CVE Database

139918+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-63687
6.5 MEDIUM

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.

Nov 7, 2025
CVE-2025-63686
6.5 MEDIUM

There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the document query function under the Download Center menu in …

Nov 7, 2025
CVE-2025-58469
8.8 HIGH

A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or …

Nov 7, 2025
CVE-2025-58465
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the …

Nov 7, 2025
CVE-2025-58464
7.5 HIGH

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit the vulnerability to read the contents …

Nov 7, 2025
CVE-2025-58463
4.9 MEDIUM

A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the …

Nov 7, 2025
CVE-2025-57712
6.5 MEDIUM

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Nov 7, 2025
CVE-2025-57706
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-54168
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an administrator account, they can then exploit the …

Nov 7, 2025
CVE-2025-54167

A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains an administrator account, they can then exploit the …

Nov 7, 2025
CVE-2025-53413
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Nov 7, 2025
CVE-2025-53412
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-53411
4.9 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, …

Nov 7, 2025
CVE-2025-53410
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Nov 7, 2025
CVE-2025-53409
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Nov 7, 2025
CVE-2025-53408
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-52865
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-52425
9.8 CRITICAL

An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have …

Nov 7, 2025
CVE-2025-47207
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit …

Nov 7, 2025
CVE-2025-12861
4.7 MEDIUM

A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the …

Nov 7, 2025
CVE-2025-12860
4.7 MEDIUM

A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results …

Nov 7, 2025
CVE-2025-12859
4.7 MEDIUM

A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_edit.php. The manipulation of the argument ids …

Nov 7, 2025
CVE-2025-34299
9.8 CRITICAL

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading …

Nov 7, 2025
CVE-2025-12857
4.7 MEDIUM

A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/roombook.php. Such manipulation …

Nov 7, 2025
CVE-2025-12856
4.7 MEDIUM

A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/reservation.php. This manipulation of the argument …

Nov 7, 2025
CVE-2025-12855
4.7 MEDIUM

A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processing of the file /admin/newsletterdel.php. The manipulation of …

Nov 7, 2025
CVE-2025-12854
3.7 LOW

A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill of the file /seckillExecution/. The manipulation of the argument userid …

Nov 7, 2025
CVE-2025-12853
4.7 MEDIUM

A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the …

Nov 7, 2025
CVE-2025-10968
8.8 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft Software Services …

Nov 7, 2025
CVE-2025-10870

SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete databases by sending POST and GET requests with the …

Nov 7, 2025
CVE-2025-46413
4.3 MEDIUM

Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. When WPS is enabled, PIN code and/or Wi-Fi password …

Nov 7, 2025
CVE-2025-10966
4.3 MEDIUM

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl …

Nov 7, 2025
CVE-2025-64346

archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to feed a specially crafted archive …

Nov 7, 2025
CVE-2025-64343
7.8 HIGH

(conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 and below, the installation directory inherits permissions …

Nov 7, 2025
CVE-2025-64339
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature is vulnerable to stored Cross-site Scripting (XSS),specifically …

Nov 7, 2025
CVE-2025-12527
4.3 MEDIUM

The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capability check on the 'yydev_notes_save_dashboard_data' function …

Nov 7, 2025
CVE-2025-12520
4.0 MEDIUM

The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2 …

Nov 7, 2025
CVE-2025-64338
9.0 CRITICAL

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection …

Nov 7, 2025
CVE-2025-64336
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-site Scripting (XSS). …

Nov 7, 2025
CVE-2025-64329
5.5 MEDIUM

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the …

Nov 7, 2025
CVE-2025-4522
6.5 MEDIUM

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in …

Nov 7, 2025
CVE-2025-4519
8.8 HIGH

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on …

Nov 7, 2025
CVE-2025-12352
9.8 CRITICAL

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions …

Nov 7, 2025
CVE-2025-64328
7.2 HIGH KEV

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the …

Nov 7, 2025
CVE-2025-64323
5.3 MEDIUM

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access …

Nov 7, 2025
CVE-2025-64187
4.4 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML …

Nov 7, 2025
CVE-2025-64184
8.8 HIGH

Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different aspects …

Nov 7, 2025
CVE-2025-64180
10.0 CRITICAL

Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw …

Nov 7, 2025
CVE-2025-5483
8.1 HIGH

The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wizard/inc/wp_user.php file in versions 1.2.10 to …

Nov 7, 2025
CVE-2025-11546

CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X …

Nov 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.