CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-14006
3.5 LOW

A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=1 of …

Dec 4, 2025
CVE-2025-14005
2.4 LOW

A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=0 of the …

Dec 4, 2025
CVE-2025-64763
3.7 LOW

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, …

Dec 3, 2025
CVE-2025-20388
2.7 LOW

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.7, and 9.3.2411.116, a user who holds a …

Dec 3, 2025
CVE-2025-20385
2.4 LOW

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117, a user who holds a …

Dec 3, 2025
CVE-2025-20382
3.5 LOW

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.10, 10.0.2503.8, and 9.3.2411.120, a low-privileged user that does …

Dec 3, 2025
CVE-2025-12954
2.7 LOW

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading …

Dec 3, 2025
CVE-2025-13640
3.5 LOW

Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the device. (Chromium security …

Dec 2, 2025
CVE-2025-59700
3.9 LOW

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with root access to modify the Recovery …

Dec 2, 2025
CVE-2025-59696
3.2 LOW

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to modify or erase tamper events via …

Dec 2, 2025
CVE-2025-65858
3.5 LOW

A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is …

Dec 2, 2025
CVE-2025-13879
2.7 LOW

Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the …

Dec 2, 2025
CVE-2025-13870
3.1 LOW

Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, …

Dec 2, 2025
CVE-2025-13805
3.7 LOW

A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoint.java of the component LiteRpc-Serializer. Executing …

Dec 1, 2025
CVE-2025-13795
2.4 LOW

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component …

Nov 30, 2025
CVE-2025-13784
2.4 LOW

A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the …

Nov 30, 2025
CVE-2025-6666
2.0 LOW

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. …

Nov 29, 2025
CVE-2025-66382
2.9 LOW

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

Nov 28, 2025
CVE-2025-66372
2.8 LOW

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

Nov 28, 2025
CVE-2025-13758
3.5 LOW

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Nov 27, 2025
CVE-2025-66040
3.6 LOW

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth callback …

Nov 27, 2025
CVE-2025-13611
2.0 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated …

Nov 26, 2025
CVE-2025-65681
3.3 LOW

An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper …

Nov 26, 2025
CVE-2025-20373
2.7 LOW

In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition …

Nov 26, 2025
CVE-2025-55174
3.2 LOW

In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the …

Nov 26, 2025
CVE-2025-65942
2.7 LOW

VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and …

Nov 25, 2025
CVE-2025-65961
3.3 LOW

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the …

Nov 25, 2025
CVE-2025-33200
2.3 LOW

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this …

Nov 25, 2025
CVE-2025-33199
3.2 LOW

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow behavior. A successful exploit of this vulnerability …

Nov 25, 2025
CVE-2025-33198
3.3 LOW

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this …

Nov 25, 2025
CVE-2025-36134
3.7 LOW

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.1 could disclose sensitive information due to a …

Nov 25, 2025
CVE-2025-59485
3.3 LOW

Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerability is exploited, an arbitrary file could be placed …

Nov 25, 2025
CVE-2025-13643
3.1 LOW

A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by …

Nov 25, 2025
CVE-2025-13584
3.5 LOW

A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the component Description Handler. The manipulation of the …

Nov 24, 2025
CVE-2025-13577
3.5 LOW

A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation …

Nov 24, 2025
CVE-2025-13566
3.3 LOW

A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_floating_window/run_cmd_as_plugin of the file nnn/src/nnn.c. The manipulation …

Nov 23, 2025
CVE-2025-11934
2.7 LOW

Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm …

Nov 21, 2025
CVE-2025-31216
2.4 LOW

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to …

Nov 21, 2025
CVE-2025-66062
3.4 LOW

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allows Phishing.This issue affects WP YouTube Lyte: from n/a through …

Nov 21, 2025
CVE-2025-64299
2.7 LOW

LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes.

Nov 21, 2025
CVE-2025-13484
2.4 LOW

A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of …

Nov 20, 2025
CVE-2025-52666
2.7 LOW

Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin …

Nov 20, 2025
CVE-2025-35029
3.5 LOW

Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' …

Nov 20, 2025
CVE-2025-64524
3.3 LOW

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and …

Nov 20, 2025
CVE-2025-13469
2.4 LOW

A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the …

Nov 20, 2025
CVE-2025-13450
3.5 LOW

A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipulation of the argument f_name …

Nov 20, 2025
CVE-2025-13415
3.5 LOW

A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image Handler. …

Nov 19, 2025
CVE-2025-13412
2.4 LOW

A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing …

Nov 19, 2025
CVE-2025-64757
3.5 LOW

Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file …

Nov 19, 2025
CVE-2025-13397
3.3 LOW

A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file src/alloc.c. Such manipulation of the argument …

Nov 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.