CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-66963
5.5 MEDIUM

An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html

Dec 15, 2025
CVE-2025-66844
9.1 CRITICAL

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration …

Dec 15, 2025
CVE-2025-66843
5.4 MEDIUM

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content …

Dec 15, 2025
CVE-2025-60786
8.8 HIGH

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a crafted …

Dec 15, 2025
CVE-2025-14387
6.4 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to …

Dec 15, 2025
CVE-2025-13888
9.1 CRITICAL

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in …

Dec 15, 2025
CVE-2025-13824

A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED …

Dec 15, 2025
CVE-2025-13823

A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The …

Dec 15, 2025
CVE-2024-44599
8.3 HIGH

FNT Command 13.4.0 is vulnerable to Directory Traversal.

Dec 15, 2025
CVE-2024-44598
8.8 HIGH

FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.

Dec 15, 2025
CVE-2025-34412

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulnerability in a SaaS product that …

Dec 15, 2025
CVE-2025-34411

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulnerability in a SaaS product that …

Dec 15, 2025
CVE-2025-34181

NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can …

Dec 15, 2025
CVE-2025-34180

NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a …

Dec 15, 2025
CVE-2025-34179

NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized …

Dec 15, 2025
CVE-2025-14383
7.5 HIGH

The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 …

Dec 15, 2025
CVE-2025-14156
9.8 CRITICAL

The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is …

Dec 15, 2025
CVE-2025-14003
4.3 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Dec 15, 2025
CVE-2025-13950
5.3 MEDIUM

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings …

Dec 15, 2025
CVE-2025-13728
6.4 MEDIUM

The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fluent_auth_reset_password` shortcode …

Dec 15, 2025
CVE-2025-13610
6.4 MEDIUM

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RM_Forms' …

Dec 15, 2025
CVE-2025-13608
6.4 MEDIUM

The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in all versions up to, and including, 2.0.0. …

Dec 15, 2025
CVE-2025-13367
6.4 MEDIUM

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to …

Dec 15, 2025
CVE-2025-12900
4.3 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, …

Dec 15, 2025
CVE-2025-65782
6.5 MEDIUM

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling …

Dec 15, 2025
CVE-2025-65781
8.2 HIGH

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization …

Dec 15, 2025
CVE-2025-65780
8.8 HIGH

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire …

Dec 15, 2025
CVE-2025-65779
7.5 HIGH

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a board's …

Dec 15, 2025
CVE-2025-65778
8.1 HIGH

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attachments can be served with …

Dec 15, 2025
CVE-2025-65431
5.4 MEDIUM

An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the identifier for third-party provider accounts. That value may …

Dec 15, 2025
CVE-2025-65430
5.4 MEDIUM

An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tokens for that user while the account was …

Dec 15, 2025
CVE-2025-66388
6.5 MEDIUM

A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing …

Dec 15, 2025
CVE-2025-37732
5.4 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the …

Dec 15, 2025
CVE-2025-37731
6.8 MEDIUM

Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a …

Dec 15, 2025
CVE-2025-14714
6.5 MEDIUM

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user …

Dec 15, 2025
CVE-2025-11670
6.4 MEDIUM

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as …

Dec 15, 2025
CVE-2025-14711
7.3 HIGH

A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulation of the …

Dec 15, 2025
CVE-2025-14710
7.3 HIGH

A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument …

Dec 15, 2025
CVE-2025-14709
9.8 CRITICAL

A security vulnerability has been detected in Shiguangwu sgwbox N3 2.0.25. Affected by this issue is some unknown functionality of the file /usr/sbin/http_eshell_server of the …

Dec 15, 2025
CVE-2025-14708
9.8 CRITICAL

A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component …

Dec 15, 2025
CVE-2025-14023
3.1 LOW

LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could …

Dec 15, 2025
CVE-2025-14022
7.7 HIGH

LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with …

Dec 15, 2025
CVE-2025-14021
4.3 MEDIUM

The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious …

Dec 15, 2025
CVE-2025-14020
5.4 MEDIUM

LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not …

Dec 15, 2025
CVE-2025-14019
3.4 LOW

LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the …

Dec 15, 2025
CVE-2025-14712
7.5 HIGH

Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific …

Dec 15, 2025
CVE-2025-14707
9.8 CRITICAL

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. …

Dec 15, 2025
CVE-2025-14706
9.8 CRITICAL

A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the component NETREBOOT Interface. Such manipulation …

Dec 15, 2025
CVE-2025-14549
8.1 HIGH

In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) …

Dec 15, 2025
CVE-2025-13355
7.1 HIGH

The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Dec 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.