CVE Database

140743+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-57354
6.5 MEDIUM

A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user-controlled input in translation key processing. The affected …

Sep 24, 2025
CVE-2025-57353
5.3 MEDIUM

The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the …

Sep 24, 2025
CVE-2025-57352
5.3 MEDIUM

A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious …

Sep 24, 2025
CVE-2025-57350
8.6 HIGH

The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototype pollution vulnerability in versions prior to 2.0.10. …

Sep 24, 2025
CVE-2025-56241
7.5 HIGH

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows …

Sep 24, 2025
CVE-2025-52907
8.8 HIGH

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

Sep 24, 2025
CVE-2025-52906
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through …

Sep 24, 2025
CVE-2025-48869
7.5 HIGH

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing …

Sep 24, 2025
CVE-2025-48867
4.8 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin …

Sep 24, 2025
CVE-2025-20352
7.7 HIGH KEV

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, …

Sep 24, 2025
CVE-2025-20338
6.0 MEDIUM

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root …

Sep 24, 2025
CVE-2025-20327
7.7 HIGH

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service …

Sep 24, 2025
CVE-2025-20316
5.3 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an …

Sep 24, 2025
CVE-2025-20315
8.6 HIGH

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device …

Sep 24, 2025
CVE-2025-20314
6.7 MEDIUM

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an …

Sep 24, 2025
CVE-2025-20313
6.7 MEDIUM

Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to …

Sep 24, 2025
CVE-2025-20312
7.7 HIGH

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial …

Sep 24, 2025
CVE-2025-20311
7.4 HIGH

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker …

Sep 24, 2025
CVE-2025-20293
5.3 MEDIUM

A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an …

Sep 24, 2025
CVE-2025-20240
6.1 MEDIUM

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack …

Sep 24, 2025
CVE-2025-20160
8.1 HIGH

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to …

Sep 24, 2025
CVE-2025-20149
6.5 MEDIUM

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device …

Sep 24, 2025
CVE-2025-56816
8.8 HIGH

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to the config/jdbc-driver-ext.yml path. …

Sep 24, 2025
CVE-2025-56815
7.1 HIGH

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to save the uploaded file to a …

Sep 24, 2025
CVE-2025-20365
4.3 MEDIUM

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 …

Sep 24, 2025
CVE-2025-20364
4.3 MEDIUM

A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless …

Sep 24, 2025
CVE-2025-20339
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass …

Sep 24, 2025
CVE-2025-20334
8.8 HIGH

A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root …

Sep 24, 2025
CVE-2025-10909
2.4 LOW

A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the …

Sep 24, 2025
CVE-2025-10892
8.8 HIGH

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10891
8.8 HIGH

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10890
9.1 CRITICAL

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10585
9.8 CRITICAL KEV

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 24, 2025
CVE-2025-10502
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium …

Sep 24, 2025
CVE-2025-10501
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 24, 2025
CVE-2025-10500
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 24, 2025
CVE-2025-56819
9.8 CRITICAL

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

Sep 24, 2025
CVE-2025-47329
7.8 HIGH

Memory corruption while handling invalid inputs in application info setup.

Sep 24, 2025
CVE-2025-47328
7.5 HIGH

Transient DOS while processing power control requests with invalid antenna or stream values.

Sep 24, 2025
CVE-2025-47327
7.8 HIGH

Memory corruption while encoding the image data.

Sep 24, 2025
CVE-2025-47326
7.5 HIGH

Transient DOS while handling command data during power control processing.

Sep 24, 2025
CVE-2025-47318
7.5 HIGH

Transient DOS while parsing the EPTM test control message to get the test pattern.

Sep 24, 2025
CVE-2025-47317
7.8 HIGH

Memory corruption due to global buffer overflow when a test command uses an invalid payload type.

Sep 24, 2025
CVE-2025-47316
7.8 HIGH

Memory corruption due to double free when multiple threads race to set the timestamp store.

Sep 24, 2025
CVE-2025-47315
7.8 HIGH

Memory corruption while handling repeated memory unmap requests from guest VM.

Sep 24, 2025
CVE-2025-47314
7.8 HIGH

Memory corruption while processing data sent by FE driver.

Sep 24, 2025
CVE-2025-27077
7.8 HIGH

Memory corruption while processing message in guest VM.

Sep 24, 2025
CVE-2025-27037
7.8 HIGH

Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.

Sep 24, 2025
CVE-2025-27036
6.1 MEDIUM

Information disclosure when Video engine escape input data is less than expected minimum size.

Sep 24, 2025
CVE-2025-27034
9.8 CRITICAL

Memory corruption while selecting the PLMN from SOR failed list.

Sep 24, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.