CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40939
4.6 MEDIUM

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This …

Dec 9, 2025
CVE-2025-40935
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2 V5.X (All versions …

Dec 9, 2025
CVE-2025-40831
6.5 MEDIUM

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation …

Dec 9, 2025
CVE-2025-40830
6.7 MEDIUM

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer …

Dec 9, 2025
CVE-2025-40819
4.3 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the …

Dec 9, 2025
CVE-2025-40807
6.3 MEDIUM

A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay of authentication tokens. This could …

Dec 9, 2025
CVE-2025-40806
5.3 MEDIUM

A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. …

Dec 9, 2025
CVE-2025-14345
4.2 MEDIUM

A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server may lead to logical data inconsistencies under specific conditions …

Dec 9, 2025
CVE-2025-14331
6.5 MEDIUM

Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird …

Dec 9, 2025
CVE-2025-14286
5.3 MEDIUM

A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File …

Dec 9, 2025
CVE-2025-14284
6.1 MEDIUM

Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An …

Dec 9, 2025
CVE-2025-13642
5.4 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode …

Dec 9, 2025
CVE-2025-13070
6.6 MEDIUM

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing …

Dec 9, 2025
CVE-2025-13031
5.9 MEDIUM

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such …

Dec 9, 2025
CVE-2025-12558
4.3 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via …

Dec 9, 2025
CVE-2025-10876
5.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Cross-Site Scripting (XSS).This issue affects e-BAP …

Dec 9, 2025
CVE-2025-66491
5.9 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation …

Dec 9, 2025
CVE-2025-66490
6.5 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests using PathPrefix, Path or PathRegex matchers …

Dec 9, 2025
CVE-2025-66470
6.1 MEDIUM

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.interactive_image component of NiceGUI. The component renders …

Dec 9, 2025
CVE-2025-66469
6.1 MEDIUM

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to Reflected XSS through its ui.add_css, ui.add_scss, and ui.add_sass functions. The functions lack …

Dec 9, 2025
CVE-2025-66202
6.5 MEDIUM

Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks …

Dec 9, 2025
CVE-2025-65962
4.6 MEDIUM

Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763803709 and Tuleap …

Dec 9, 2025
CVE-2025-64760
4.6 MEDIUM

Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap …

Dec 8, 2025
CVE-2025-64499
4.6 MEDIUM

Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon versions prior to 17.0.99.1762456922 and Tuleap Enterprise …

Dec 8, 2025
CVE-2025-64498
4.6 MEDIUM

Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior …

Dec 8, 2025
CVE-2025-64497
6.5 MEDIUM

Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Edition and Tuleap Enterprise Edition below …

Dec 8, 2025
CVE-2025-36140
6.5 MEDIUM

IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation of resources …

Dec 8, 2025
CVE-2025-64650
6.5 MEDIUM

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.

Dec 8, 2025
CVE-2025-62408
5.9 MEDIUM

c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a …

Dec 8, 2025
CVE-2025-36017
6.5 MEDIUM

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained …

Dec 8, 2025
CVE-2025-36015
6.5 MEDIUM

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due …

Dec 8, 2025
CVE-2025-33111
4.3 MEDIUM

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of temporary files without atomic operations which may …

Dec 8, 2025
CVE-2025-14276
5.6 MEDIUM

A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the …

Dec 8, 2025
CVE-2025-12832
4.6 MEDIUM

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from …

Dec 8, 2025
CVE-2025-12635
5.4 MEDIUM

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.12 are affected by cross-site scripting due to improper validation of …

Dec 8, 2025
CVE-2025-65230
5.4 MEDIUM

Barix Instreamer v04.06 and v04.05 contains a stored cross-site scripting (XSS) vulnerability in the Web UI Configuration Streaming Destination input.

Dec 8, 2025
CVE-2025-65229
4.6 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the web interface of Lyrion Music Server <= 9.0.3. An authenticated user with access to Settings Player …

Dec 8, 2025
CVE-2025-65231
6.1 MEDIUM

Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close …

Dec 8, 2025
CVE-2025-65804
6.5 MEDIUM

Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE).

Dec 8, 2025
CVE-2025-48608
5.5 MEDIUM

In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local information disclosure …

Dec 8, 2025
CVE-2025-48569
5.5 MEDIUM

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no …

Dec 8, 2025
CVE-2025-14259
6.3 MEDIUM

A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functionality of the file /index.php/api.html. The manipulation …

Dec 8, 2025
CVE-2025-65799
4.3 MEDIUM

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

Dec 8, 2025
CVE-2025-65797
6.5 MEDIUM

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, …

Dec 8, 2025
CVE-2025-59391
6.5 MEDIUM

A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing …

Dec 8, 2025
CVE-2025-48633
5.5 MEDIUM KEV

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This …

Dec 8, 2025
CVE-2025-48631
6.5 MEDIUM

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with …

Dec 8, 2025
CVE-2025-48622
5.5 MEDIUM

In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with …

Dec 8, 2025
CVE-2025-48618
6.8 MEDIUM

In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could lead to physical escalation of privilege …

Dec 8, 2025
CVE-2025-48614
4.6 MEDIUM

In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check. This …

Dec 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.