CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-42892
6.8 MEDIUM

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted …

Nov 11, 2025
CVE-2025-42890
10.0 CRITICAL

SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code …

Nov 11, 2025
CVE-2025-42889
5.4 MEDIUM

SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this vulnerability has a low …

Nov 11, 2025
CVE-2025-42888
5.5 MEDIUM

SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during …

Nov 11, 2025
CVE-2025-42887
9.9 CRITICAL

Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide …

Nov 11, 2025
CVE-2025-42886
6.1 MEDIUM

Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. …

Nov 11, 2025
CVE-2025-42885
5.8 MEDIUM

Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled function that will enable them to view information. As …

Nov 11, 2025
CVE-2025-42884
6.5 MEDIUM

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to …

Nov 11, 2025
CVE-2025-42883
2.7 LOW

Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files …

Nov 11, 2025
CVE-2025-42882
4.3 MEDIUM

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module …

Nov 11, 2025
CVE-2025-31719
5.1 MEDIUM

In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature results with low probability.

Nov 11, 2025
CVE-2025-64529
6.5 MEDIUM

SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator …

Nov 10, 2025
CVE-2025-64522
9.1 CRITICAL

Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, …

Nov 10, 2025
CVE-2025-64519
8.8 HIGH

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL injection vulnerability exists …

Nov 10, 2025
CVE-2025-63678
7.2 HIGH

An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute …

Nov 10, 2025
CVE-2025-12542

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 10, 2025
CVE-2025-11892
9.6 CRITICAL

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross-site scripting via Issues search label filter that could lead …

Nov 10, 2025
CVE-2025-11578
7.2 HIGH

A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by …

Nov 10, 2025
CVE-2021-4462
9.8 CRITICAL

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; …

Nov 10, 2025
CVE-2018-25124

PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within the web-based DICOM viewer component. Successful exploitation allows a remote …

Nov 10, 2025
CVE-2025-64518
7.5 HIGH

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version …

Nov 10, 2025
CVE-2025-64513

Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a vulnerability in versions prior to 2.4.24, 2.5.21, and …

Nov 10, 2025
CVE-2025-64512
8.6 HIGH

Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107, pdfminer.six will execute …

Nov 10, 2025
CVE-2025-64509
7.5 HIGH

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope can cause Bugsink to spend excessive CPU time …

Nov 10, 2025
CVE-2025-64508
7.5 HIGH

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli streams, such as many zeros) can be sent …

Nov 10, 2025
CVE-2025-64507
7.8 HIGH

Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment …

Nov 10, 2025
CVE-2025-64504
5.0 MEDIUM

Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2.95.11 and 3.124.1, in certain project membership …

Nov 10, 2025
CVE-2025-64502

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `explain()` method provides detailed information …

Nov 10, 2025
CVE-2025-64501
7.6 HIGH

ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and below, the `prosemirror_to_html` gem is vulnerable to Cross-Site Scripting …

Nov 10, 2025
CVE-2025-64484
8.5 HIGH

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load …

Nov 10, 2025
CVE-2025-64183
7.5 HIGH

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.2.0 through …

Nov 10, 2025
CVE-2025-64182
7.8 HIGH

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.2.0 through …

Nov 10, 2025
CVE-2025-64181
7.5 HIGH

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through …

Nov 10, 2025
CVE-2025-64167
7.1 HIGH

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to …

Nov 10, 2025
CVE-2025-63397
6.5 MEDIUM

Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.

Nov 10, 2025
CVE-2025-62780
3.5 LOW

changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in changedetection.io Watch update API in versions …

Nov 10, 2025
CVE-2025-49145
8.7 HIGH

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create …

Nov 10, 2025
CVE-2025-63617
6.5 MEDIUM

ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.

Nov 10, 2025
CVE-2025-63296
6.5 MEDIUM

KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted …

Nov 10, 2025
CVE-2025-48878
4.3 MEDIUM

Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows …

Nov 10, 2025
CVE-2025-48065
8.8 HIGH

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with …

Nov 10, 2025
CVE-2025-48055
8.5 HIGH

Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user …

Nov 10, 2025
CVE-2025-63384
6.5 MEDIUM

A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege …

Nov 10, 2025
CVE-2025-63149
7.5 HIGH

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a …

Nov 10, 2025
CVE-2025-60876
6.5 MEDIUM

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be …

Nov 10, 2025
CVE-2025-56503
6.5 MEDIUM

An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the …

Nov 10, 2025
CVE-2025-47932
8.8 HIGH

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is …

Nov 10, 2025
CVE-2025-33150
5.3 MEDIUM

IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages.

Nov 10, 2025
CVE-2025-12729
4.2 MEDIUM

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI …

Nov 10, 2025
CVE-2025-12728
4.2 MEDIUM

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI …

Nov 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.