CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8404
5.5 MEDIUM

Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted …

Nov 18, 2025
CVE-2025-11267
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, …

Nov 18, 2025
CVE-2025-11265
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions …

Nov 18, 2025
CVE-2025-7623
5.4 MEDIUM

Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted …

Nov 18, 2025
CVE-2025-12524
5.4 MEDIUM

The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.0 due to missing validation …

Nov 18, 2025
CVE-2025-52578
5.7 MEDIUM

Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a sophisticated attacker with physical access, to …

Nov 18, 2025
CVE-2025-52457
5.7 MEDIUM

Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extract device-specific keys, potentially compromising further site …

Nov 18, 2025
CVE-2025-6599
5.3 MEDIUM

An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an attacker to perform Slowloris‑style denial‑of‑service …

Nov 18, 2025
CVE-2025-13325
6.3 MEDIUM

A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the …

Nov 18, 2025
CVE-2025-13306
6.3 MEDIUM

A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation …

Nov 18, 2025
CVE-2025-7711
5.4 MEDIUM

The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Nov 17, 2025
CVE-2025-64766
5.3 MEDIUM

NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.11 to before 25.05 …

Nov 17, 2025
CVE-2025-13303
6.3 MEDIUM

A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation of …

Nov 17, 2025
CVE-2025-13302
4.7 MEDIUM

A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName …

Nov 17, 2025
CVE-2025-36299
4.3 MEDIUM

IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further attacks against the system.

Nov 17, 2025
CVE-2024-44664
6.5 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.

Nov 17, 2025
CVE-2024-44661
5.4 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.

Nov 17, 2025
CVE-2024-46335
4.6 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.

Nov 17, 2025
CVE-2024-44663
6.5 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.

Nov 17, 2025
CVE-2024-44662
6.5 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.

Nov 17, 2025
CVE-2024-44660
6.5 MEDIUM

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.

Nov 17, 2025
CVE-2024-44658
6.5 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.

Nov 17, 2025
CVE-2024-44655
6.1 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php.

Nov 17, 2025
CVE-2024-44654
6.5 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php.

Nov 17, 2025
CVE-2025-64758
4.8 MEDIUM

@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in …

Nov 17, 2025
CVE-2025-55059
4.8 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Nov 17, 2025
CVE-2025-55058
4.5 MEDIUM

CWE-20 Improper Input Validation

Nov 17, 2025
CVE-2025-55057
4.5 MEDIUM

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

Nov 17, 2025
CVE-2025-55056
4.8 MEDIUM

Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Nov 17, 2025
CVE-2025-55055
6.8 MEDIUM

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Nov 17, 2025
CVE-2024-44657
6.5 MEDIUM

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php.

Nov 17, 2025
CVE-2024-44653
6.5 MEDIUM

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.

Nov 17, 2025
CVE-2024-44651
6.5 MEDIUM

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.

Nov 17, 2025
CVE-2025-63918
6.2 MEDIUM

PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations.

Nov 17, 2025
CVE-2025-13290
6.3 MEDIUM

A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /saveorder.php. Such …

Nov 17, 2025
CVE-2025-13193
5.5 MEDIUM

A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, making it possible for unprivileged users to inspect …

Nov 17, 2025
CVE-2024-46336
6.1 MEDIUM

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.

Nov 17, 2025
CVE-2024-46334
6.1 MEDIUM

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.

Nov 17, 2025
CVE-2024-44652
6.5 MEDIUM

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.

Nov 17, 2025
CVE-2024-44648
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.

Nov 17, 2025
CVE-2024-44647
6.1 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.

Nov 17, 2025
CVE-2024-44644
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.

Nov 17, 2025
CVE-2024-44641
6.5 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.

Nov 17, 2025
CVE-2025-64046
6.1 MEDIUM

OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.

Nov 17, 2025
CVE-2025-63708
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows remote attackers to execute arbitrary JavaScript in victims' browsers. The vulnerability …

Nov 17, 2025
CVE-2025-13289
6.3 MEDIUM

A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The …

Nov 17, 2025
CVE-2025-13287
6.3 MEDIUM

A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /index.php?page=categories. Executing manipulation of the argument …

Nov 17, 2025
CVE-2025-13286
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation …

Nov 17, 2025
CVE-2025-13279
6.3 MEDIUM

A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of …

Nov 17, 2025
CVE-2025-13278
6.3 MEDIUM

A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowed_book_search.php. Such manipulation of the …

Nov 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.