CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53192
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using …

Aug 18, 2025
CVE-2025-4371
6.8 MEDIUM

A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write …

Aug 18, 2025
CVE-2025-32992
8.5 HIGH

Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.

Aug 18, 2025
CVE-2025-43731
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.8, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, …

Aug 18, 2025
CVE-2025-7693

A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller enters a solid red Fault LED state …

Aug 18, 2025
CVE-2025-55300

Komari is a lightweight, self-hosted server monitoring tool designed to provide a simple and efficient solution for monitoring server performance. Prior to 1.0.4-fix1, WebSocket upgrader …

Aug 18, 2025
CVE-2025-55299
9.4 CRITICAL

VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty …

Aug 18, 2025
CVE-2025-55296
5.5 MEDIUM

librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. …

Aug 18, 2025
CVE-2025-55293
9.4 CRITICAL

Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with …

Aug 18, 2025
CVE-2025-55291
7.1 HIGH

Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag page is not properly sanitized. …

Aug 18, 2025
CVE-2025-55288
5.5 MEDIUM

Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Reflected Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could …

Aug 18, 2025
CVE-2025-55287
5.4 MEDIUM

Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could …

Aug 18, 2025
CVE-2025-55283
9.1 CRITICAL

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superuser inside PostgreSQL databases during …

Aug 18, 2025
CVE-2025-55282
9.1 CRITICAL

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to superuser inside …

Aug 18, 2025
CVE-2025-55214

Copier library and CLI app for rendering project templates. From 7.1.0 to before 9.9.1, Copier suggests that it's safe to generate a project from a …

Aug 18, 2025
CVE-2025-55205
9.0 CRITICAL

Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant users to inject …

Aug 18, 2025
CVE-2025-55201

Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write arbitrary files because Copier exposes …

Aug 18, 2025
CVE-2025-54234
2.7 LOW

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limited file system read. A …

Aug 18, 2025
CVE-2025-3639

Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, 7.4 GA …

Aug 18, 2025
CVE-2025-54421
7.2 HIGH

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated …

Aug 18, 2025
CVE-2025-54118
5.3 MEDIUM

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker …

Aug 18, 2025
CVE-2025-54117
9.0 CRITICAL

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated …

Aug 18, 2025
CVE-2025-4962
7.7 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up to 0.8.8. This vulnerability …

Aug 18, 2025
CVE-2025-43732
2.7 LOW

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 …

Aug 18, 2025
CVE-2025-36120
8.8 HIGH

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization …

Aug 18, 2025
CVE-2025-33100
6.2 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound …

Aug 18, 2025
CVE-2025-33090
7.5 HIGH

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would …

Aug 18, 2025
CVE-2025-27909
5.4 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name …

Aug 18, 2025
CVE-2025-1759
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Aug 18, 2025
CVE-2024-49827
3.7 LOW

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to excessive data exposure, allowing attackers to access sensitive information without proper filtering.

Aug 18, 2025
CVE-2025-43733
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript …

Aug 18, 2025
CVE-2025-47206
8.1 HIGH

An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the …

Aug 18, 2025
CVE-2025-41242
5.9 MEDIUM

Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. An application can be vulnerable when …

Aug 18, 2025
CVE-2025-5296
7.3 HIGH

CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to …

Aug 18, 2025
CVE-2025-6625
7.5 HIGH

CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.

Aug 18, 2025
CVE-2025-57703
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57702
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57701
6.1 MEDIUM

DIAEnergie - Reflected Cross-site Scripting

Aug 18, 2025
CVE-2025-57700
6.1 MEDIUM

DIAEnergie - Stored Cross-site Scripting

Aug 18, 2025
CVE-2025-9109
3.7 LOW

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of …

Aug 18, 2025
CVE-2025-9108
4.3 MEDIUM

Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of rendered ui layers. It is possible to launch …

Aug 18, 2025
CVE-2025-9107
4.3 MEDIUM

A vulnerability was determined in Portabilis i-Diario up to 1.5.0. This impacts an unknown function of the file /alunos/search_autocomplete. Executing manipulation of the argument q …

Aug 18, 2025
CVE-2025-9106
3.5 LOW

A vulnerability was found in Portabilis i-Diario up to 1.5.0. This affects an unknown function of the file /planos-de-ensino-por-disciplina/ of the component Informações Adicionais Page. …

Aug 18, 2025
CVE-2025-9105
3.5 LOW

A vulnerability has been found in Portabilis i-Diario up to 1.5.0. The impacted element is an unknown function of the file /planos-de-ensino-por-areas-de-conhecimento/ of the component …

Aug 18, 2025
CVE-2025-9104
3.5 LOW

A flaw has been found in Portabilis i-Diario up to 1.5.0. The affected element is an unknown function of the file /planos-de-aulas-por-disciplina/ of the component …

Aug 18, 2025
CVE-2025-9103
2.4 LOW

A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site …

Aug 18, 2025
CVE-2025-9102
5.3 MEDIUM

A security vulnerability has been detected in 1&1 Mail & Media mail.com App 8.8.0 on Android. Affected is an unknown function of the file AndroidManifest.xml …

Aug 18, 2025
CVE-2025-9101
3.5 LOW

A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the component Tag …

Aug 18, 2025
CVE-2025-9100
5.3 MEDIUM

A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article …

Aug 18, 2025
CVE-2025-9099
6.3 MEDIUM

A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of …

Aug 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.