CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13181
3.5 LOW

A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/material/add. Executing a manipulation of the argument …

Nov 14, 2025
CVE-2025-13180
3.5 LOW

A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. Impacted is an unknown function of the file /edit_profile. …

Nov 14, 2025
CVE-2025-13179
4.3 MEDIUM

A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects some unknown processing. Such manipulation …

Nov 14, 2025
CVE-2025-13033
7.5 HIGH

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient email addresses. An attacker can exploit this flaw …

Nov 14, 2025
CVE-2025-63680
8.6 HIGH

Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallback extension resolution, leads …

Nov 14, 2025
CVE-2025-63291
5.4 MEDIUM

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The …

Nov 14, 2025
CVE-2025-13178
3.5 LOW

A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file /edit_profile of the component User Profile …

Nov 14, 2025
CVE-2025-13177
4.3 MEDIUM

A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can …

Nov 14, 2025
CVE-2025-13174
6.3 MEDIUM

A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function do_job of the file /rachelos/we-mp-rss/blob/main/jobs/mps.py of …

Nov 14, 2025
CVE-2025-63830
6.1 MEDIUM

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

Nov 14, 2025
CVE-2025-63725
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php.

Nov 14, 2025
CVE-2025-63724
6.0 MEDIUM

SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php.

Nov 14, 2025
CVE-2025-54562
4.3 MEDIUM

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack …

Nov 14, 2025
CVE-2025-54561
4.3 MEDIUM

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote access to content …

Nov 14, 2025
CVE-2025-54560
3.8 LOW

A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Probing of internal infrastructure.

Nov 14, 2025
CVE-2025-54559
3.7 LOW

An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for loading arbitrary external …

Nov 14, 2025
CVE-2025-54348
6.5 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker …

Nov 14, 2025
CVE-2025-54346
7.6 HIGH

A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker …

Nov 14, 2025
CVE-2025-54345
7.5 HIGH

An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Information is exposed to an Unauthorized Actor.

Nov 14, 2025
CVE-2025-54343
9.6 CRITICAL

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

Nov 14, 2025
CVE-2025-54342
3.3 LOW

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible …

Nov 14, 2025
CVE-2025-54340
4.1 MEDIUM

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is a Broken or Risky Cryptographic Algorithm.

Nov 14, 2025
CVE-2025-54339
10.0 CRITICAL

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

Nov 14, 2025
CVE-2025-4618

A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser …

Nov 14, 2025
CVE-2025-4617

An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature …

Nov 14, 2025
CVE-2025-4616

An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security …

Nov 14, 2025
CVE-2025-13172
6.3 MEDIUM

A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file /admin/view-member-report.php. Performing a manipulation of …

Nov 14, 2025
CVE-2025-13171
6.3 MEDIUM

A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such manipulation of the argument keyword leads to sql …

Nov 14, 2025
CVE-2025-13204
7.3 HIGH

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary …

Nov 14, 2025
CVE-2025-8870
4.9 MEDIUM

On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153

Nov 14, 2025
CVE-2025-64446
9.8 CRITICAL KEV

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 …

Nov 14, 2025
CVE-2025-13170
7.3 HIGH

A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation …

Nov 14, 2025
CVE-2025-13169
7.3 HIGH

A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation …

Nov 14, 2025
CVE-2024-55016
6.5 MEDIUM

PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

Nov 14, 2025
CVE-2024-44640
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.

Nov 14, 2025
CVE-2024-44639
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php.

Nov 14, 2025
CVE-2024-44636
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.

Nov 14, 2025
CVE-2024-44635
6.1 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.

Nov 14, 2025
CVE-2024-44633
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.

Nov 14, 2025
CVE-2024-44632
6.5 MEDIUM

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.

Nov 14, 2025
CVE-2024-44630
6.5 MEDIUM

Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, …

Nov 14, 2025
CVE-2024-42749
6.1 MEDIUM

Cross Site Scripting vulnerability in Alto CMS v.1.1.13 allows a local attacker to execute arbitrary code via a crafted script.

Nov 14, 2025
CVE-2025-13168
6.3 MEDIUM

A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py. This manipulation of the argument …

Nov 14, 2025
CVE-2024-21635
7.5 HIGH

Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of …

Nov 14, 2025
CVE-2025-9982
7.5 HIGH

A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file and stored in plaintext. This flaw allows attackers …

Nov 14, 2025
CVE-2025-12149

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, …

Nov 14, 2025
CVE-2025-11918
7.3 HIGH

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to …

Nov 14, 2025
CVE-2025-10018
4.8 MEDIUM

QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, …

Nov 14, 2025
CVE-2025-8855
8.1 HIGH

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting …

Nov 14, 2025
CVE-2025-11981
4.9 MEDIUM

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, …

Nov 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.