CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-56423
5.3 MEDIUM

An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error …

Nov 24, 2025
CVE-2025-12978
5.4 MEDIUM

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows …

Nov 24, 2025
CVE-2025-12972
5.3 MEDIUM

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted …

Nov 24, 2025
CVE-2025-12969
6.5 MEDIUM

Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to …

Nov 24, 2025
CVE-2025-65503
5.5 MEDIUM

Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that …

Nov 24, 2025
CVE-2025-65502
4.3 MEDIUM

Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns …

Nov 24, 2025
CVE-2025-65501
4.3 MEDIUM

Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() returns …

Nov 24, 2025
CVE-2025-65500
4.3 MEDIUM

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-65499
4.3 MEDIUM

Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-65498
4.3 MEDIUM

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-65497
4.3 MEDIUM

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-65496
4.3 MEDIUM

NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake …

Nov 24, 2025
CVE-2025-12628
6.3 MEDIUM

The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass the second factor by brute forcing …

Nov 24, 2025
CVE-2025-13588
6.3 MEDIUM

A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown function of the file public/proxy.php. Performing …

Nov 24, 2025
CVE-2025-13586
4.7 MEDIUM

A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file /Admin/changepassword.php. This manipulation of the …

Nov 24, 2025
CVE-2025-12569
4.7 MEDIUM

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, …

Nov 24, 2025
CVE-2025-12394
5.9 MEDIUM

The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log …

Nov 24, 2025
CVE-2025-13581
6.3 MEDIUM

A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of …

Nov 24, 2025
CVE-2025-13580
6.3 MEDIUM

A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.php. This manipulation of the argument ID causes …

Nov 24, 2025
CVE-2025-13579
6.3 MEDIUM

A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php. The manipulation of the argument ID results …

Nov 24, 2025
CVE-2025-13576
6.3 MEDIUM

A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulation results in improper …

Nov 24, 2025
CVE-2025-13575
6.3 MEDIUM

A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/blog.php of the component Category Handler. …

Nov 24, 2025
CVE-2025-13574
4.7 MEDIUM

A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the …

Nov 24, 2025
CVE-2025-13573
6.3 MEDIUM

A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_book.php. The …

Nov 24, 2025
CVE-2025-12800
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via …

Nov 23, 2025
CVE-2025-13571
6.3 MEDIUM

A vulnerability was determined in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /listorder.php. Executing manipulation …

Nov 23, 2025
CVE-2025-13570
6.3 MEDIUM

A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=state. Performing manipulation of …

Nov 23, 2025
CVE-2025-13569
6.3 MEDIUM

A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/?page=city. Such manipulation of the argument …

Nov 23, 2025
CVE-2025-13568
6.3 MEDIUM

A flaw has been found in itsourcecode COVID Tracking System 1.0. This impacts an unknown function of the file /admin/?page=people. This manipulation of the argument …

Nov 23, 2025
CVE-2025-13567
6.3 MEDIUM

A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This affects an unknown function of the file /admin/?page=establishment. The manipulation of the argument ID …

Nov 23, 2025
CVE-2025-13565
5.3 MEDIUM

A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can …

Nov 23, 2025
CVE-2025-13564
5.4 MEDIUM

A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the …

Nov 23, 2025
CVE-2025-13546
6.3 MEDIUM

A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component …

Nov 23, 2025
CVE-2025-13545
4.7 MEDIUM

A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The …

Nov 23, 2025
CVE-2025-13544
6.3 MEDIUM

A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to …

Nov 23, 2025
CVE-2025-13318
5.3 MEDIUM

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to …

Nov 22, 2025
CVE-2025-13136
4.3 MEDIUM

The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' …

Nov 22, 2025
CVE-2025-13317
5.3 MEDIUM

The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the …

Nov 22, 2025
CVE-2025-12877
5.3 MEDIUM

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized modification od data due to a missing capability …

Nov 22, 2025
CVE-2025-12752
5.3 MEDIUM

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is …

Nov 22, 2025
CVE-2025-11186
6.4 MEDIUM

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookies_accepted shortcode in all …

Nov 22, 2025
CVE-2025-12889
5.4 MEDIUM

With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.

Nov 22, 2025
CVE-2025-11936
5.3 MEDIUM

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by …

Nov 21, 2025
CVE-2025-11933
6.5 MEDIUM

Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially …

Nov 21, 2025
CVE-2025-11932
4.3 MEDIUM

The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder

Nov 21, 2025
CVE-2025-65111
5.3 MEDIUM

SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: …

Nov 21, 2025
CVE-2025-65107
6.5 MEDIUM

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO …

Nov 21, 2025
CVE-2025-43374
4.3 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS …

Nov 21, 2025
CVE-2025-31266
4.3 MEDIUM

A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5. …

Nov 21, 2025
CVE-2025-31248
5.5 MEDIUM

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma …

Nov 21, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.