CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64684
4.3 MEDIUM

In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

Nov 10, 2025
CVE-2025-64683
5.3 MEDIUM

In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

Nov 10, 2025
CVE-2025-64682
2.7 LOW

In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit

Nov 10, 2025
CVE-2025-64681
2.7 LOW

In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

Nov 10, 2025
CVE-2025-64457
4.2 MEDIUM

In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

Nov 10, 2025
CVE-2025-64456
8.4 HIGH

In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation

Nov 10, 2025
CVE-2025-12939
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file …

Nov 10, 2025
CVE-2025-12938
7.3 HIGH

A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of …

Nov 10, 2025
CVE-2025-41001
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user input …

Nov 10, 2025
CVE-2025-12405

An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report view access could make …

Nov 10, 2025
CVE-2025-41107
5.4 MEDIUM

Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to …

Nov 10, 2025
CVE-2025-12409

A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native …

Nov 10, 2025
CVE-2025-12397

A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with …

Nov 10, 2025
CVE-2025-12155

A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer permission to execute arbitrary shell commands …

Nov 10, 2025
CVE-2025-41731
7.4 HIGH

A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticated local attacker with knowledge of the password generation timeframe might …

Nov 10, 2025
CVE-2025-12933
6.3 MEDIUM

A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument roleid …

Nov 10, 2025
CVE-2025-62689
7.5 HIGH

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd …

Nov 10, 2025
CVE-2025-59777
7.5 HIGH

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd …

Nov 10, 2025
CVE-2025-12932
4.7 MEDIUM

A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of …

Nov 10, 2025
CVE-2025-12931
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of …

Nov 10, 2025
CVE-2025-12613
8.6 HIGH

Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker …

Nov 10, 2025
CVE-2025-12930
6.3 MEDIUM

A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument …

Nov 10, 2025
CVE-2025-12929
7.3 HIGH

A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument …

Nov 10, 2025
CVE-2025-12928
7.3 HIGH

A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument …

Nov 10, 2025
CVE-2025-12868
9.8 CRITICAL

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain administrator …

Nov 10, 2025
CVE-2025-12867
7.2 HIGH

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling …

Nov 10, 2025
CVE-2025-12927
4.7 MEDIUM

A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of …

Nov 10, 2025
CVE-2025-12926
6.3 MEDIUM

A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of …

Nov 10, 2025
CVE-2025-12866
9.8 CRITICAL

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, …

Nov 10, 2025
CVE-2025-12865
8.8 HIGH

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database …

Nov 10, 2025
CVE-2025-12864
8.8 HIGH

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database …

Nov 10, 2025
CVE-2025-12925
7.3 HIGH

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulation results in …

Nov 10, 2025
CVE-2025-12924
4.3 MEDIUM

A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing …

Nov 10, 2025
CVE-2025-12923
2.7 LOW

A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipulation of the argument …

Nov 10, 2025
CVE-2025-12922
6.3 MEDIUM

A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data …

Nov 10, 2025
CVE-2025-12921
4.3 MEDIUM

A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknown functionality of the file /ImportCRFData?action=confirm of …

Nov 10, 2025
CVE-2025-12920
2.4 LOW

A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation …

Nov 9, 2025
CVE-2025-12919
3.7 LOW

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation …

Nov 9, 2025
CVE-2025-12918
3.1 LOW

A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file …

Nov 9, 2025
CVE-2025-12917
4.3 MEDIUM

A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file /reqproc/proc_post of the component Reboot Handler. …

Nov 9, 2025
CVE-2025-40109

In the Linux kernel, the following vulnerability has been resolved: crypto: rng - Ensure set_ent is always present Ensure that set_ent is always set since …

Nov 9, 2025
CVE-2025-40108

In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: Fix blocked task Revert commit 1afa70632c39 ("serial: qcom-geni: Enable PM runtime for serial …

Nov 9, 2025
CVE-2025-12916
6.3 MEDIUM

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component …

Nov 9, 2025
CVE-2025-12915
6.4 MEDIUM

A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init Script Handler. The manipulation results …

Nov 8, 2025
CVE-2025-12914
4.7 MEDIUM

A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The …

Nov 8, 2025
CVE-2025-12913
4.7 MEDIUM

A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument …

Nov 8, 2025
CVE-2025-12837
6.4 MEDIUM

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Action widget in versions up to, and …

Nov 8, 2025
CVE-2025-12643
6.4 MEDIUM

The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay' shortcode in all versions up to, and including, …

Nov 8, 2025
CVE-2025-12399
7.2 HIGH

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST …

Nov 8, 2025
CVE-2025-12092
6.5 MEDIUM

The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete' functionality in all versions …

Nov 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.