CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8918
2.4 LOW

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /intranet/educar_instituicao_cad.php of the component Editar Page. …

Aug 13, 2025
CVE-2025-51452
9.8 CRITICAL

In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

Aug 13, 2025
CVE-2025-50614
7.5 HIGH

A buffer overflow vulnerability has been discovered in the Netis WF2880 v2.1.40207 in the FUN_0047151c function of the cgitest.cgi file. Attackers can trigger this vulnerability …

Aug 13, 2025
CVE-2025-50613
7.5 HIGH

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00475e1c function of the cgitest.cgi file. Attackers can trigger this vulnerability by …

Aug 13, 2025
CVE-2025-50612
7.5 HIGH

A buffer overflow vulnerability has been discovered in the Netis WF2880 v2.1.40207 in the FUN_004743f8 function of the cgitest.cgi file. Attackers can trigger this vulnerability …

Aug 13, 2025
CVE-2025-50611
7.5 HIGH

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00473154 function of the cgitest.cgi file. Attackers can trigger this vulnerability by …

Aug 13, 2025
CVE-2025-50610
7.5 HIGH

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00476598 function of the cgitest.cgi file. Attackers can trigger this vulnerability by …

Aug 13, 2025
CVE-2025-50609
7.5 HIGH

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the Function_00465620 of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling …

Aug 13, 2025
CVE-2025-50608
7.5 HIGH

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgitest.cgi file. Attackers can trigger this vulnerability by …

Aug 13, 2025
CVE-2025-8941
7.8 HIGH

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to …

Aug 13, 2025
CVE-2025-55163
7.5 HIGH

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability …

Aug 13, 2025
CVE-2025-54809
7.4 HIGH

F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of …

Aug 13, 2025
CVE-2025-54500
5.3 MEDIUM

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset …

Aug 13, 2025
CVE-2025-53859
3.7 LOW

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; …

Aug 13, 2025
CVE-2025-52585
7.5 HIGH

When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed …

Aug 13, 2025
CVE-2025-51691
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability found in MarkTwo commit e3a1d3f90cce4ea9c26efcbbf3a1cbfb9dcdb298 (May 2025) allows a remote attacker to execute arbitrary code via a crafted script input to …

Aug 13, 2025
CVE-2025-50690
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in SpatialReference.org (OSGeo/spatialreference.org) versions prior to 2025-05-17 (commit 2120adfa17ddd535bd0f539e6c4988fa3a2cb491). The vulnerability is caused by improper handling of user input …

Aug 13, 2025
CVE-2025-50635
7.5 HIGH

A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function of the cgitest.cgi file. Attackers can trigger …

Aug 13, 2025
CVE-2025-50251
9.1 CRITICAL

Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.

Aug 13, 2025
CVE-2025-48500
7.3 HIGH

A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the …

Aug 13, 2025
CVE-2025-46405
7.5 HIGH

When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions …

Aug 13, 2025
CVE-2025-55668
6.5 MEDIUM

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through …

Aug 13, 2025
CVE-2025-55160
6.1 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in …

Aug 13, 2025
CVE-2025-55154
8.8 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage …

Aug 13, 2025
CVE-2025-55005
5.5 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB …

Aug 13, 2025
CVE-2025-55004
7.6 HIGH

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around …

Aug 13, 2025
CVE-2025-54791
5.3 MEDIUM

OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot …

Aug 13, 2025
CVE-2025-54382
9.6 CRITICAL

Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry …

Aug 13, 2025
CVE-2025-54074
9.8 CRITICAL

Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio is vulnerable to OS Command Injection …

Aug 13, 2025
CVE-2025-52392
5.4 MEDIUM

Soosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An attacker can repeatedly submit login attempts …

Aug 13, 2025
CVE-2025-52386
5.4 MEDIUM

CycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file

Aug 13, 2025
CVE-2025-32451
8.8 HIGH

A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript code inside a malicious …

Aug 13, 2025
CVE-2025-8908
6.3 MEDIUM

A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this issue is some unknown functionality of the file …

Aug 13, 2025
CVE-2025-8907
7.0 HIGH

A vulnerability was found in H3C M2 NAS V100R006. Affected by this vulnerability is an unknown functionality of the component Webserver Configuration. The manipulation leads …

Aug 13, 2025
CVE-2025-8671
7.5 HIGH

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource …

Aug 13, 2025
CVE-2025-48989
7.5 HIGH

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 …

Aug 13, 2025
CVE-2025-55280

This vulnerability exists in ZKTeco WL20 due to storage of Wi-Fi credentials, configuration data and system data in plaintext within the device firmware. An attacker …

Aug 13, 2025
CVE-2025-55279

This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. An attacker with physical access could exploit …

Aug 13, 2025
CVE-2025-54465

This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the device firmware. An attacker with physical access …

Aug 13, 2025
CVE-2025-54464

This vulnerability exists in ZKTeco WL20 due to storage of admin and user credentials without encryption in the device firmware. An attacker with physical access …

Aug 13, 2025
CVE-2025-8916

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the …

Aug 13, 2025
CVE-2025-8914
6.5 MEDIUM

Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Aug 13, 2025
CVE-2025-8913
9.8 CRITICAL

Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

Aug 13, 2025
CVE-2025-8912
7.5 HIGH

Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system …

Aug 13, 2025
CVE-2025-8911
6.1 MEDIUM

Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through …

Aug 13, 2025
CVE-2025-8910
6.1 MEDIUM

Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through …

Aug 13, 2025
CVE-2025-8909
6.5 MEDIUM

Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download …

Aug 13, 2025
CVE-2025-55345
8.8 HIGH

Using Codex CLI in workspace-write mode inside a malicious context (repo, directory, etc) could lead to arbitrary file overwrite and potentially remote code execution due …

Aug 13, 2025
CVE-2025-8762
6.8 MEDIUM

A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The manipulation …

Aug 13, 2025
CVE-2025-8761
7.5 HIGH

A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the component Backend IPC Server. The …

Aug 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.