CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9169
3.5 LOW

A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation …

Aug 19, 2025
CVE-2025-9187
9.8 CRITICAL

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Aug 19, 2025
CVE-2025-9186
6.5 MEDIUM

Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142.

Aug 19, 2025
CVE-2025-9185
8.1 HIGH

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. …

Aug 19, 2025
CVE-2025-9184
8.1 HIGH

Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption …

Aug 19, 2025
CVE-2025-9183
6.5 MEDIUM

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2.

Aug 19, 2025
CVE-2025-9182
7.5 HIGH

Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, and Thunderbird 140.2.

Aug 19, 2025
CVE-2025-9181
6.5 MEDIUM

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and …

Aug 19, 2025
CVE-2025-9180
8.1 HIGH

Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird …

Aug 19, 2025
CVE-2025-9179
9.8 CRITICAL

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly …

Aug 19, 2025
CVE-2025-9168
3.5 LOW

A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. …

Aug 19, 2025
CVE-2025-9167
3.5 LOW

A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. …

Aug 19, 2025
CVE-2025-8364
4.3 MEDIUM

A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue …

Aug 19, 2025
CVE-2025-8042
9.8 CRITICAL

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability was fixed in Firefox 141.

Aug 19, 2025
CVE-2025-8041
5.3 MEDIUM

In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability was fixed in …

Aug 19, 2025
CVE-2025-55033
6.1 MEDIUM

Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially resulting in XSS attacks. This vulnerability …

Aug 19, 2025
CVE-2025-55032
6.1 MEDIUM

Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline, potentially allowing for XSS attacks. This …

Aug 19, 2025
CVE-2025-55031
9.8 CRITICAL

Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …

Aug 19, 2025
CVE-2025-55030
6.1 MEDIUM

Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for …

Aug 19, 2025
CVE-2025-55029
7.5 HIGH

Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed in Firefox for …

Aug 19, 2025
CVE-2025-55028
6.5 MEDIUM

Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This vulnerability was fixed …

Aug 19, 2025
CVE-2025-54145
9.1 CRITICAL

The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL …

Aug 19, 2025
CVE-2025-54144
5.4 MEDIUM

The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if …

Aug 19, 2025
CVE-2025-54143
9.8 CRITICAL

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed …

Aug 19, 2025
CVE-2025-9165
2.5 LOW

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead …

Aug 19, 2025
CVE-2025-9157
5.3 MEDIUM

A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. …

Aug 19, 2025
CVE-2025-9156
7.3 HIGH

A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the …

Aug 19, 2025
CVE-2025-9155
7.3 HIGH

A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget_password.php. Such manipulation …

Aug 19, 2025
CVE-2025-55740
6.5 MEDIUM

nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender …

Aug 19, 2025
CVE-2025-55737
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. …

Aug 19, 2025
CVE-2025-52337
6.5 MEDIUM

An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to execute arbitrary code via uploading a …

Aug 19, 2025
CVE-2025-51543
9.8 CRITICAL

An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password endpoint.

Aug 19, 2025
CVE-2025-50926
6.5 MEDIUM

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function.

Aug 19, 2025
CVE-2025-43744
5.4 MEDIUM

A stored DOM-based Cross-Site Scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.5, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, …

Aug 19, 2025
CVE-2025-43743
4.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 …

Aug 19, 2025
CVE-2025-2988
2.7 LOW

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized …

Aug 19, 2025
CVE-2025-9154
7.3 HIGH

A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This …

Aug 19, 2025
CVE-2025-9153
6.3 MEDIUM

A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of …

Aug 19, 2025
CVE-2025-55736
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges …

Aug 19, 2025
CVE-2025-55735
5.4 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post …

Aug 19, 2025
CVE-2025-55734
6.5 MEDIUM

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin …

Aug 19, 2025
CVE-2025-55733
9.6 CRITICAL

DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker …

Aug 19, 2025
CVE-2025-55306
9.8 CRITICAL

GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys …

Aug 19, 2025
CVE-2025-55303
6.1 MEDIUM

Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand …

Aug 19, 2025
CVE-2025-52338
5.3 MEDIUM

An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts …

Aug 19, 2025
CVE-2025-50891
7.2 HIGH

The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does …

Aug 19, 2025
CVE-2025-43745
6.5 MEDIUM

A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 …

Aug 19, 2025
CVE-2025-43737
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated …

Aug 19, 2025
CVE-2025-33008
5.4 MEDIUM

IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Aug 19, 2025
CVE-2025-31988
4.9 MEDIUM

HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.

Aug 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.