CVE Database

138577+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-66909
7.5 HIGH

Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerability. The ExtendedOpenCVImage class in ai/djl/opencv/ExtendedOpenCVImage.java loads images using OpenCV's imread() …

Dec 19, 2025
CVE-2025-66908
5.3 MEDIUM

Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR image upload functionality. The OcrController in turms-ai-serving/src/main/java/im/turms/ai/domain/ocr/controller/OcrController.java uses the …

Dec 19, 2025
CVE-2025-50681
7.5 HIGH

igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a crafted IGMPv3 membership report packet with a …

Dec 19, 2025
CVE-2025-14952
7.3 HIGH

A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Performing a manipulation of the argument …

Dec 19, 2025
CVE-2025-14951
7.3 HIGH

A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unknown function of the file /home.php. Such manipulation …

Dec 19, 2025
CVE-2025-14950
7.3 HIGH

A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.php. This manipulation of …

Dec 19, 2025
CVE-2025-1928
9.1 CRITICAL

Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation.This issue affects Online Food Delivery …

Dec 19, 2025
CVE-2025-14946
4.8 MEDIUM

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This …

Dec 19, 2025
CVE-2025-14882

An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible …

Dec 19, 2025
CVE-2025-14881

Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible …

Dec 19, 2025
CVE-2025-1927
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Cross Site Request Forgery.This issue affects Online Food Delivery System: …

Dec 19, 2025
CVE-2025-1885
5.4 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Phishing, Forceful Browsing.This issue affects Online Food …

Dec 19, 2025
CVE-2025-14847
7.5 HIGH KEV

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB …

Dec 19, 2025
CVE-2025-66524
8.8 HIGH

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state …

Dec 19, 2025
CVE-2025-14455
5.4 MEDIUM

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is …

Dec 19, 2025
CVE-2025-12361
4.3 MEDIUM

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, …

Dec 19, 2025
CVE-2025-14151
7.2 HIGH

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' parameter in the slimtrack AJAX action in all versions up …

Dec 19, 2025
CVE-2025-11747
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 …

Dec 19, 2025
CVE-2025-66522
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize …

Dec 19, 2025
CVE-2025-66521
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature. A crafted payload can be injected as the certificate name, which …

Dec 19, 2025
CVE-2025-66520
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied SVG files are not properly sanitized …

Dec 19, 2025
CVE-2025-66519
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A crafted payload can be injected into the “Create new Layer” …

Dec 19, 2025
CVE-2025-66502
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which …

Dec 19, 2025
CVE-2025-66501
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A crafted payload can be stored …

Dec 19, 2025
CVE-2025-66500
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script …

Dec 19, 2025
CVE-2025-66499
7.8 HIGH

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer overflow in the …

Dec 19, 2025
CVE-2025-66498
5.3 MEDIUM

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening …

Dec 19, 2025
CVE-2025-66497
5.3 MEDIUM

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening …

Dec 19, 2025
CVE-2025-66496
5.3 MEDIUM

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening …

Dec 19, 2025
CVE-2025-66495
7.8 HIGH

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF …

Dec 19, 2025
CVE-2025-66494
7.8 HIGH

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by …

Dec 19, 2025
CVE-2025-66493
7.8 HIGH

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening …

Dec 19, 2025
CVE-2025-66174
6.5 MEDIUM

There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with …

Dec 19, 2025
CVE-2025-66173
6.2 MEDIUM

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with …

Dec 19, 2025
CVE-2025-14449
6.4 MEDIUM

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-form shortcode in all versions up to, and including, …

Dec 19, 2025
CVE-2025-14267
4.9 MEDIUM

Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7

Dec 19, 2025
CVE-2025-13999
7.2 HIGH

The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions …

Dec 19, 2025
CVE-2025-13754
5.3 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Dec 19, 2025
CVE-2025-13008

An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using …

Dec 19, 2025
CVE-2025-13307
7.2 HIGH

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under …

Dec 19, 2025
CVE-2025-14546
6.3 MEDIUM

Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth state parameter during …

Dec 19, 2025
CVE-2025-68491

Rejected reason: Not used

Dec 19, 2025
CVE-2025-68490

Rejected reason: Not used

Dec 19, 2025
CVE-2025-68489

Rejected reason: Not used

Dec 19, 2025
CVE-2025-68488

Rejected reason: Not used

Dec 19, 2025
CVE-2025-68487

Rejected reason: Not used

Dec 19, 2025
CVE-2025-68486

Rejected reason: Not used

Dec 19, 2025
CVE-2025-68485

Rejected reason: Not used

Dec 19, 2025
CVE-2025-68484

Rejected reason: Not used

Dec 19, 2025
CVE-2025-68483

Rejected reason: Not used

Dec 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.