CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-55127
5.4 MEDIUM

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading …

Nov 20, 2025
CVE-2025-55126
6.5 MEDIUM

HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign …

Nov 20, 2025
CVE-2025-10571
9.6 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects ABB Ability Edgenius: 3.2.0.0, 3.2.1.1.

Nov 20, 2025
CVE-2025-64524
3.3 LOW

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and …

Nov 20, 2025
CVE-2025-63889
7.5 HIGH

The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

Nov 20, 2025
CVE-2025-63888
9.8 CRITICAL

The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

Nov 20, 2025
CVE-2025-64428
9.8 CRITICAL

Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch …

Nov 20, 2025
CVE-2025-64185

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand …

Nov 20, 2025
CVE-2025-64027
6.1 MEDIUM

Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application …

Nov 20, 2025
CVE-2025-63848
6.1 MEDIUM

Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook.

Nov 20, 2025
CVE-2025-62724
4.3 MEDIUM

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) …

Nov 20, 2025
CVE-2025-62709
6.8 MEDIUM

ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server …

Nov 20, 2025
CVE-2025-52410
9.8 CRITICAL

Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The `myds` GET parameter is not adequately sanitized before being used in …

Nov 20, 2025
CVE-2025-13437

When zx is invoked with --prefer-local=<path>, the CLI creates a symlink named ./node_modules pointing to <path>/node_modules. Due to a logic error in src/cli.ts (linkNodeModules / …

Nov 20, 2025
CVE-2025-12121
7.3 HIGH

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function …

Nov 20, 2025
CVE-2025-12120
7.3 HIGH

Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file …

Nov 20, 2025
CVE-2025-62875
5.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before …

Nov 20, 2025
CVE-2025-62731
4.8 MEDIUM

SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS …

Nov 20, 2025
CVE-2025-62730
8.8 HIGH

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able …

Nov 20, 2025
CVE-2025-62729
5.4 MEDIUM

SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML and JS into website, which will be …

Nov 20, 2025
CVE-2025-62297
5.4 MEDIUM

SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be …

Nov 20, 2025
CVE-2025-62296
5.4 MEDIUM

SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be …

Nov 20, 2025
CVE-2025-62295
5.4 MEDIUM

SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be …

Nov 20, 2025
CVE-2025-62294
7.5 HIGH

SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force …

Nov 20, 2025
CVE-2025-62293
5.4 MEDIUM

SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able …

Nov 20, 2025
CVE-2025-60738
9.8 CRITICAL

An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute …

Nov 20, 2025
CVE-2025-60737
6.1 MEDIUM

Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the …

Nov 20, 2025
CVE-2025-36161
5.9 MEDIUM

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker …

Nov 20, 2025
CVE-2025-34320

BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize input path segments. This allows unauthenticated directory …

Nov 20, 2025
CVE-2025-13425

A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in …

Nov 20, 2025
CVE-2024-31405

Rejected reason: Voluntarily withdrawn

Nov 20, 2025
CVE-2025-65226
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.

Nov 20, 2025
CVE-2025-65223
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.

Nov 20, 2025
CVE-2025-65222
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.

Nov 20, 2025
CVE-2025-65221
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.

Nov 20, 2025
CVE-2025-65220
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.

Nov 20, 2025
CVE-2025-64984
6.1 MEDIUM

Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux …

Nov 20, 2025
CVE-2025-62346
6.8 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious …

Nov 20, 2025
CVE-2025-60799
6.1 MEDIUM

phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting …

Nov 20, 2025
CVE-2025-60798
6.5 MEDIUM

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery …

Nov 20, 2025
CVE-2025-60797
6.5 MEDIUM

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter …

Nov 20, 2025
CVE-2025-60796
6.1 MEDIUM

phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper …

Nov 20, 2025
CVE-2025-60794
6.5 MEDIUM

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates …

Nov 20, 2025
CVE-2025-5092
6.4 MEDIUM

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to …

Nov 20, 2025
CVE-2025-41076
6.5 MEDIUM

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of …

Nov 20, 2025
CVE-2025-41075
7.5 HIGH

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation …

Nov 20, 2025
CVE-2025-41074
7.5 HIGH

Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. This behavior can be exploited to generate a Denegation …

Nov 20, 2025
CVE-2025-40605
5.3 MEDIUM

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences …

Nov 20, 2025
CVE-2025-40604
9.8 CRITICAL

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or …

Nov 20, 2025
CVE-2025-40601
7.5 HIGH

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an …

Nov 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.