CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30038

The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security …

Aug 27, 2025
CVE-2025-30037

The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal services, but are instead publicly accessible without authentication …

Aug 27, 2025
CVE-2025-30036

Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can …

Aug 27, 2025
CVE-2025-2313

In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.

Aug 27, 2025
CVE-2021-4459
6.5 MEDIUM

An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.

Aug 27, 2025
CVE-2025-9514
3.7 LOW

A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak …

Aug 27, 2025
CVE-2025-9513
3.7 LOW

A flaw has been found in editso fuso up to 1.0.4-beta.7. This affects the function PenetrateRsaAndAesHandshake of the file src/net/penetrate/handshake/mod.rs. This manipulation of the argument …

Aug 27, 2025
CVE-2025-9511
7.3 HIGH

A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code of the file /visitor/addvisitor.php. Such manipulation of the argument ID …

Aug 27, 2025
CVE-2025-57846
7.8 HIGH

Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a local authenticated attacker may replace a service executable on …

Aug 27, 2025
CVE-2025-57797
7.8 HIGH

Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vulnerability is exploited, an authenticated local attacker may escalate privileges …

Aug 27, 2025
CVE-2025-9510
7.3 HIGH

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /branch/addbranch.php. The manipulation …

Aug 27, 2025
CVE-2025-9509
7.3 HIGH

A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of the file /report/fair_info_all.php. Performing manipulation of …

Aug 27, 2025
CVE-2025-9508
7.3 HIGH

A vulnerability was detected in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of the file /report/rented_info.php. The manipulation of the …

Aug 27, 2025
CVE-2025-48081
5.3 MEDIUM

Path Traversal: '.../...//' vulnerability in Printeers Printeers Print & Ship allows Path Traversal.This issue affects Printeers Print & Ship: from n/a through 1.17.0.

Aug 27, 2025
CVE-2025-9507
7.3 HIGH

A weakness has been identified in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/visitor_info.php. Executing manipulation of the argument …

Aug 27, 2025
CVE-2025-9506
7.3 HIGH

A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file /ajax.php?action=delete_plan. Such manipulation of the …

Aug 27, 2025
CVE-2025-9505
7.3 HIGH

A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_loan_type. This …

Aug 27, 2025
CVE-2025-9504
7.3 HIGH

A vulnerability was detected in Campcodes Online Loan Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_plan. The manipulation …

Aug 27, 2025
CVE-2025-49040
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery.This issue affects Backup Bolt: from n/a through <= 1.5.0.

Aug 27, 2025
CVE-2025-49039
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mibuthu Link View link-view allows Stored XSS.This issue affects Link View: from n/a …

Aug 27, 2025
CVE-2025-49035
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in chaimchaikin Admin Menu Groups admin-menu-groups allows Stored XSS.This issue affects Admin Menu Groups: …

Aug 27, 2025
CVE-2025-9503
7.3 HIGH

A security vulnerability has been detected in Campcodes Online Loan Management System 1.0. Affected is an unknown function of the file /ajax.php?action=save_borrower. The manipulation of …

Aug 27, 2025
CVE-2025-9502
7.3 HIGH

A weakness has been identified in Campcodes Online Loan Management System 1.0. This impacts an unknown function of the file /ajax.php?action=save_payment. Executing manipulation of the …

Aug 27, 2025
CVE-2025-7732
6.4 MEDIUM

The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers in all versions up to, and including, …

Aug 27, 2025
CVE-2025-8490
4.4 MEDIUM

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, …

Aug 27, 2025
CVE-2025-9277
6.4 MEDIUM

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_replace expression in all versions up to, and …

Aug 26, 2025
CVE-2025-57820

Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse …

Aug 26, 2025
CVE-2025-35115
8.1 HIGH

Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of …

Aug 26, 2025
CVE-2025-35114
7.5 HIGH

Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of …

Aug 26, 2025
CVE-2025-35113
5.9 MEDIUM

Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by …

Aug 26, 2025
CVE-2025-35112
4.1 MEDIUM

Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and …

Aug 26, 2025
CVE-2025-26417
4.0 MEDIUM

In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could …

Aug 26, 2025
CVE-2025-22413
4.0 MEDIUM

In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local information …

Aug 26, 2025
CVE-2025-22412
8.8 HIGH

In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote …

Aug 26, 2025
CVE-2025-22411
8.8 HIGH

In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) …

Aug 26, 2025
CVE-2025-22410
8.4 HIGH

In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of …

Aug 26, 2025
CVE-2025-22409
8.4 HIGH

In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation …

Aug 26, 2025
CVE-2025-22408
9.8 CRITICAL

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code …

Aug 26, 2025
CVE-2025-22407
5.5 MEDIUM

In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local information …

Aug 26, 2025
CVE-2025-22406
8.4 HIGH

In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation …

Aug 26, 2025
CVE-2025-22405
8.4 HIGH

In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of …

Aug 26, 2025
CVE-2025-22404
8.4 HIGH

In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation …

Aug 26, 2025
CVE-2025-22403
9.8 CRITICAL

In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code …

Aug 26, 2025
CVE-2025-0093
7.5 HIGH

In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with …

Aug 26, 2025
CVE-2025-0092
6.5 MEDIUM

In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with …

Aug 26, 2025
CVE-2025-0086
6.2 MEDIUM

In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to local information …

Aug 26, 2025
CVE-2025-0084
8.8 HIGH

In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over …

Aug 26, 2025
CVE-2025-0083
4.0 MEDIUM

In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information …

Aug 26, 2025
CVE-2025-0082
5.5 MEDIUM

In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confused deputy. This could lead …

Aug 26, 2025
CVE-2025-0081
7.5 HIGH

In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to remote denial of service …

Aug 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.