CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11990
3.1 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated …

Nov 15, 2025
CVE-2025-11865
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain …

Nov 15, 2025
CVE-2025-13191
8.8 HIGH

A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the file /soap.cgi. This manipulation causes stack-based buffer overflow. It …

Nov 15, 2025
CVE-2025-13190
8.8 HIGH

A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the file /portal/__ajax_exporer.sgi. The manipulation of the argument en results …

Nov 15, 2025
CVE-2025-12849
5.3 MEDIUM

The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin …

Nov 15, 2025
CVE-2025-8994
6.5 MEDIUM

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL …

Nov 15, 2025
CVE-2025-13189
8.8 HIGH

A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena.cgi. The manipulation of the argument SERVER_ID/HTTP_SID leads …

Nov 15, 2025
CVE-2025-12847
4.3 MEDIUM

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media …

Nov 15, 2025
CVE-2025-12494
4.3 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in …

Nov 15, 2025
CVE-2025-65072

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65071

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65070

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65069

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65068

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65067

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65066

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65065

Rejected reason: Not used

Nov 15, 2025
CVE-2025-65064

Rejected reason: Not used

Nov 15, 2025
CVE-2025-12182
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up …

Nov 15, 2025
CVE-2025-9317
8.4 HIGH

The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' …

Nov 15, 2025
CVE-2025-8386
6.9 MEDIUM

The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting …

Nov 15, 2025
CVE-2025-64309
8.6 HIGH

Brightpick Mission Control discloses device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated …

Nov 15, 2025
CVE-2025-64308
7.5 HIGH

The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle.

Nov 15, 2025
CVE-2025-64307
6.5 MEDIUM

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, …

Nov 15, 2025
CVE-2025-62765
7.5 HIGH

General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, …

Nov 15, 2025
CVE-2025-59780
7.5 HIGH

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain …

Nov 15, 2025
CVE-2025-58083
10.0 CRITICAL

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

Nov 15, 2025
CVE-2025-55034
8.2 HIGH

General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in …

Nov 15, 2025
CVE-2025-1256

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 14, 2025
CVE-2025-13188
9.8 CRITICAL

A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument …

Nov 14, 2025
CVE-2023-7328
5.3 MEDIUM

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to …

Nov 14, 2025
CVE-2022-4985

Vodafone H500s devices running firmware v3.5.10 (hardware model Sercomm VFH500) expose the WiFi access point password via an unauthenticated HTTP endpoint. By sending a crafted …

Nov 14, 2025
CVE-2021-4471

TG8 Firewall exposes a directory such as /data/ over HTTP without authentication. This directory stores credential files for previously logged-in users. A remote unauthenticated attacker …

Nov 14, 2025
CVE-2021-4470

TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without …

Nov 14, 2025
CVE-2021-4469

Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary …

Nov 14, 2025
CVE-2021-4468

PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated attacker can directly retrieve a compressed …

Nov 14, 2025
CVE-2021-4467

Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. The service generates a new …

Nov 14, 2025
CVE-2021-4466

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled …

Nov 14, 2025
CVE-2021-4465

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial-of-service vulnerability. The device can be shut …

Nov 14, 2025
CVE-2018-25125

Netis ADSL Router DL4322D firmware RTK 2.1.1 contains a buffer overflow vulnerability in the embedded FTP service that allows an authenticated remote user to trigger …

Nov 14, 2025
CVE-2016-15056

Ubee EVW3226 cable modem/routers firmware versions up to and including 1.0.20 store configuration backup files in the web root after they are generated for download. …

Nov 14, 2025
CVE-2025-13187
5.3 MEDIUM

A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess …

Nov 14, 2025
CVE-2025-13186
2.4 LOW

A weakness has been identified in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution up to 4.0. This impacts an unknown function of the file …

Nov 14, 2025
CVE-2025-64084
5.4 MEDIUM

An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. …

Nov 14, 2025
CVE-2025-63891
7.5 HIGH

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema …

Nov 14, 2025
CVE-2025-63745
5.5 MEDIUM

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a …

Nov 14, 2025
CVE-2025-63744
4.3 MEDIUM

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a …

Nov 14, 2025
CVE-2025-13185
4.7 MEDIUM

A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. The manipulation of the …

Nov 14, 2025
CVE-2025-13182
3.5 LOW

A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/category/addtitle. The manipulation of the argument Title …

Nov 14, 2025
CVE-2025-63701
6.8 MEDIUM

A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized …

Nov 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.