CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11794
4.9 MEDIUM

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and …

Nov 14, 2025
CVE-2025-55073
5.4 MEDIUM

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin …

Nov 14, 2025
CVE-2025-55070
6.5 MEDIUM

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

Nov 14, 2025
CVE-2025-41436
3.1 LOW

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and …

Nov 14, 2025
CVE-2025-11776
4.3 MEDIUM

Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` …

Nov 14, 2025
CVE-2025-64444
7.2 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker …

Nov 14, 2025
CVE-2025-10686
7.2 HIGH

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and …

Nov 14, 2025
CVE-2025-13161
7.5 HIGH

IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system …

Nov 14, 2025
CVE-2025-13160
5.3 MEDIUM

IQ-Support developed by IQ Service International has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to access specific APIs to obtain sensitive information …

Nov 14, 2025
CVE-2025-9479
4.3 MEDIUM

Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Nov 14, 2025
CVE-2025-13107
4.3 MEDIUM

Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Nov 14, 2025
CVE-2025-13102
4.3 MEDIUM

Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HTML …

Nov 14, 2025
CVE-2025-13097
5.4 MEDIUM

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Nov 14, 2025
CVE-2025-12904
7.2 HIGH

The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJAX endpoint in all versions up to, and including, 0.4.17 …

Nov 14, 2025
CVE-2024-9126
7.5 HIGH

Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific …

Nov 14, 2025
CVE-2024-7021
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Nov 14, 2025
CVE-2024-7017
7.5 HIGH

Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Nov 14, 2025
CVE-2024-13983
6.3 MEDIUM

Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. …

Nov 14, 2025
CVE-2024-13178
4.3 MEDIUM

Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Nov 14, 2025
CVE-2024-11920
4.3 MEDIUM

Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a …

Nov 14, 2025
CVE-2024-11919
4.3 MEDIUM

Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Nov 14, 2025
CVE-2025-64530
7.5 HIGH

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, …

Nov 13, 2025
CVE-2025-64754

Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window …

Nov 13, 2025
CVE-2025-64753
5.3 MEDIUM

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing …

Nov 13, 2025
CVE-2025-64752
6.8 MEDIUM

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature …

Nov 13, 2025
CVE-2025-64749
4.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST …

Nov 13, 2025
CVE-2025-64748
6.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search …

Nov 13, 2025
CVE-2025-64747
5.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 11.13.0 …

Nov 13, 2025
CVE-2025-47913
7.5 HIGH

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.

Nov 13, 2025
CVE-2025-36251
9.6 CRITICAL

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due …

Nov 13, 2025
CVE-2025-36250
10.0 CRITICAL

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker …

Nov 13, 2025
CVE-2025-36236
8.2 HIGH

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker …

Nov 13, 2025
CVE-2025-36096
9.0 CRITICAL

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is …

Nov 13, 2025
CVE-2025-13131
7.8 HIGH

A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results …

Nov 13, 2025
CVE-2025-13130
7.8 HIGH

A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Console.exe of the component Service. Such manipulation …

Nov 13, 2025
CVE-2025-64746
4.6 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions …

Nov 13, 2025
CVE-2025-64745
2.7 LOW

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's development server …

Nov 13, 2025
CVE-2025-64744
3.5 LOW

OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming an organization with HTML in the name, the …

Nov 13, 2025
CVE-2025-4619

A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through …

Nov 13, 2025
CVE-2025-47222
6.5 MEDIUM

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a …

Nov 13, 2025
CVE-2025-47221
5.3 MEDIUM

An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTERN can be set to any path, even …

Nov 13, 2025
CVE-2025-47220
5.3 MEDIUM

A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in the PDFSigner and the PAdESSigner, can …

Nov 13, 2025
CVE-2025-64726

Socket Firewall is an HTTP/HTTPS proxy server that intercepts package manager requests and enforces security policies by blocking dangerous packages. Socket Firewall binary versions (separate …

Nov 13, 2025
CVE-2025-64709
9.6 CRITICAL

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) …

Nov 13, 2025
CVE-2025-60702
6.5 MEDIUM

A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user …

Nov 13, 2025
CVE-2025-60699
6.5 MEDIUM

A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `global.so` binary. The `getSaveConfig` function retrieves the `http_host` parameter from user …

Nov 13, 2025
CVE-2025-60679
8.8 HIGH

A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs …

Nov 13, 2025
CVE-2025-59840
8.1 HIGH

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 6.2.0, applications meeting 2 …

Nov 13, 2025
CVE-2025-55810
6.8 MEDIUM

A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allows physical attackers …

Nov 13, 2025
CVE-2025-46370
3.3 LOW

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low privileged attacker with local access could potentially exploit …

Nov 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.