CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-42884
6.5 MEDIUM

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to …

Nov 11, 2025
CVE-2025-42882
4.3 MEDIUM

Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module …

Nov 11, 2025
CVE-2025-31719
5.1 MEDIUM

In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature results with low probability.

Nov 11, 2025
CVE-2025-64529
6.5 MEDIUM

SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator …

Nov 10, 2025
CVE-2025-64504
5.0 MEDIUM

Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2.95.11 and 3.124.1, in certain project membership …

Nov 10, 2025
CVE-2025-63397
6.5 MEDIUM

Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.

Nov 10, 2025
CVE-2025-63617
6.5 MEDIUM

ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.

Nov 10, 2025
CVE-2025-63296
6.5 MEDIUM

KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: during startup /usr/sbin/anyka_service.sh scans mounted …

Nov 10, 2025
CVE-2025-48878
4.3 MEDIUM

Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct object reference allows …

Nov 10, 2025
CVE-2025-63384
6.5 MEDIUM

A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege …

Nov 10, 2025
CVE-2025-60876
6.5 MEDIUM

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be …

Nov 10, 2025
CVE-2025-56503
6.5 MEDIUM

An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator via replacing the …

Nov 10, 2025
CVE-2025-33150
5.3 MEDIUM

IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages.

Nov 10, 2025
CVE-2025-12729
4.2 MEDIUM

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI …

Nov 10, 2025
CVE-2025-12728
4.2 MEDIUM

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI …

Nov 10, 2025
CVE-2025-12447
4.2 MEDIUM

Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific …

Nov 10, 2025
CVE-2025-12446
4.2 MEDIUM

Incorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Nov 10, 2025
CVE-2025-12445
6.5 MEDIUM

Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin …

Nov 10, 2025
CVE-2025-12444
4.2 MEDIUM

Incorrect security UI in Fullscreen UI in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI …

Nov 10, 2025
CVE-2025-12443
4.3 MEDIUM

Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via …

Nov 10, 2025
CVE-2025-12441
4.3 MEDIUM

Out of bounds read in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via …

Nov 10, 2025
CVE-2025-12440
5.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Nov 10, 2025
CVE-2025-12439
5.5 MEDIUM

Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory …

Nov 10, 2025
CVE-2025-12436
5.9 MEDIUM

Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obtain potentially …

Nov 10, 2025
CVE-2025-12435
5.4 MEDIUM

Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML …

Nov 10, 2025
CVE-2025-12434
4.2 MEDIUM

Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Nov 10, 2025
CVE-2025-12433
4.3 MEDIUM

Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Nov 10, 2025
CVE-2025-12431
6.5 MEDIUM

Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation …

Nov 10, 2025
CVE-2025-43723
5.9 MEDIUM

Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated …

Nov 10, 2025
CVE-2025-43079
6.3 MEDIUM

The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute …

Nov 10, 2025
CVE-2025-63834
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the ssid parameter of the wireless settings. Remote attackers …

Nov 10, 2025
CVE-2025-63710
6.5 MEDIUM

The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms …

Nov 10, 2025
CVE-2025-63709
5.4 MEDIUM

A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text input. An authenticated user can submit HTML/JavaScript …

Nov 10, 2025
CVE-2025-64684
4.3 MEDIUM

In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

Nov 10, 2025
CVE-2025-64683
5.3 MEDIUM

In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

Nov 10, 2025
CVE-2025-64457
4.2 MEDIUM

In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

Nov 10, 2025
CVE-2025-12939
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file …

Nov 10, 2025
CVE-2025-41001
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user input …

Nov 10, 2025
CVE-2025-41107
5.4 MEDIUM

Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to …

Nov 10, 2025
CVE-2025-12933
6.3 MEDIUM

A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument roleid …

Nov 10, 2025
CVE-2025-12932
4.7 MEDIUM

A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of …

Nov 10, 2025
CVE-2025-12931
6.3 MEDIUM

A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of …

Nov 10, 2025
CVE-2025-12930
6.3 MEDIUM

A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument …

Nov 10, 2025
CVE-2025-12927
4.7 MEDIUM

A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of …

Nov 10, 2025
CVE-2025-12926
6.3 MEDIUM

A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function of the file /review.php. This manipulation of …

Nov 10, 2025
CVE-2025-12924
4.3 MEDIUM

A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing …

Nov 10, 2025
CVE-2025-12922
6.3 MEDIUM

A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data …

Nov 10, 2025
CVE-2025-12921
4.3 MEDIUM

A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknown functionality of the file /ImportCRFData?action=confirm of …

Nov 10, 2025
CVE-2025-12917
4.3 MEDIUM

A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file /reqproc/proc_post of the component Reboot Handler. …

Nov 9, 2025
CVE-2025-12916
6.3 MEDIUM

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component …

Nov 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.