CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64517
4.4 MEDIUM

sudo-rs is a memory safe implementation of sudo and su written in Rust. With `Defaults targetpw` (or `Defaults rootpw`) enabled, the password of the target …

Nov 12, 2025
CVE-2025-64503
4.0 MEDIUM

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In cups-filters prior to …

Nov 12, 2025
CVE-2025-64482
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition …

Nov 12, 2025
CVE-2025-64429
6.5 MEDIUM

DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting with DuckDB 1.4.0. There are a few issues …

Nov 12, 2025
CVE-2025-63645
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application's message system. Unsanitized message content submitted by one user is persisted …

Nov 12, 2025
CVE-2025-33119
6.5 MEDIUM

IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.

Nov 12, 2025
CVE-2025-36223
5.4 MEDIUM

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an …

Nov 12, 2025
CVE-2025-13061
6.3 MEDIUM

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Performing manipulation results in unrestricted upload. …

Nov 12, 2025
CVE-2025-8421
6.6 MEDIUM

An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect …

Nov 12, 2025
CVE-2025-64117
4.6 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1761813675 and Tuleap Enterprise Edition …

Nov 12, 2025
CVE-2025-27368
4.3 MEDIUM

IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points …

Nov 12, 2025
CVE-2025-13059
6.3 MEDIUM

A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career.php. This manipulation of …

Nov 12, 2025
CVE-2025-12047
5.3 MEDIUM

A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under certain circumstances, could allow an attacker on the …

Nov 12, 2025
CVE-2024-48829
6.7 MEDIUM

Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A high privileged attacker with local …

Nov 12, 2025
CVE-2025-63927
4.0 MEDIUM

A heap-use-after-free vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). During multi-threaded client execution, the function Iec10x_Scheduled can access memory that has already been …

Nov 12, 2025
CVE-2025-60646
6.1 MEDIUM

A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitrary web scripts or HTML via injecting a …

Nov 12, 2025
CVE-2025-13057
6.3 MEDIUM

A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_student. The manipulation of the …

Nov 12, 2025
CVE-2024-45301
5.3 MEDIUM

Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access …

Nov 12, 2025
CVE-2025-60645
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.

Nov 12, 2025
CVE-2025-25236
5.3 MEDIUM

Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and …

Nov 12, 2025
CVE-2025-63419
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to …

Nov 12, 2025
CVE-2025-59491
6.1 MEDIUM

Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.

Nov 12, 2025
CVE-2025-59089
5.9 MEDIUM

If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact that kdcproxy does …

Nov 12, 2025
CVE-2025-52331
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the computer username, generated …

Nov 12, 2025
CVE-2025-40164
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible code warnings Syzbot reported the following warning: BUG: using …

Nov 12, 2025
CVE-2025-11454
6.5 MEDIUM

The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable to SQL Injection via the eos_scfm_duplicate_post_as_draft() function in …

Nov 12, 2025
CVE-2025-64407
5.3 MEDIUM

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links …

Nov 12, 2025
CVE-2025-61623
6.5 MEDIUM

Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the …

Nov 12, 2025
CVE-2025-37734
4.3 MEDIUM

Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

Nov 12, 2025
CVE-2025-64406
4.3 MEDIUM

An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash the program, or otherwise corrupt other memory …

Nov 12, 2025
CVE-2025-64402
6.5 MEDIUM

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links …

Nov 12, 2025
CVE-2025-12732
4.3 MEDIUM

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing …

Nov 12, 2025
CVE-2025-12872
5.4 MEDIUM

The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to upload files containing malicious JavaScript code, which …

Nov 12, 2025
CVE-2025-12869
4.8 MEDIUM

The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administrator privileges to inject persistent JavaScript codes that are executed …

Nov 12, 2025
CVE-2025-12113
4.3 MEDIUM

The Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images plugin for WordPress is vulnerable to unauthorized loss of data …

Nov 12, 2025
CVE-2025-12018
4.4 MEDIUM

The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Nov 12, 2025
CVE-2025-12901
4.3 MEDIUM

The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing …

Nov 12, 2025
CVE-2025-12833
4.3 MEDIUM

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up …

Nov 12, 2025
CVE-2025-12087
4.3 MEDIUM

The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Nov 12, 2025
CVE-2025-54983
5.2 MEDIUM

A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released …

Nov 12, 2025
CVE-2025-43205
4.0 MEDIUM

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, …

Nov 12, 2025
CVE-2025-40817
6.5 MEDIUM

A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All …

Nov 11, 2025
CVE-2025-40760
5.5 MEDIUM

A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly handle error messages and discloses sensitive password …

Nov 11, 2025
CVE-2024-32014
4.7 MEDIUM

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alter the local …

Nov 11, 2025
CVE-2025-12748
5.5 MEDIUM

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL …

Nov 11, 2025
CVE-2025-61845
5.5 MEDIUM

Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability …

Nov 11, 2025
CVE-2025-61844
5.5 MEDIUM

Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability …

Nov 11, 2025
CVE-2025-61843
5.5 MEDIUM

Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability …

Nov 11, 2025
CVE-2025-61842
5.5 MEDIUM

Format Plugins versions 1.1.1 and earlier are affected by a Use After Free vulnerability that could lead to memory exposure. An attacker could leverage this …

Nov 11, 2025
CVE-2025-61841
5.5 MEDIUM

Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability …

Nov 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.