CVE Database

140423+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62396
5.3 MEDIUM

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

Oct 23, 2025
CVE-2025-62395
4.3 MEDIUM

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted …

Oct 23, 2025
CVE-2025-62394
4.3 MEDIUM

Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course …

Oct 23, 2025
CVE-2025-62393
4.3 MEDIUM

A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view …

Oct 23, 2025
CVE-2025-10355

Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirection parameter, potentially leading users …

Oct 23, 2025
CVE-2024-14011

Rejected reason: This is a duplicate.

Oct 23, 2025
CVE-2025-41073
6.5 MEDIUM

Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated attacker to download a ZIP file containing files from …

Oct 23, 2025
CVE-2025-40643
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of …

Oct 23, 2025
CVE-2025-9981
4.8 MEDIUM

QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, …

Oct 23, 2025
CVE-2025-9980
4.8 MEDIUM

QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, …

Oct 23, 2025
CVE-2025-12105
7.5 HIGH

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. …

Oct 23, 2025
CVE-2025-10914
7.6 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Reflected …

Oct 23, 2025
CVE-2025-10727
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ArkSigner Software and Hardware Inc. AcBakImzala allows Reflected XSS.This issue affects …

Oct 23, 2025
CVE-2025-62499
4.8 MEDIUM

Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of ContentType page. If crafted input is stored by an attacker with "ContentType Management" …

Oct 23, 2025
CVE-2025-61865
6.7 MEDIUM

Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the …

Oct 23, 2025
CVE-2025-54856
4.8 MEDIUM

Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If crafted input is stored by an attacker with "ContentType Management" privilege, an …

Oct 23, 2025
CVE-2025-54806
6.1 MEDIUM

GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert function. If a user accesses a crafted URL while logged in to …

Oct 23, 2025
CVE-2025-62820
4.9 MEDIUM

Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.

Oct 23, 2025
CVE-2025-62813

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Oct 23, 2025
CVE-2025-48430
5.5 MEDIUM

Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Command Centre Server at will. This issue affects …

Oct 23, 2025
CVE-2025-48428
6.7 MEDIUM

Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to the Command Centre Server to export …

Oct 23, 2025
CVE-2025-47699
9.9 CRITICAL

Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions …

Oct 23, 2025
CVE-2025-41402
5.5 MEDIUM

Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue …

Oct 23, 2025
CVE-2025-35981
5.5 MEDIUM

Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about …

Oct 23, 2025
CVE-2025-12104
9.8 CRITICAL

Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Oct 23, 2025
CVE-2025-62812

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62811

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62810

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62809

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62808

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62807

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62806

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62805

Rejected reason: Not used

Oct 23, 2025
CVE-2025-62804

Rejected reason: Not used

Oct 23, 2025
CVE-2025-11575
7.8 HIGH

Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through …

Oct 23, 2025
CVE-2025-62710
5.9 MEDIUM

Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default java.util.Random. …

Oct 22, 2025
CVE-2025-62708
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads …

Oct 22, 2025
CVE-2025-62707
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads …

Oct 22, 2025
CVE-2025-62706
6.5 MEDIUM

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression. A …

Oct 22, 2025
CVE-2025-62705
4.9 MEDIUM

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent …

Oct 22, 2025
CVE-2025-62617
7.2 HIGH

Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionality of …

Oct 22, 2025
CVE-2025-62614

BookLore is a self-hosted web app for organizing and managing personal book collections. In versions 1.8.1 and prior, an authentication bypass vulnerability in the BookMediaController …

Oct 22, 2025
CVE-2025-62613

VDO.Ninja is a tool that brings remote video feeds into OBS or other studio software via WebRTC. From versions 28.0 to before 28.4, a reflected …

Oct 22, 2025
CVE-2025-62612
5.3 MEDIUM

FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a …

Oct 22, 2025
CVE-2025-62611

aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local …

Oct 22, 2025
CVE-2025-62610
8.1 HIGH

Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does …

Oct 22, 2025
CVE-2025-62513
7.5 HIGH

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used …

Oct 22, 2025
CVE-2025-62247
6.5 MEDIUM

Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, …

Oct 22, 2025
CVE-2025-62248
4.8 MEDIUM

A reflected cross-site scripting (XSS) vulnerability, resulting from a regression, has been identified in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, …

Oct 22, 2025
CVE-2025-58712
6.4 MEDIUM

A container privilege escalation flaw was found in certain AMQ Broker images. This issue stems from the /etc/passwd file being created with group-writable permissions during …

Oct 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.