CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64569
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64566
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64565
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64564
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64563
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64562
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64560
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64559
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64558
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64557
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64556
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64555
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64554
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64553
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64551
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64550
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64549
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64548
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64547
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64546
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-64545
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64544
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64543
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker …

Dec 10, 2025
CVE-2025-64541
5.4 MEDIUM

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Dec 10, 2025
CVE-2025-56429
6.1 MEDIUM

Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component.

Dec 10, 2025
CVE-2025-34430
4.3 MEDIUM

1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not implement CSRF …

Dec 10, 2025
CVE-2025-65754
6.1 MEDIUM

Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.

Dec 10, 2025
CVE-2025-67643
4.3 MEDIUM

Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to …

Dec 10, 2025
CVE-2025-67642
4.3 MEDIUM

Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and …

Dec 10, 2025
CVE-2025-67641
5.4 MEDIUM

Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through …

Dec 10, 2025
CVE-2025-67640
5.0 MEDIUM

Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a …

Dec 10, 2025
CVE-2025-67638
4.3 MEDIUM

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers …

Dec 10, 2025
CVE-2025-67637
4.3 MEDIUM

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be …

Dec 10, 2025
CVE-2025-67636
4.3 MEDIUM

A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.

Dec 10, 2025
CVE-2025-65815
6.5 MEDIUM

A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory …

Dec 10, 2025
CVE-2025-65814
6.5 MEDIUM

A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal.

Dec 10, 2025
CVE-2025-52493
6.5 MEDIUM

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the …

Dec 10, 2025
CVE-2025-65803
6.5 MEDIUM

An integer overflow in the psdParser::ReadImageData function of FreeImage v3.18.0 and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Dec 10, 2025
CVE-2025-13125
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Exploitation of Trusted Identifiers.This …

Dec 10, 2025
CVE-2024-2105
6.5 MEDIUM

An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.

Dec 10, 2025
CVE-2025-66004
5.7 MEDIUM

A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba.

Dec 10, 2025
CVE-2025-14087
5.6 MEDIUM

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or …

Dec 10, 2025
CVE-2025-9056
5.3 MEDIUM

Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.

Dec 10, 2025
CVE-2025-13677
4.9 MEDIUM

The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.2. This is due to insufficient …

Dec 10, 2025
CVE-2025-67485
5.3 MEDIUM

mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers …

Dec 10, 2025
CVE-2025-67502
5.4 MEDIUM

Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs that redirect users to arbitrary external websites …

Dec 10, 2025
CVE-2025-67499
6.6 MEDIUM

The CNI portmap plugin allows containers to emulate opening a host port, forwarding that traffic to the container. Versions 1.6.0 through 1.8.0 inadvertently forward all …

Dec 10, 2025
CVE-2025-64898
4.3 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker …

Dec 10, 2025
CVE-2025-64897
5.6 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass …

Dec 10, 2025
CVE-2025-61823
6.2 MEDIUM

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary …

Dec 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.