CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-6251
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['field_id'] in all versions up to, and including, 1.7.1036 …

Nov 19, 2025
CVE-2025-12777
5.3 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the …

Nov 19, 2025
CVE-2025-12770
5.3 MEDIUM

The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and including, 3.0.9 due to insufficient API …

Nov 19, 2025
CVE-2025-12427
5.3 MEDIUM

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST …

Nov 19, 2025
CVE-2025-13225
5.6 MEDIUM

Tanium addressed an arbitrary file deletion vulnerability in TanOS.

Nov 19, 2025
CVE-2025-65093
5.5 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application …

Nov 18, 2025
CVE-2025-65013
6.2 MEDIUM

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application …

Nov 18, 2025
CVE-2025-65012
5.4 MEDIUM

Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any page or the name of any …

Nov 18, 2025
CVE-2025-64515
4.3 MEDIUM

Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data fields are dynamically set to …

Nov 18, 2025
CVE-2025-54990
5.3 MEDIUM

XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights …

Nov 18, 2025
CVE-2025-63229
5.4 MEDIUM

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious …

Nov 18, 2025
CVE-2025-12119
6.8 MEDIUM

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

Nov 18, 2025
CVE-2025-63226
5.7 MEDIUM

The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. …

Nov 18, 2025
CVE-2025-37162
6.5 MEDIUM

A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could …

Nov 18, 2025
CVE-2025-63749
6.5 MEDIUM

pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter.

Nov 18, 2025
CVE-2025-63693
5.4 MEDIUM

The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows …

Nov 18, 2025
CVE-2025-61664
4.9 MEDIUM

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit …

Nov 18, 2025
CVE-2025-61663
4.9 MEDIUM

A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free …

Nov 18, 2025
CVE-2025-61661
4.8 MEDIUM

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from …

Nov 18, 2025
CVE-2025-56499
6.5 MEDIUM

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key …

Nov 18, 2025
CVE-2025-54771
4.9 MEDIUM

A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, …

Nov 18, 2025
CVE-2025-54770
4.9 MEDIUM

A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free …

Nov 18, 2025
CVE-2025-54320
4.3 MEDIUM

In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated …

Nov 18, 2025
CVE-2025-37160
5.3 MEDIUM

A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful …

Nov 18, 2025
CVE-2025-37159
5.8 MEDIUM

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user …

Nov 18, 2025
CVE-2025-37158
6.7 MEDIUM

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) …

Nov 18, 2025
CVE-2025-37157
6.7 MEDIUM

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) …

Nov 18, 2025
CVE-2025-37156
6.8 MEDIUM

A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code …

Nov 18, 2025
CVE-2025-63828
6.1 MEDIUM

Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains …

Nov 18, 2025
CVE-2025-63514
6.1 MEDIUM

kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.

Nov 18, 2025
CVE-2025-63513
6.5 MEDIUM

kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.

Nov 18, 2025
CVE-2025-63512
6.5 MEDIUM

kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or …

Nov 18, 2025
CVE-2025-63258
6.5 MEDIUM

A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series routers, cloud gateways, and wireless access points (versions …

Nov 18, 2025
CVE-2025-61713
4.2 MEDIUM

A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all …

Nov 18, 2025
CVE-2025-59669
5.3 MEDIUM

A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an …

Nov 18, 2025
CVE-2025-56526
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.

Nov 18, 2025
CVE-2025-54972
4.3 MEDIUM

An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 …

Nov 18, 2025
CVE-2025-54971
4.3 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all …

Nov 18, 2025
CVE-2025-54660
5.5 MEDIUM

An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to …

Nov 18, 2025
CVE-2025-53360
4.3 MEDIUM

pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior …

Nov 18, 2025
CVE-2025-48839
6.6 MEDIUM

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all …

Nov 18, 2025
CVE-2025-46776
6.4 MEDIUM

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all …

Nov 18, 2025
CVE-2025-46775
5.5 MEDIUM

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions …

Nov 18, 2025
CVE-2025-46215
5.3 MEDIUM

An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions …

Nov 18, 2025
CVE-2025-13082
4.3 MEDIUM

User Interface (UI) Misrepresentation of Critical Information vulnerability in Drupal Drupal core allows Content Spoofing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 …

Nov 18, 2025
CVE-2025-13081
5.9 MEDIUM

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 …

Nov 18, 2025
CVE-2025-13080
5.3 MEDIUM

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This issue affects Drupal core: from 8.0.0 before 10.4.9, from 10.5.0 …

Nov 18, 2025
CVE-2025-12760
5.4 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6.

Nov 18, 2025
CVE-2025-64996
4.4 MEDIUM

In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local …

Nov 18, 2025
CVE-2025-63604
6.5 MEDIUM

A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code execution through insufficient input validation in the execute_query method. The vulnerability stems from …

Nov 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.