CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0080
7.8 HIGH

In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack. This could lead to local escalation …

Aug 26, 2025
CVE-2025-0079
7.8 HIGH

In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error in the code. This …

Aug 26, 2025
CVE-2025-0078
8.8 HIGH

In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to local …

Aug 26, 2025
CVE-2025-0075
9.8 CRITICAL

In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code …

Aug 26, 2025
CVE-2025-0074
9.8 CRITICAL

In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code …

Aug 26, 2025
CVE-2024-49740
5.5 MEDIUM

In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution …

Aug 26, 2025
CVE-2023-21125
8.0 HIGH

In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of …

Aug 26, 2025
CVE-2025-9492
7.3 HIGH

A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the file /addclient1.php. Executing manipulation of the argument …

Aug 26, 2025
CVE-2024-47192
5.3 MEDIUM

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that …

Aug 26, 2025
CVE-2024-35203
6.1 MEDIUM

Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via …

Aug 26, 2025
CVE-2025-55443
9.1 CRITICAL

Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files …

Aug 26, 2025
CVE-2025-52353
9.8 CRITICAL

An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload …

Aug 26, 2025
CVE-2025-50971
7.5 HIGH

Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.

Aug 26, 2025
CVE-2025-9478
8.8 HIGH

Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 26, 2025
CVE-2025-50975
5.4 MEDIUM

IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr, allowing …

Aug 26, 2025
CVE-2025-23315
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious data created by an attacker could cause a …

Aug 26, 2025
CVE-2025-23314
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection …

Aug 26, 2025
CVE-2025-23313
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection …

Aug 26, 2025
CVE-2025-23312
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker could cause a code …

Aug 26, 2025
CVE-2025-23307
7.8 HIGH

NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. A successful exploit of …

Aug 26, 2025
CVE-2025-57818
6.3 MEDIUM

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to version 2.0.1, a server-side request forgery (SSRF) vulnerability was discovered in Firecrawl's webhook …

Aug 26, 2025
CVE-2025-57803
7.5 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit …

Aug 26, 2025
CVE-2025-55298
7.5 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability …

Aug 26, 2025
CVE-2025-50976
6.1 MEDIUM

IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query parameters, resulting in a reflected cross-site …

Aug 26, 2025
CVE-2025-9491
7.8 HIGH

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. …

Aug 26, 2025
CVE-2025-57425
6.1 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated attacker to inject malicious JavaScript into the 'question' and 'answer' …

Aug 26, 2025
CVE-2025-55212
3.7 LOW

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only …

Aug 26, 2025
CVE-2025-52184
6.1 MEDIUM

Cross Site Scripting vulnerability in Helpy.io v.2.8.0 allows a remote attacker to escalate privileges via the New Topic Ticket funtion.

Aug 26, 2025
CVE-2025-50974
6.5 MEDIUM

The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell command. An unauthenticated …

Aug 26, 2025
CVE-2025-36729
7.2 HIGH

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device including the master …

Aug 26, 2025
CVE-2025-2697
7.4 HIGH

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim …

Aug 26, 2025
CVE-2025-1994
7.8 HIGH

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due to the use of unsafe …

Aug 26, 2025
CVE-2025-1494
6.1 MEDIUM

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to …

Aug 26, 2025
CVE-2025-57813
5.9 MEDIUM

traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, such as OAuth tokens, …

Aug 26, 2025
CVE-2025-57810
7.5 HIGH

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU …

Aug 26, 2025
CVE-2025-56432
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in …

Aug 26, 2025
CVE-2025-6366
8.8 HIGH

The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin …

Aug 26, 2025
CVE-2025-52219
6.5 MEDIUM

SelectZero SelectZero Data Observability Platform before 2025.5.2 contains an Open Redirect vulnerability. Legacy UI fields can be used to create arbitrary external links via HTML …

Aug 26, 2025
CVE-2025-52218
7.5 HIGH

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified parameters allows attackers to inject arbitrary text …

Aug 26, 2025
CVE-2025-52217
5.4 MEDIUM

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to HTML Injection. Legacy UI fields improperly handle user-supplied input, allowing injection of arbitrary HTML.

Aug 26, 2025
CVE-2025-52037
6.1 MEDIUM

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=sites. The manipulation of the title of …

Aug 26, 2025
CVE-2025-52036
6.1 MEDIUM

A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=categories. The manipulation of the title of …

Aug 26, 2025
CVE-2025-52035
6.1 MEDIUM

A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. …

Aug 26, 2025
CVE-2025-25737
6.8 MEDIUM

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User …

Aug 26, 2025
CVE-2025-25736
6.8 MEDIUM

Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to contain Android Debug Bridge (ADB) pre-installed (/mnt/c3platpersistent/opt/platform-tools/adb) and enabled by default, allowing unauthenticated …

Aug 26, 2025
CVE-2025-25735
4.6 MEDIUM

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack SPI Protected Range Registers (PRRs), allowing attackers with software …

Aug 26, 2025
CVE-2025-25734
6.8 MEDIUM

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute …

Aug 26, 2025
CVE-2025-25733
3.5 LOW

Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows physically proximate attackers …

Aug 26, 2025
CVE-2025-25732
6.8 MEDIUM

Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 allows attackers to replace password …

Aug 26, 2025
CVE-2024-39335
9.1 CRITICAL

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via …

Aug 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.