CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12777
5.3 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the …

Nov 19, 2025
CVE-2025-12770
5.3 MEDIUM

The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API …

Nov 19, 2025
CVE-2025-12427
5.3 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST …

Nov 19, 2025
CVE-2025-13225
5.6 MEDIUM

Tanium addressed an arbitrary file deletion vulnerability in TanOS.

Nov 19, 2025
CVE-2025-12852

DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to cause unintended operations on the …

Nov 19, 2025
CVE-2025-65093
5.5 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application …

Nov 18, 2025
CVE-2025-65015
7.5 HIGH

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 …

Nov 18, 2025
CVE-2025-65014
3.7 LOW

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality …

Nov 18, 2025
CVE-2025-65013
6.2 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application …

Nov 18, 2025
CVE-2025-65012
5.4 MEDIUM

Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any …

Nov 18, 2025
CVE-2025-64515
4.3 MEDIUM

Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data fields are dynamically set to …

Nov 18, 2025
CVE-2025-64325
9.0 CRITICAL

Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request …

Nov 18, 2025
CVE-2025-64324
7.7 HIGH

KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user …

Nov 18, 2025
CVE-2025-62406
8.1 HIGH

Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset …

Nov 18, 2025
CVE-2025-54990
5.3 MEDIUM

XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights …

Nov 18, 2025
CVE-2025-63229
5.4 MEDIUM

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious …

Nov 18, 2025
CVE-2025-63217
9.8 CRITICAL

The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT …

Nov 18, 2025
CVE-2025-63216
10.0 CRITICAL

The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT …

Nov 18, 2025
CVE-2025-63215
7.2 HIGH

The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate …

Nov 18, 2025
CVE-2025-12119
6.8 MEDIUM

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

Nov 18, 2025
CVE-2025-63228
9.8 CRITICAL

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this …

Nov 18, 2025
CVE-2025-63227
7.2 HIGH

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials …

Nov 18, 2025
CVE-2025-63226
5.7 MEDIUM

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. …

Nov 18, 2025
CVE-2025-37162
6.5 MEDIUM

A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could …

Nov 18, 2025
CVE-2025-37161
7.5 HIGH

A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation could …

Nov 18, 2025
CVE-2025-63955
7.5 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into …

Nov 18, 2025
CVE-2025-63749
6.5 MEDIUM

pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.

Nov 18, 2025
CVE-2025-63693
5.4 MEDIUM

The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows …

Nov 18, 2025
CVE-2025-63225
9.8 CRITICAL

The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access …

Nov 18, 2025
CVE-2025-61664
4.9 MEDIUM

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit …

Nov 18, 2025
CVE-2025-61663
4.9 MEDIUM

A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free …

Nov 18, 2025
CVE-2025-61662
7.8 HIGH

A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory …

Nov 18, 2025
CVE-2025-61661
4.8 MEDIUM

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from …

Nov 18, 2025
CVE-2025-60455
8.4 HIGH

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

Nov 18, 2025
CVE-2025-56499
6.5 MEDIUM

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key …

Nov 18, 2025
CVE-2025-54771
4.9 MEDIUM

A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, …

Nov 18, 2025
CVE-2025-54770
4.9 MEDIUM

A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free …

Nov 18, 2025
CVE-2025-54321
9.8 CRITICAL

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated …

Nov 18, 2025
CVE-2025-54320
4.3 MEDIUM

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated …

Nov 18, 2025
CVE-2025-52639
3.5 LOW

HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused …

Nov 18, 2025
CVE-2025-37163
7.2 HIGH

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this …

Nov 18, 2025
CVE-2025-37160
5.3 MEDIUM

A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful …

Nov 18, 2025
CVE-2025-37159
5.8 MEDIUM

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user …

Nov 18, 2025
CVE-2025-37158
6.7 MEDIUM

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) …

Nov 18, 2025
CVE-2025-37157
6.7 MEDIUM

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) …

Nov 18, 2025
CVE-2025-37156
6.8 MEDIUM

A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code …

Nov 18, 2025
CVE-2025-37155
7.8 HIGH

A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this …

Nov 18, 2025
CVE-2025-64076
7.5 HIGH

Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read …

Nov 18, 2025
CVE-2025-63994
9.8 CRITICAL

An arbitrary file upload vulnerability in the /php/UploadHandler.php component of RichFilemanager v2.7.6 allows attackers to execute arbitrary code via uploading a crafted file.

Nov 18, 2025
CVE-2025-63828
6.1 MEDIUM

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains …

Nov 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.