CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13193
5.5 MEDIUM

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect …

Nov 17, 2025
CVE-2024-46336
6.1 MEDIUM

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.

Nov 17, 2025
CVE-2024-46334
6.1 MEDIUM

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.

Nov 17, 2025
CVE-2024-44652
6.5 MEDIUM

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.

Nov 17, 2025
CVE-2024-44648
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.

Nov 17, 2025
CVE-2024-44647
6.1 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.

Nov 17, 2025
CVE-2024-44644
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.

Nov 17, 2025
CVE-2024-44641
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.

Nov 17, 2025
CVE-2025-65083
3.2 LOW

GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSign Desktop user selects …

Nov 17, 2025
CVE-2025-64046
6.1 MEDIUM

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.

Nov 17, 2025
CVE-2025-63916
8.1 HIGH

MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supplied file paths before passing …

Nov 17, 2025
CVE-2025-63748
8.8 HIGH

QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file …

Nov 17, 2025
CVE-2025-63747
9.8 CRITICAL

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the …

Nov 17, 2025
CVE-2025-63708
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows remote attackers to execute arbitrary JavaScript in victims' browsers. The vulnerability …

Nov 17, 2025
CVE-2025-13289
6.3 MEDIUM

A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The …

Nov 17, 2025
CVE-2025-13288
8.8 HIGH

A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno …

Nov 17, 2025
CVE-2025-4321

In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device …

Nov 17, 2025
CVE-2025-13287
6.3 MEDIUM

A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /index.php?page=categories. Executing manipulation of the argument …

Nov 17, 2025
CVE-2025-13286
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation …

Nov 17, 2025
CVE-2025-13285
7.3 HIGH

A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the …

Nov 17, 2025
CVE-2025-13280
7.3 HIGH

A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. …

Nov 17, 2025
CVE-2025-13279
6.3 MEDIUM

A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of …

Nov 17, 2025
CVE-2025-13278
6.3 MEDIUM

A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowed_book_search.php. Such manipulation of the …

Nov 17, 2025
CVE-2025-40936
7.8 HIGH

A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Solid Edge (All versions < V226.00 Update 03). The affected applications …

Nov 17, 2025
CVE-2025-40834
5.7 MEDIUM

A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not properly neutralize the input. This could allow …

Nov 17, 2025
CVE-2025-13277
7.3 HIGH

A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of …

Nov 17, 2025
CVE-2025-11681
6.5 MEDIUM

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver …

Nov 17, 2025
CVE-2025-13276
7.3 HIGH

A vulnerability was detected in g33kyrash Online-Banking-System up to 12dbfa690e5af649fb72d2e5d3674e88d6743455. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument Username …

Nov 17, 2025
CVE-2025-13275
4.7 MEDIUM

A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This affects an unknown part of the file /admin/about.php. The manipulation leads to …

Nov 17, 2025
CVE-2025-13274
6.3 MEDIUM

A weakness has been identified in Campcodes School Fees Payment Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_fees. …

Nov 17, 2025
CVE-2025-13273
6.3 MEDIUM

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Nov 17, 2025
CVE-2025-13272
7.3 HIGH

A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Affected is an unknown function of the file /manage_course.php. Such manipulation of the …

Nov 17, 2025
CVE-2025-13271
7.3 HIGH

A vulnerability was determined in Campcodes School Fees Payment Management System 1.0. This impacts an unknown function of the file /ajax.php?action=login. This manipulation of the …

Nov 17, 2025
CVE-2025-65073
7.5 HIGH

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

Nov 17, 2025
CVE-2025-13270
6.3 MEDIUM

A vulnerability was found in Campcodes School Fees Payment Management System 1.0. This affects an unknown function of the file /ajax.php?action=save_course. The manipulation of the …

Nov 17, 2025
CVE-2025-13269
6.3 MEDIUM

A vulnerability has been found in Campcodes School Fees Payment Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_payment. The …

Nov 17, 2025
CVE-2025-13268
6.3 MEDIUM

A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/main/java/com/vince/xq/project/system/dbconfig/service/DbconfigServiceImpl.java of the component …

Nov 17, 2025
CVE-2025-13267
6.3 MEDIUM

A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown function of the file /success.php. Performing manipulation of the …

Nov 17, 2025
CVE-2025-13165
7.5 HIGH

EasyFlow GP developed by Digiwin has a Denial of service vulnerability, allowing unauthenticated remote attackers to send specific requests that result in denial of web …

Nov 17, 2025
CVE-2025-13164
4.9 MEDIUM

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from …

Nov 17, 2025
CVE-2025-13163
4.9 MEDIUM

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext database account credentials from the system frontend.

Nov 17, 2025
CVE-2025-9501
9.0 CRITICAL

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by …

Nov 17, 2025
CVE-2025-60022
4.8 MEDIUM

Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man-in-the-middle attack may allow an attacker …

Nov 17, 2025
CVE-2025-13266
5.3 MEDIUM

A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the file vlife-base/src/main/java/cn/wwwlike/sys/api/SysFileApi.java of the component …

Nov 17, 2025
CVE-2025-13265
6.3 MEDIUM

A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. This manipulation causes path …

Nov 17, 2025
CVE-2025-13264
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown part of the file /view_magazine.php. The manipulation of …

Nov 17, 2025
CVE-2025-13263
6.3 MEDIUM

A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation …

Nov 17, 2025
CVE-2025-13262
7.3 HIGH

A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file platform/web-client/src/main/java/lsfusion/http/controller/file/UploadFileRequestHandler.java. Executing manipulation of …

Nov 17, 2025
CVE-2025-13284
9.8 CRITICAL

ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

Nov 17, 2025
CVE-2025-13283
7.1 HIGH

TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs …

Nov 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.