CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64749
4.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messaging was found in the Directus REST …

Nov 13, 2025
CVE-2025-64748
6.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11.13.0 allows authenticated users to search …

Nov 13, 2025
CVE-2025-64747
5.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 11.13.0 …

Nov 13, 2025
CVE-2025-64746
4.6 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions …

Nov 13, 2025
CVE-2025-47222
6.5 MEDIUM

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a …

Nov 13, 2025
CVE-2025-47221
5.3 MEDIUM

An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTERN can be set to any path, even …

Nov 13, 2025
CVE-2025-47220
5.3 MEDIUM

A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in the PDFSigner and the PAdESSigner, can …

Nov 13, 2025
CVE-2025-60702
6.5 MEDIUM

A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user …

Nov 13, 2025
CVE-2025-60699
6.5 MEDIUM

A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `global.so` binary. The `getSaveConfig` function retrieves the `http_host` parameter from user …

Nov 13, 2025
CVE-2025-55810
6.8 MEDIUM

A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allows physical attackers …

Nov 13, 2025
CVE-2025-46368
6.6 MEDIUM

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially …

Nov 13, 2025
CVE-2025-46362
6.6 MEDIUM

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially …

Nov 13, 2025
CVE-2025-60676
6.5 MEDIUM

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' …

Nov 13, 2025
CVE-2025-60675
5.4 MEDIUM

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /tmp/new_qos.rule configuration file. The …

Nov 13, 2025
CVE-2025-60674
6.8 MEDIUM

A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when …

Nov 13, 2025
CVE-2025-60673
6.5 MEDIUM

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in …

Nov 13, 2025
CVE-2025-60672
6.5 MEDIUM

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' …

Nov 13, 2025
CVE-2025-13123
6.3 MEDIUM

A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation …

Nov 13, 2025
CVE-2025-64706
5.0 MEDIUM

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the …

Nov 13, 2025
CVE-2025-60701
6.5 MEDIUM

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_433188` function in `prog.cgi` stores user-supplied …

Nov 13, 2025
CVE-2025-60700
6.5 MEDIUM

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied …

Nov 13, 2025
CVE-2025-60693
6.5 MEDIUM

A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to …

Nov 13, 2025
CVE-2025-60671
5.4 MEDIUM

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /var/system/linux_vlan_reinit file. The vulnerability …

Nov 13, 2025
CVE-2025-59480
6.1 MEDIUM

Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path …

Nov 13, 2025
CVE-2025-12784
4.9 MEDIUM

Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP …

Nov 13, 2025
CVE-2025-60695
5.9 MEDIUM

A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032). The function sub_4045A8 reads up to 256 bytes from …

Nov 13, 2025
CVE-2025-20355
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthenticated, remote attacker to redirect a user to a …

Nov 13, 2025
CVE-2025-20353
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against …

Nov 13, 2025
CVE-2025-20349
6.3 MEDIUM

A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container as …

Nov 13, 2025
CVE-2025-20346
4.3 MEDIUM

A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should require Administrator privileges. The attacker would need valid …

Nov 13, 2025
CVE-2025-11538
6.8 MEDIUM

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to …

Nov 13, 2025
CVE-2025-64718
5.3 MEDIUM

js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the …

Nov 13, 2025
CVE-2025-64714
5.8 MEDIUM

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated …

Nov 13, 2025
CVE-2025-64703
6.3 MEDIUM

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations by Python code in tool module, …

Nov 13, 2025
CVE-2025-64525
6.5 MEDIUM

Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request headers `x-forwarded-proto` and `x-forwarded-port` are insecurely used, …

Nov 13, 2025
CVE-2025-60689
5.4 MEDIUM

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because …

Nov 13, 2025
CVE-2025-60688
6.5 MEDIUM

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads …

Nov 13, 2025
CVE-2025-60687
6.5 MEDIUM

An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter …

Nov 13, 2025
CVE-2025-60686
5.1 MEDIUM

A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs …

Nov 13, 2025
CVE-2025-60685
5.1 MEDIUM

A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using …

Nov 13, 2025
CVE-2025-60684
6.5 MEDIUM

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface …

Nov 13, 2025
CVE-2025-60683
6.5 MEDIUM

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface …

Nov 13, 2025
CVE-2025-60682
6.5 MEDIUM

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update …

Nov 13, 2025
CVE-2025-52186
6.5 MEDIUM

Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed directly to …

Nov 13, 2025
CVE-2025-13120
5.3 MEDIUM

A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use …

Nov 13, 2025
CVE-2025-64739
4.3 MEDIUM

External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.

Nov 13, 2025
CVE-2025-64738
5.0 MEDIUM

External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of …

Nov 13, 2025
CVE-2025-62483
5.3 MEDIUM

Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network …

Nov 13, 2025
CVE-2025-62482
4.3 MEDIUM

Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact integrity via network access.

Nov 13, 2025
CVE-2025-30669
4.8 MEDIUM

Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via adjacent access.

Nov 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.