CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2879
5.1 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver …

Dec 1, 2025
CVE-2025-41739
5.9 MEDIUM

An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux …

Dec 1, 2025
CVE-2025-13819
6.1 MEDIUM

Open redirect in the web server component of MiR Robot and Fleet software allows a remote attacker to redirect users to arbitrary external websites via …

Dec 1, 2025
CVE-2025-13816
6.3 MEDIUM

A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile …

Dec 1, 2025
CVE-2025-13815
6.3 MEDIUM

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This …

Dec 1, 2025
CVE-2025-13813
5.6 MEDIUM

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component …

Dec 1, 2025
CVE-2025-13811
6.3 MEDIUM

A vulnerability was determined in jsnjfz WebStack-Guns 1.0. This vulnerability affects unknown code of the file src/main/java/com/jsnjfz/manage/core/common/constant/factory/PageFactory.java. Executing a manipulation of the argument sort can …

Dec 1, 2025
CVE-2025-13810
5.3 MEDIUM

A vulnerability was found in jsnjfz WebStack-Guns 1.0. This affects the function renderPicture of the file src/main/java/com/jsnjfz/manage/modular/system/controller/KaptchaController.java. Performing a manipulation results in path traversal. It …

Dec 1, 2025
CVE-2025-13809
6.3 MEDIUM

A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this issue is some unknown functionality of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineInfoController.java of the …

Dec 1, 2025
CVE-2025-13807
4.3 MEDIUM

A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineKeyController.java of the component API. The manipulation …

Dec 1, 2025
CVE-2025-13804
4.3 MEDIUM

A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the …

Dec 1, 2025
CVE-2025-13802
4.3 MEDIUM

A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted is an unknown function of the component Make a Reservation. This manipulation of the …

Dec 1, 2025
CVE-2025-13800
6.3 MEDIUM

A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The manipulation of the argument mac results …

Dec 1, 2025
CVE-2025-13799
6.3 MEDIUM

A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.cgi. The manipulation of the argument mac …

Dec 1, 2025
CVE-2025-13798
6.3 MEDIUM

A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulation of the argument mac can …

Dec 1, 2025
CVE-2025-13797
6.3 MEDIUM

A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cgi. Performing manipulation of the argument …

Dec 1, 2025
CVE-2025-13796
6.3 MEDIUM

A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function AnalyticsScript of the file website/loaders/analyticsScript.ts of …

Dec 1, 2025
CVE-2025-13793
4.3 MEDIUM

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the …

Nov 30, 2025
CVE-2025-13791
6.3 MEDIUM

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation …

Nov 30, 2025
CVE-2025-13790
4.3 MEDIUM

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated …

Nov 30, 2025
CVE-2025-13789
6.3 MEDIUM

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results …

Nov 30, 2025
CVE-2025-13787
5.4 MEDIUM

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File …

Nov 30, 2025
CVE-2025-13785
4.3 MEDIUM

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile …

Nov 30, 2025
CVE-2025-13783
6.3 MEDIUM

A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/CommentadminController.class.php of the component CommentadminController. …

Nov 30, 2025
CVE-2025-66433
4.2 MEDIUM

HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed …

Nov 30, 2025
CVE-2025-66432
5.0 MEDIUM

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

Nov 30, 2025
CVE-2025-66424
6.5 MEDIUM

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Nov 30, 2025
CVE-2025-66422
4.3 MEDIUM

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Nov 30, 2025
CVE-2025-66421
5.4 MEDIUM

Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.69.

Nov 30, 2025
CVE-2025-66420
5.4 MEDIUM

Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and 6.0.67.

Nov 30, 2025
CVE-2025-66291
4.3 MEDIUM

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files …

Nov 29, 2025
CVE-2025-66290
4.3 MEDIUM

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required …

Nov 29, 2025
CVE-2025-65892
6.1 MEDIUM

Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted …

Nov 29, 2025
CVE-2025-65540
6.1 MEDIUM

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are …

Nov 29, 2025
CVE-2025-66221
5.3 MEDIUM

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows device names. On Windows, there …

Nov 29, 2025
CVE-2025-61915
6.0 MEDIUM

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group …

Nov 29, 2025
CVE-2025-58436
5.1 MEDIUM

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd …

Nov 29, 2025
CVE-2025-53939
6.3 MEDIUM

Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly …

Nov 29, 2025
CVE-2025-53900
6.5 MEDIUM

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could …

Nov 29, 2025
CVE-2025-53897
6.8 MEDIUM

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from …

Nov 29, 2025
CVE-2025-66036
6.1 MEDIUM

Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cross-site scripting (XSS) in the input …

Nov 29, 2025
CVE-2025-66034
6.3 MEDIUM

fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script …

Nov 29, 2025
CVE-2025-66027
6.5 MEDIUM

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through …

Nov 29, 2025
CVE-2025-65113
6.5 MEDIUM

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging system allows …

Nov 29, 2025
CVE-2025-64715
4.0 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference …

Nov 29, 2025
CVE-2025-13683
6.5 MEDIUM

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

Nov 28, 2025
CVE-2025-59792
5.3 MEDIUM

Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade …

Nov 28, 2025
CVE-2025-59790
5.4 MEDIUM

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which …

Nov 28, 2025
CVE-2025-51736
6.3 MEDIUM

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025
CVE-2025-51734
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

Nov 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.