CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11368
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is …

Nov 21, 2025
CVE-2025-62426
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize endpoints allow a …

Nov 21, 2025
CVE-2025-62372
6.5 MEDIUM

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving …

Nov 21, 2025
CVE-2025-36160
5.3 MEDIUM

IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in further attacks against the system.

Nov 20, 2025
CVE-2025-36159
6.2 MEDIUM

IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper …

Nov 20, 2025
CVE-2025-36158
5.1 MEDIUM

IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.

Nov 20, 2025
CVE-2025-36153
6.1 MEDIUM

IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI …

Nov 20, 2025
CVE-2025-13087
6.2 MEDIUM

A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code execution with root privileges. When …

Nov 20, 2025
CVE-2025-64770
6.8 MEDIUM

The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may allow an attacker unauthorized access to camera configuration information.

Nov 20, 2025
CVE-2025-62674
6.8 MEDIUM

The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an attacker unauthorized access to camera configuration information.

Nov 20, 2025
CVE-2025-55124
6.1 MEDIUM

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

Nov 20, 2025
CVE-2025-55123
5.4 MEDIUM

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their …

Nov 20, 2025
CVE-2025-52671
4.3 MEDIUM

Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about …

Nov 20, 2025
CVE-2025-52670
6.5 MEDIUM

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

Nov 20, 2025
CVE-2025-52669
4.3 MEDIUM

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the …

Nov 20, 2025
CVE-2025-52668
5.4 MEDIUM

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a …

Nov 20, 2025
CVE-2025-52667
5.4 MEDIUM

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for …

Nov 20, 2025
CVE-2025-48987
6.1 MEDIUM

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

Nov 20, 2025
CVE-2025-55128
6.5 MEDIUM

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface …

Nov 20, 2025
CVE-2025-55127
5.4 MEDIUM

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading …

Nov 20, 2025
CVE-2025-55126
6.5 MEDIUM

HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign …

Nov 20, 2025
CVE-2025-64027
6.1 MEDIUM

Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application …

Nov 20, 2025
CVE-2025-63848
6.1 MEDIUM

Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook.

Nov 20, 2025
CVE-2025-62724
4.3 MEDIUM

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) …

Nov 20, 2025
CVE-2025-62709
6.8 MEDIUM

ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server …

Nov 20, 2025
CVE-2025-62875
5.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before …

Nov 20, 2025
CVE-2025-62731
4.8 MEDIUM

SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS …

Nov 20, 2025
CVE-2025-62729
5.4 MEDIUM

SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML and JS into website, which will be …

Nov 20, 2025
CVE-2025-62297
5.4 MEDIUM

SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be …

Nov 20, 2025
CVE-2025-62296
5.4 MEDIUM

SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be …

Nov 20, 2025
CVE-2025-62295
5.4 MEDIUM

SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be …

Nov 20, 2025
CVE-2025-62293
5.4 MEDIUM

SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able …

Nov 20, 2025
CVE-2025-60737
6.1 MEDIUM

Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the …

Nov 20, 2025
CVE-2025-36161
5.9 MEDIUM

IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict-Transport-Security. An attacker …

Nov 20, 2025
CVE-2025-65226
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.

Nov 20, 2025
CVE-2025-65223
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo.

Nov 20, 2025
CVE-2025-65222
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.

Nov 20, 2025
CVE-2025-65221
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList.

Nov 20, 2025
CVE-2025-65220
4.3 MEDIUM

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.

Nov 20, 2025
CVE-2025-64984
6.1 MEDIUM

Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases prior to 18.11.2025), Kaspersky Industrial CyberSecurity for Linux …

Nov 20, 2025
CVE-2025-62346
6.8 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's web browser to execute an unwanted, malicious …

Nov 20, 2025
CVE-2025-60799
6.1 MEDIUM

phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting …

Nov 20, 2025
CVE-2025-60798
6.5 MEDIUM

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery …

Nov 20, 2025
CVE-2025-60797
6.5 MEDIUM

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter …

Nov 20, 2025
CVE-2025-60796
6.1 MEDIUM

phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper …

Nov 20, 2025
CVE-2025-60794
6.5 MEDIUM

Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates …

Nov 20, 2025
CVE-2025-5092
6.4 MEDIUM

Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled lightGallery library (<= 2.8.3) in various versions due to …

Nov 20, 2025
CVE-2025-41076
6.5 MEDIUM

In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed session cookie. Instead of …

Nov 20, 2025
CVE-2025-40605
5.3 MEDIUM

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences …

Nov 20, 2025
CVE-2025-13468
5.4 MEDIUM

A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete …

Nov 20, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.