CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-14749
6.3 MEDIUM

A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVIF PTZ Control Interface. The …

Dec 16, 2025
CVE-2025-14748
5.4 MEDIUM

A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVIF Device Management Service. Executing …

Dec 16, 2025
CVE-2025-14747
4.3 MEDIUM

A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTSP Service. Performing manipulation results in denial …

Dec 16, 2025
CVE-2025-14746
4.3 MEDIUM

A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endpoint. Such …

Dec 16, 2025
CVE-2025-68115
6.1 MEDIUM

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, …

Dec 16, 2025
CVE-2025-68113
6.5 MEDIUM

ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay …

Dec 16, 2025
CVE-2025-67874
6.5 MEDIUM

ChurchCRM is an open-source church management system. Prior to version 6.5.0, the application echoes back plaintext passwords submitted by users in subsequent HTTP responses. This …

Dec 16, 2025
CVE-2025-67735
6.5 MEDIUM

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI …

Dec 16, 2025
CVE-2025-67715
4.3 MEDIUM

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via …

Dec 16, 2025
CVE-2025-67492
5.3 MEDIUM

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted …

Dec 16, 2025
CVE-2025-14758
6.5 MEDIUM

Incorrect configuration of replication security in the MariaDB component of the infra-operator in YAOOK Operator allows an on-path attacker to read database contents, potentially including …

Dec 16, 2025
CVE-2025-66482
6.5 MEDIUM

Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can …

Dec 16, 2025
CVE-2025-66407
5.0 MEDIUM

Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a …

Dec 16, 2025
CVE-2025-66402
6.5 MEDIUM

Misskey is an open source, federated social media platform. Starting in version 13.0.0-beta.16 and prior to version 2025.12.0, an actor who does not have permission …

Dec 16, 2025
CVE-2025-14731
6.3 MEDIUM

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component …

Dec 16, 2025
CVE-2025-9122
5.3 MEDIUM

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when …

Dec 15, 2025
CVE-2025-14730
4.7 MEDIUM

A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php …

Dec 15, 2025
CVE-2025-14729
4.7 MEDIUM

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the …

Dec 15, 2025
CVE-2023-53893
6.5 MEDIUM

Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers …

Dec 15, 2025
CVE-2023-53891
5.4 MEDIUM

Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads …

Dec 15, 2025
CVE-2023-53890
5.4 MEDIUM

Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG …

Dec 15, 2025
CVE-2023-53887
5.4 MEDIUM

Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating new pages. Attackers can craft malicious image source …

Dec 15, 2025
CVE-2023-53884
5.4 MEDIUM

Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted …

Dec 15, 2025
CVE-2023-53879
5.5 MEDIUM

NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attackers to crash the application. Attackers can overwrite 846 …

Dec 15, 2025
CVE-2023-53876
5.4 MEDIUM

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject …

Dec 15, 2025
CVE-2023-38913
5.3 MEDIUM

SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

Dec 15, 2025
CVE-2023-36338
5.3 MEDIUM

Inventory Management System 1 was discovered to contain a SQL injection vulnerability.

Dec 15, 2025
CVE-2025-67809
4.7 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr …

Dec 15, 2025
CVE-2025-36360
5.0 MEDIUM

IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through …

Dec 15, 2025
CVE-2025-14148
6.5 MEDIUM

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM …

Dec 15, 2025
CVE-2025-13489
5.9 MEDIUM

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attacker to obtain sensitive …

Dec 15, 2025
CVE-2025-12035
6.5 MEDIUM

An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for processing inbound BR/EDR L2CAP traffic.

Dec 15, 2025
CVE-2025-65835
6.2 MEDIUM

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRA_CHOSEN_COMPONENT without …

Dec 15, 2025
CVE-2025-51962
6.1 MEDIUM

A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attackers to inject arbitrary web script or HTML …

Dec 15, 2025
CVE-2023-36337
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML …

Dec 15, 2025
CVE-2025-66436
4.3 MEDIUM

An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (terms) using frappe.render_template() …

Dec 15, 2025
CVE-2025-66435
4.3 MEDIUM

An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext through 15.89.0. The function renders attacker-controlled Jinja2 templates (contract_terms) using frappe.render_template() …

Dec 15, 2025
CVE-2025-55901
6.5 MEDIUM

TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_time parameter.

Dec 15, 2025
CVE-2025-55893
6.5 MEDIUM

TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName.

Dec 15, 2025
CVE-2025-66963
5.5 MEDIUM

An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in the index.html

Dec 15, 2025
CVE-2025-66843
5.4 MEDIUM

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content …

Dec 15, 2025
CVE-2025-14387
6.4 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to …

Dec 15, 2025
CVE-2025-14003
4.3 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Dec 15, 2025
CVE-2025-13950
5.3 MEDIUM

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings …

Dec 15, 2025
CVE-2025-13728
6.4 MEDIUM

The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fluent_auth_reset_password` shortcode …

Dec 15, 2025
CVE-2025-13610
6.4 MEDIUM

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RM_Forms' …

Dec 15, 2025
CVE-2025-13608
6.4 MEDIUM

The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in all versions up to, and including, 2.0.0. …

Dec 15, 2025
CVE-2025-13367
6.4 MEDIUM

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to …

Dec 15, 2025
CVE-2025-12900
4.3 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, …

Dec 15, 2025
CVE-2025-65782
6.5 MEDIUM

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling …

Dec 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.