CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30188
7.5 HIGH

Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate …

Oct 31, 2025
CVE-2025-10897
8.6 HIGH

The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible …

Oct 31, 2025
CVE-2025-7846
8.8 HIGH

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in …

Oct 31, 2025
CVE-2025-54763
7.2 HIGH

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web …

Oct 31, 2025
CVE-2025-8849
7.5 HIGH

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` …

Oct 31, 2025
CVE-2025-6176
7.5 HIGH

Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection …

Oct 31, 2025
CVE-2025-52664
8.8 HIGH

SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users

Oct 31, 2025
CVE-2025-52663
7.3 HIGH

A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to …

Oct 31, 2025
CVE-2025-48984
8.8 HIGH

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

Oct 31, 2025
CVE-2025-48982
7.8 HIGH

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

Oct 31, 2025
CVE-2025-34298
8.8 HIGH

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to …

Oct 30, 2025
CVE-2025-34287
7.8 HIGH

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because …

Oct 30, 2025
CVE-2025-34286
7.2 HIGH

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters …

Oct 30, 2025
CVE-2025-34284
8.8 HIGH

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to …

Oct 30, 2025
CVE-2025-34280
7.2 HIGH

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate …

Oct 30, 2025
CVE-2025-34134
7.2 HIGH

Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled …

Oct 30, 2025
CVE-2024-58273
7.8 HIGH

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web …

Oct 30, 2025
CVE-2024-14009
7.2 HIGH

Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/configuration capability. …

Oct 30, 2025
CVE-2024-14008
7.2 HIGH

Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of user-supplied input allows an authenticated …

Oct 30, 2025
CVE-2024-14005
8.8 HIGH

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an …

Oct 30, 2025
CVE-2024-14004
8.8 HIGH

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data …

Oct 30, 2025
CVE-2024-13995
8.8 HIGH

Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated …

Oct 30, 2025
CVE-2023-7322
8.1 HIGH

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API …

Oct 30, 2025
CVE-2023-7317
8.8 HIGH

Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact …

Oct 30, 2025
CVE-2021-47700
7.8 HIGH

Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes …

Oct 30, 2025
CVE-2021-47693
8.8 HIGH

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulnerability in the search …

Oct 30, 2025
CVE-2020-36869
7.2 HIGH

Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitation requires an account with administrative privileges …

Oct 30, 2025
CVE-2020-36868
7.8 HIGH

Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using …

Oct 30, 2025
CVE-2020-36867
8.8 HIGH

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline …

Oct 30, 2025
CVE-2020-36863
8.8 HIGH

Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler …

Oct 30, 2025
CVE-2020-36859
8.8 HIGH

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the object …

Oct 30, 2025
CVE-2020-36857
7.2 HIGH

Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative privileges …

Oct 30, 2025
CVE-2020-36856
8.8 HIGH

Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` parameter allows …

Oct 30, 2025
CVE-2018-25123
7.8 HIGH

Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, allowing a local …

Oct 30, 2025
CVE-2018-25122
8.8 HIGH

Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with …

Oct 30, 2025
CVE-2016-15050
8.8 HIGH

Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters were incorporated into SQL statements without …

Oct 30, 2025
CVE-2013-10073
8.8 HIGH

Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate …

Oct 30, 2025
CVE-2011-10035
7.0 HIGH

Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions …

Oct 30, 2025
CVE-2025-8850
8.8 HIGH

In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA without …

Oct 30, 2025
CVE-2025-63423
7.5 HIGH

Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password.

Oct 30, 2025
CVE-2025-61498
7.5 HIGH

A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Oct 30, 2025
CVE-2025-61141
7.5 HIGH

sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environment variable and config file path to …

Oct 30, 2025
CVE-2025-3356
8.6 HIGH

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a …

Oct 30, 2025
CVE-2025-3355
7.5 HIGH

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a …

Oct 30, 2025
CVE-2025-63422
7.5 HIGH

Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username …

Oct 30, 2025
CVE-2025-63298
8.2 HIGH

A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage …

Oct 30, 2025
CVE-2025-36137
7.2 HIGH

IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks …

Oct 30, 2025
CVE-2025-64112
8.0 HIGH

Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions …

Oct 30, 2025
CVE-2025-64096
8.8 HIGH

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the …

Oct 30, 2025
CVE-2025-62795
7.1 HIGH

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privileged authenticated user can …

Oct 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.