CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1885
5.4 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Phishing, Forceful Browsing.This issue affects Online Food …

Dec 19, 2025
CVE-2025-14455
5.4 MEDIUM

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.7. This is …

Dec 19, 2025
CVE-2025-12361
4.3 MEDIUM

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, …

Dec 19, 2025
CVE-2025-11747
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the colibri_blog_posts shortcode in all versions up to, and including, 1.0.345 …

Dec 19, 2025
CVE-2025-66522
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize …

Dec 19, 2025
CVE-2025-66521
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature. A crafted payload can be injected as the certificate name, which …

Dec 19, 2025
CVE-2025-66520
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied SVG files are not properly sanitized …

Dec 19, 2025
CVE-2025-66519
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A crafted payload can be injected into the “Create new Layer” …

Dec 19, 2025
CVE-2025-66502
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which …

Dec 19, 2025
CVE-2025-66501
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A crafted payload can be stored …

Dec 19, 2025
CVE-2025-66500
6.3 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script …

Dec 19, 2025
CVE-2025-66498
5.3 MEDIUM

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing U3D data. When opening …

Dec 19, 2025
CVE-2025-66497
5.3 MEDIUM

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening …

Dec 19, 2025
CVE-2025-66496
5.3 MEDIUM

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data. When opening …

Dec 19, 2025
CVE-2025-66174
6.5 MEDIUM

There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with …

Dec 19, 2025
CVE-2025-66173
6.2 MEDIUM

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with …

Dec 19, 2025
CVE-2025-14449
6.4 MEDIUM

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-form shortcode in all versions up to, and including, …

Dec 19, 2025
CVE-2025-14267
4.9 MEDIUM

Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7

Dec 19, 2025
CVE-2025-13754
5.3 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Dec 19, 2025
CVE-2025-14546
6.3 MEDIUM

Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth state parameter during …

Dec 19, 2025
CVE-2025-14939
4.7 MEDIUM

A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the file /admin/deletemanager.php. The manipulation of the argument …

Dec 19, 2025
CVE-2025-67846
4.9 MEDIUM

The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the …

Dec 19, 2025
CVE-2025-67845
6.4 MEDIUM

A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML …

Dec 19, 2025
CVE-2025-67844
5.0 MEDIUM

The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields. It …

Dec 19, 2025
CVE-2025-67842
6.4 MEDIUM

The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any …

Dec 19, 2025
CVE-2025-14910
4.3 MEDIUM

A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation results in path traversal. …

Dec 19, 2025
CVE-2025-14909
4.3 MEDIUM

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead …

Dec 19, 2025
CVE-2025-14908
6.3 MEDIUM

A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the component …

Dec 19, 2025
CVE-2025-14900
4.7 MEDIUM

A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /admin/userdelete.php of the component …

Dec 19, 2025
CVE-2025-14899
4.7 MEDIUM

A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /admin/stateadd.php of the component Administrator …

Dec 19, 2025
CVE-2025-14898
4.7 MEDIUM

A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component …

Dec 19, 2025
CVE-2025-14897
4.7 MEDIUM

A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component …

Dec 19, 2025
CVE-2025-68422
4.3 MEDIUM

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to bypass intended permission restrictions via a crafted HTTP …

Dec 18, 2025
CVE-2025-68390
4.9 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of …

Dec 18, 2025
CVE-2025-68389
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) of computing resources and …

Dec 18, 2025
CVE-2025-68387
6.1 MEDIUM

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be …

Dec 18, 2025
CVE-2025-68386
4.3 MEDIUM

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even …

Dec 18, 2025
CVE-2025-68388
5.3 MEDIUM

Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration …

Dec 18, 2025
CVE-2025-68384
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial …

Dec 18, 2025
CVE-2025-68383
6.5 MEDIUM

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to …

Dec 18, 2025
CVE-2025-68382
6.5 MEDIUM

Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through …

Dec 18, 2025
CVE-2025-68381
6.5 MEDIUM

Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause …

Dec 18, 2025
CVE-2025-68161
4.8 MEDIUM

The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName …

Dec 18, 2025
CVE-2025-67653
4.3 MEDIUM

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.

Dec 18, 2025
CVE-2025-63949
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' …

Dec 18, 2025
CVE-2025-63948
5.4 MEDIUM

A SQL Injection vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially …

Dec 18, 2025
CVE-2025-63947
5.4 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via …

Dec 18, 2025
CVE-2025-62002
4.3 MEDIUM

BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection …

Dec 18, 2025
CVE-2025-59529
5.5 MEDIUM

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the …

Dec 18, 2025
CVE-2025-46268
6.3 MEDIUM

Advantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.

Dec 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.