CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64541
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-56429
6.1 MEDIUM

Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component.

Dec 10, 2025
CVE-2025-34430
4.3 MEDIUM

1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not implement CSRF …

Dec 10, 2025
CVE-2025-65754
6.1 MEDIUM

Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.

Dec 10, 2025
CVE-2025-67643
4.3 MEDIUM

Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to …

Dec 10, 2025
CVE-2025-67642
4.3 MEDIUM

Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and …

Dec 10, 2025
CVE-2025-67641
5.4 MEDIUM

Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through …

Dec 10, 2025
CVE-2025-67640
5.0 MEDIUM

Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a …

Dec 10, 2025
CVE-2025-67638
4.3 MEDIUM

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers …

Dec 10, 2025
CVE-2025-67637
4.3 MEDIUM

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be …

Dec 10, 2025
CVE-2025-67636
4.3 MEDIUM

A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.

Dec 10, 2025
CVE-2025-65815
6.5 MEDIUM

A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory …

Dec 10, 2025
CVE-2025-65814
6.5 MEDIUM

A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal.

Dec 10, 2025
CVE-2025-52493
6.5 MEDIUM

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the …

Dec 10, 2025
CVE-2025-65803
6.5 MEDIUM

An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Dec 10, 2025
CVE-2025-13125
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers.This …

Dec 10, 2025
CVE-2024-2105
6.5 MEDIUM

An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.

Dec 10, 2025
CVE-2025-66004
5.7 MEDIUM

A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba.

Dec 10, 2025
CVE-2025-14087
5.6 MEDIUM

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or …

Dec 10, 2025
CVE-2025-9056
5.3 MEDIUM

Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.

Dec 10, 2025
CVE-2025-13677
4.9 MEDIUM

The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.2. This is due to insufficient …

Dec 10, 2025
CVE-2025-67485
5.3 MEDIUM

mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers …

Dec 10, 2025
CVE-2025-67502
5.4 MEDIUM

Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites …

Dec 10, 2025
CVE-2025-67499
6.6 MEDIUM

The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all …

Dec 10, 2025
CVE-2025-64898
4.3 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker …

Dec 10, 2025
CVE-2025-64897
5.6 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass …

Dec 10, 2025
CVE-2025-61823
6.2 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary …

Dec 10, 2025
CVE-2025-61822
6.2 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker …

Dec 10, 2025
CVE-2025-61821
6.8 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary …

Dec 10, 2025
CVE-2025-67496
4.3 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting …

Dec 9, 2025
CVE-2025-36437
4.3 MEDIUM

IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could aid in further attacks against the system.

Dec 9, 2025
CVE-2025-34425
6.1 MEDIUM

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext parameter of /Mondo/lang/sys/Forms/MAI/compose.aspx. The WindowContext value is not properly sanitized …

Dec 9, 2025
CVE-2025-64896
5.5 MEDIUM

Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could lead to …

Dec 9, 2025
CVE-2023-53773
5.3 MEDIUM

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers …

Dec 9, 2025
CVE-2021-47729
5.4 MEDIUM

Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. …

Dec 9, 2025
CVE-2021-47727
5.3 MEDIUM

Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to …

Dec 9, 2025
CVE-2021-47724
6.5 MEDIUM

STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download …

Dec 9, 2025
CVE-2021-47704
6.5 MEDIUM

OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests …

Dec 9, 2025
CVE-2021-47702
4.3 MEDIUM

OpenBMCS 2.4 contains a CSRF vulnerability that allows attackers to perform actions with administrative privileges by exploiting the sendFeedback.php endpoint. Attackers can submit malicious requests …

Dec 9, 2025
CVE-2025-66625
4.9 MEDIUM

Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an …

Dec 9, 2025
CVE-2025-9614
6.5 MEDIUM

An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on re-keying and stream flushing during device …

Dec 9, 2025
CVE-2025-9613
6.5 MEDIUM

A vulnerability was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on tag reuse after completion timeouts may …

Dec 9, 2025
CVE-2025-9612
5.1 MEDIUM

An issue was discovered in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, where insufficient guidance on Transaction Layer Packet (TLP) ordering and …

Dec 9, 2025
CVE-2025-65572
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to execute arbitrary code via the (1) config, (2) filename, or (3) extratext …

Dec 9, 2025
CVE-2025-65300
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28) in the Account Settings module, where unsanitized user input in Address …

Dec 9, 2025
CVE-2025-64894
5.5 MEDIUM

DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit …

Dec 9, 2025
CVE-2025-64670
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.

Dec 9, 2025
CVE-2025-64667
5.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Dec 9, 2025
CVE-2025-64471
4.9 MEDIUM

A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 …

Dec 9, 2025
CVE-2025-62631
5.6 MEDIUM

An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker …

Dec 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.