025-9599
7.3 HIGH

A weakness has been identified in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /setting/month_setup.php. Executing manipulation …

Aug 29, 2025
CVE-2025-54142
4.0 MEDIUM

Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within …

Aug 29, 2025
CVE-2025-43284
5.5 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app …

Aug 29, 2025
CVE-2025-43268
7.8 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root …

Aug 29, 2025
CVE-2025-43255
3.3 LOW

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app …

Aug 29, 2025
CVE-2025-43187
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Running an …

Aug 29, 2025
CVE-2025-40927
7.3 HIGH

CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP response splitting flaw in CGI::Simple that allows …

Aug 29, 2025
CVE-2024-54568
4.3 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. Parsing a maliciously crafted file may lead to an …

Aug 29, 2025
CVE-2024-54554
5.5 MEDIUM

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive …

Aug 29, 2025
CVE-2024-44271
3.3 LOW

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record the screen without …

Aug 29, 2025
CVE-2025-9598
7.3 HIGH

A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of the file /setting/year_setup.php. Performing manipulation of the …

Aug 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.