CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-40834
5.7 MEDIUM

A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not properly neutralize the input. This could allow …

Nov 17, 2025
CVE-2025-11681
6.5 MEDIUM

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver …

Nov 17, 2025
CVE-2025-13275
4.7 MEDIUM

A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This affects an unknown part of the file /admin/about.php. The manipulation leads to …

Nov 17, 2025
CVE-2025-13274
6.3 MEDIUM

A weakness has been identified in Campcodes School Fees Payment Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_fees. …

Nov 17, 2025
CVE-2025-13273
6.3 MEDIUM

A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Nov 17, 2025
CVE-2025-13270
6.3 MEDIUM

A vulnerability was found in Campcodes School Fees Payment Management System 1.0. This affects an unknown function of the file /ajax.php?action=save_course. The manipulation of the …

Nov 17, 2025
CVE-2025-13269
6.3 MEDIUM

A vulnerability has been found in Campcodes School Fees Payment Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_payment. The …

Nov 17, 2025
CVE-2025-13268
6.3 MEDIUM

A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/main/java/com/vince/xq/project/system/dbconfig/service/DbconfigServiceImpl.java of the component …

Nov 17, 2025
CVE-2025-13267
6.3 MEDIUM

A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown function of the file /success.php. Performing manipulation of the …

Nov 17, 2025
CVE-2025-13164
4.9 MEDIUM

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system mail from …

Nov 17, 2025
CVE-2025-13163
4.9 MEDIUM

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext database account credentials from the system frontend.

Nov 17, 2025
CVE-2025-60022
4.8 MEDIUM

Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man-in-the-middle attack may allow an attacker …

Nov 17, 2025
CVE-2025-13266
5.3 MEDIUM

A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the file vlife-base/src/main/java/cn/wwwlike/sys/api/SysFileApi.java of the component …

Nov 17, 2025
CVE-2025-13265
6.3 MEDIUM

A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. This manipulation causes path …

Nov 17, 2025
CVE-2025-13264
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown part of the file /view_magazine.php. The manipulation of …

Nov 17, 2025
CVE-2025-13263
6.3 MEDIUM

A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation …

Nov 17, 2025
CVE-2025-13261
5.3 MEDIUM

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version …

Nov 17, 2025
CVE-2025-13260
6.3 MEDIUM

A vulnerability has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /manufacturer/edit_product.php. Such manipulation of the argument …

Nov 17, 2025
CVE-2025-13259
6.3 MEDIUM

A flaw has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /manufacturer/edit_unit.php. This manipulation of the argument …

Nov 17, 2025
CVE-2025-13256
6.3 MEDIUM

A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrow.php. Executing a manipulation of …

Nov 17, 2025
CVE-2025-13255
6.3 MEDIUM

A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing a …

Nov 17, 2025
CVE-2025-13254
6.3 MEDIUM

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /add_member.php. Such manipulation of the argument …

Nov 17, 2025
CVE-2025-13253
6.3 MEDIUM

A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /add_librarian.php. This manipulation of the argument …

Nov 17, 2025
CVE-2025-13251
6.3 MEDIUM

A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can lead to sql injection. The attack …

Nov 16, 2025
CVE-2025-13250
6.3 MEDIUM

A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job Handler. Performing manipulation results in improper …

Nov 16, 2025
CVE-2025-13249
6.3 MEDIUM

A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTemplate=false of the component OfficeServer …

Nov 16, 2025
CVE-2025-13246
6.3 MEDIUM

A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthenticationFilter of the file src/main/java/com/suisung/shopsuite/common/security/JwtAuthenticationFilter.java. The manipulation leads to path …

Nov 16, 2025
CVE-2025-13244
4.3 MEDIUM

A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown function of the file /register.php. This manipulation causes cross …

Nov 16, 2025
CVE-2025-13243
6.3 MEDIUM

A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /editprofile.php. The manipulation results in sql injection. …

Nov 16, 2025
CVE-2025-13239
4.3 MEDIUM

A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of …

Nov 16, 2025
CVE-2025-13238
6.3 MEDIUM

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the …

Nov 16, 2025
CVE-2025-13236
6.3 MEDIUM

A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID …

Nov 16, 2025
CVE-2025-13234
6.3 MEDIUM

A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the …

Nov 16, 2025
CVE-2025-13221
5.3 MEDIUM

A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument …

Nov 15, 2025
CVE-2025-13210
4.7 MEDIUM

A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the …

Nov 15, 2025
CVE-2025-13209
6.3 MEDIUM

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument …

Nov 15, 2025
CVE-2025-13208
6.3 MEDIUM

A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The …

Nov 15, 2025
CVE-2025-13200
5.3 MEDIUM

A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of information through …

Nov 15, 2025
CVE-2025-13199
5.3 MEDIUM

A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username …

Nov 15, 2025
CVE-2025-13198
4.7 MEDIUM

A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the …

Nov 15, 2025
CVE-2025-7000
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific …

Nov 15, 2025
CVE-2025-6171
5.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have …

Nov 15, 2025
CVE-2025-2615
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have …

Nov 15, 2025
CVE-2025-11865
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain …

Nov 15, 2025
CVE-2025-12849
5.3 MEDIUM

The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin …

Nov 15, 2025
CVE-2025-8994
6.5 MEDIUM

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL …

Nov 15, 2025
CVE-2025-12847
4.3 MEDIUM

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media …

Nov 15, 2025
CVE-2025-12494
4.3 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in …

Nov 15, 2025
CVE-2025-12182
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up …

Nov 15, 2025
CVE-2025-8386
6.9 MEDIUM

The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting …

Nov 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.