CVE Database

140423+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12044
7.5 HIGH

Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a …

Oct 23, 2025
CVE-2025-6980
7.5 HIGH

Captive Portal can expose sensitive information

Oct 23, 2025
CVE-2025-6979
8.8 HIGH

Captive Portal can allow authentication bypass

Oct 23, 2025
CVE-2025-6978
7.2 HIGH

Diagnostics command injection vulnerability

Oct 23, 2025
CVE-2025-62255
6.1 MEDIUM

Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsupported versions, and Liferay DXP …

Oct 23, 2025
CVE-2025-60859
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bbs/view_comment.php.

Oct 23, 2025
CVE-2025-60837
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted …

Oct 23, 2025
CVE-2025-54808
7.8 HIGH

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on …

Oct 23, 2025
CVE-2025-23352
7.8 HIGH

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitialized pointer access. A successful exploit of this …

Oct 23, 2025
CVE-2025-23347
7.8 HIGH

NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulnerability might lead to code …

Oct 23, 2025
CVE-2025-23345
4.4 MEDIUM

NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds read. A successful exploit …

Oct 23, 2025
CVE-2025-23332
5.0 MEDIUM

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A …

Oct 23, 2025
CVE-2025-23330
5.5 MEDIUM

NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer dereference. A successful exploit of this …

Oct 23, 2025
CVE-2025-23300
5.5 MEDIUM

NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific …

Oct 23, 2025
CVE-2025-11621
8.1 HIGH

Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across …

Oct 23, 2025
CVE-2025-10937
5.5 MEDIUM

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local authentication token during startup, before copying …

Oct 23, 2025
CVE-2025-61464
6.5 MEDIUM

gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.

Oct 23, 2025
CVE-2025-61413
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating …

Oct 23, 2025
CVE-2025-57240
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute arbitrary code via the registration step.

Oct 23, 2025
CVE-2025-62713

Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running …

Oct 23, 2025
CVE-2025-34156

Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, …

Oct 23, 2025
CVE-2025-34155

Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authentication failure messages differ based on whether a supplied username …

Oct 23, 2025
CVE-2025-62169
8.1 HIGH

OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and …

Oct 23, 2025
CVE-2025-59048
8.1 HIGH

OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation …

Oct 23, 2025
CVE-2025-50951
6.5 MEDIUM

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

Oct 23, 2025
CVE-2025-50950
7.5 HIGH

Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.

Oct 23, 2025
CVE-2025-50949
6.5 MEDIUM

FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.

Oct 23, 2025
CVE-2025-12114
5.5 MEDIUM

Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 23, 2025
CVE-2025-61136
7.1 HIGH

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover …

Oct 23, 2025
CVE-2025-61132
7.1 HIGH

A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover …

Oct 23, 2025
CVE-2025-56009
5.3 MEDIUM

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding additional users …

Oct 23, 2025
CVE-2025-56008
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via …

Oct 23, 2025
CVE-2025-56007
6.5 MEDIUM

CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing …

Oct 23, 2025
CVE-2025-12110
5.4 MEDIUM

A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the client. The refresh token …

Oct 23, 2025
CVE-2025-62256
5.3 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and …

Oct 23, 2025
CVE-2025-60852
6.5 MEDIUM

A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanitize …

Oct 23, 2025
CVE-2025-53702
6.5 MEDIUM

Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action …

Oct 23, 2025
CVE-2025-53701
6.1 MEDIUM

Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET requests sent to /cgi-bin/action endpoint are not sanitized properly, …

Oct 23, 2025
CVE-2025-1680

An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate …

Oct 23, 2025
CVE-2025-1679

Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service …

Oct 23, 2025
CVE-2025-11429
5.4 MEDIUM

A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created …

Oct 23, 2025
CVE-2025-8427
6.4 MEDIUM

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and …

Oct 23, 2025
CVE-2025-11128
5.0 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery …

Oct 23, 2025
CVE-2025-11023
9.8 CRITICAL

Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ArkSigner Software …

Oct 23, 2025
CVE-2025-10705
5.3 MEDIUM

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.4.6. …

Oct 23, 2025
CVE-2025-62401
5.4 MEDIUM

An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

Oct 23, 2025
CVE-2025-62400
4.3 MEDIUM

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal …

Oct 23, 2025
CVE-2025-62399
7.5 HIGH

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

Oct 23, 2025
CVE-2025-62398
5.4 MEDIUM

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

Oct 23, 2025
CVE-2025-62397
5.3 MEDIUM

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

Oct 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.