CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2848
6.3 MEDIUM

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

Dec 4, 2025
CVE-2025-29845
4.3 MEDIUM

A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.

Dec 4, 2025
CVE-2025-29844
4.3 MEDIUM

A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.

Dec 4, 2025
CVE-2025-29843
5.4 MEDIUM

A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.

Dec 4, 2025
CVE-2025-14008
4.7 MEDIUM

A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec220c7e.php?c=api&m=test_site_domain of the component Project Domain …

Dec 4, 2025
CVE-2024-5401
4.3 MEDIUM

Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 and 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller …

Dec 4, 2025
CVE-2025-14004
4.7 MEDIUM

A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add of the component Email …

Dec 4, 2025
CVE-2025-11222
6.1 MEDIUM

Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating …

Dec 4, 2025
CVE-2025-41080
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser …

Dec 4, 2025
CVE-2025-41079
6.1 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attacker to execute arbitrary code in the victim's browser …

Dec 4, 2025
CVE-2025-14010
5.5 MEDIUM

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via verbose output when running Ansible …

Dec 4, 2025
CVE-2025-12826
4.8 MEDIUM

The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to …

Dec 4, 2025
CVE-2025-12782
4.3 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.9.4. This is …

Dec 4, 2025
CVE-2025-13513
6.1 MEDIUM

The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.8 due …

Dec 4, 2025
CVE-2025-11379
5.3 MEDIUM

The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and including, 0.25.9. This is due …

Dec 4, 2025
CVE-2025-66404
6.4 MEDIUM

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue …

Dec 3, 2025
CVE-2025-66406
5.0 MEDIUM

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorization check for SSH …

Dec 3, 2025
CVE-2025-65345
6.5 MEDIUM

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the …

Dec 3, 2025
CVE-2025-65097
6.5 MEDIUM

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, …

Dec 3, 2025
CVE-2025-65096
4.3 MEDIUM

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, …

Dec 3, 2025
CVE-2025-61727
6.5 MEDIUM

An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that …

Dec 3, 2025
CVE-2025-50361
5.1 MEDIUM

Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function main.cpp, which can lead to potential information …

Dec 3, 2025
CVE-2025-66220
5.0 MEDIUM

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS certificate matcher for match_typed_subject_alt_names may incorrectly treat certificates containing an …

Dec 3, 2025
CVE-2025-63402
5.5 MEDIUM

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on …

Dec 3, 2025
CVE-2025-63401
5.5 MEDIUM

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

Dec 3, 2025
CVE-2025-13992
4.7 MEDIUM

Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML …

Dec 3, 2025
CVE-2025-12084
5.3 MEDIUM

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when …

Dec 3, 2025
CVE-2025-64527
6.5 MEDIUM

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes when JWT authentication is configured with the remote JWKS fetching, …

Dec 3, 2025
CVE-2025-65842
5.1 MEDIUM

The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local …

Dec 3, 2025
CVE-2025-65841
6.2 MEDIUM

Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings using a weak obfuscation scheme. The password is "encrypted" through …

Dec 3, 2025
CVE-2025-62686
6.2 MEDIUM

A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 on macOS. Due to the absence …

Dec 3, 2025
CVE-2025-55076
6.2 MEDIUM

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections …

Dec 3, 2025
CVE-2025-53965
5.3 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, …

Dec 3, 2025
CVE-2025-20389
4.3 MEDIUM

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk …

Dec 3, 2025
CVE-2025-20384
5.3 MEDIUM

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated attacker can inject …

Dec 3, 2025
CVE-2025-20383
4.3 MEDIUM

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, …

Dec 3, 2025
CVE-2025-20381
5.4 MEDIUM

In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command …

Dec 3, 2025
CVE-2025-13751
5.5 MEDIUM

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service …

Dec 3, 2025
CVE-2025-57202
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML …

Dec 3, 2025
CVE-2025-57200
6.5 MEDIUM

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary …

Dec 3, 2025
CVE-2025-13949
6.3 MEDIUM

A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.go. The manipulation of the argument File leads to …

Dec 3, 2025
CVE-2025-13948
5.6 MEDIUM

A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. …

Dec 3, 2025
CVE-2025-13756
4.3 MEDIUM

The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in …

Dec 3, 2025
CVE-2025-13401
6.4 MEDIUM

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox in all versions up to, and including, …

Dec 3, 2025
CVE-2025-13359
6.5 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in …

Dec 3, 2025
CVE-2025-13354
4.3 MEDIUM

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and …

Dec 3, 2025
CVE-2025-13109
4.3 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Dec 3, 2025
CVE-2025-12887
5.4 MEDIUM

The Post SMTP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.1. This is due to the plugin …

Dec 3, 2025
CVE-2025-12358
4.3 MEDIUM

The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is …

Dec 3, 2025
CVE-2025-39665
5.3 MEDIUM

User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.

Dec 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.