CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64773
2.7 LOW

In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

Nov 11, 2025
CVE-2025-13015
3.4 LOW

Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.

Nov 11, 2025
CVE-2025-8998
3.1 LOW

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw …

Nov 11, 2025
CVE-2025-42883
2.7 LOW

Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrative privileges uploads files …

Nov 11, 2025
CVE-2025-62780
3.5 LOW

changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in changedetection.io Watch update API in versions …

Nov 10, 2025
CVE-2025-64682
2.7 LOW

In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit

Nov 10, 2025
CVE-2025-64681
2.7 LOW

In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

Nov 10, 2025
CVE-2025-12923
2.7 LOW

A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipulation of the argument …

Nov 10, 2025
CVE-2025-12920
2.4 LOW

A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation …

Nov 9, 2025
CVE-2025-12919
3.7 LOW

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation …

Nov 9, 2025
CVE-2025-12918
3.1 LOW

A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file …

Nov 9, 2025
CVE-2025-12854
3.7 LOW

A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill of the file /seckillExecution/. The manipulation of the argument userid …

Nov 7, 2025
CVE-2025-48985
3.7 LOW

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists …

Nov 7, 2025
CVE-2025-11219
3.1 LOW

Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a …

Nov 6, 2025
CVE-2025-64326
2.6 LOW

Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to …

Nov 6, 2025
CVE-2025-21077
3.3 LOW

Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity with Samsung Email privilege.

Nov 5, 2025
CVE-2025-43442
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app …

Nov 4, 2025
CVE-2025-43423
2.0 LOW

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS …

Nov 4, 2025
CVE-2025-43408
2.4 LOW

This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe …

Nov 4, 2025
CVE-2025-43395
3.3 LOW

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app …

Nov 4, 2025
CVE-2025-43365
2.8 LOW

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26 and iPadOS 26. An …

Nov 4, 2025
CVE-2025-43350
2.4 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view …

Nov 4, 2025
CVE-2025-43309
2.4 LOW

A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical access to an …

Nov 4, 2025
CVE-2025-12623
3.1 LOW

A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this issue is some unknown functionality of the file fuint-application/src/main/java/com/fuint/module/clientApi/controller/ClientSignController.java of the component …

Nov 3, 2025
CVE-2025-12616
3.7 LOW

A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in …

Nov 3, 2025
CVE-2025-12547
3.7 LOW

A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of the file /login.jsp of the component Admin Login …

Oct 31, 2025
CVE-2025-12546
3.5 LOW

A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This manipulation …

Oct 31, 2025
CVE-2025-36249
3.7 LOW

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to …

Oct 31, 2025
CVE-2025-64352
2.7 LOW

Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from …

Oct 31, 2025
CVE-2025-64350
3.8 LOW

Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from …

Oct 31, 2025
CVE-2025-23050
3.1 LOW

QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, …

Oct 31, 2025
CVE-2025-10636
3.5 LOW

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users …

Oct 30, 2025
CVE-2025-10931
3.8 LOW

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analytics allows Cross-Site Scripting (XSS).This issue affects Umami Analytics: from 0.0.0 …

Oct 30, 2025
CVE-2025-11203
3.5 LOW

LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LiteLLM. Authentication is required to …

Oct 29, 2025
CVE-2025-56558
3.0 LOW

The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, and …

Oct 29, 2025
CVE-2025-62794
3.8 LOW

GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token …

Oct 28, 2025
CVE-2025-10939
3.7 LOW

A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a …

Oct 28, 2025
CVE-2025-12332
2.4 LOW

A flaw has been found in SourceCodester Student Grades Management System 1.0. This affects the function delete_user of the file /admin.php. Executing manipulation can lead …

Oct 28, 2025
CVE-2025-12330
2.4 LOW

A security flaw has been discovered in Willow CMS up to 1.4.0. This issue affects some unknown processing of the file /admin/articles/add of the component …

Oct 27, 2025
CVE-2025-12312
2.4 LOW

A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the …

Oct 27, 2025
CVE-2025-12311
2.4 LOW

A vulnerability was detected in PHPGurukul Curfew e-Pass Management System 1.0. This issue affects some unknown processing of the file edit-category-detail.php. The manipulation of the …

Oct 27, 2025
CVE-2025-12303
2.4 LOW

A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of the file admin-profile.php. Executing a …

Oct 27, 2025
CVE-2025-12282
2.4 LOW

A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function of the file /admin/manage-users.php. The manipulation leads to …

Oct 27, 2025
CVE-2025-12281
2.4 LOW

A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executing manipulation can lead to cross …

Oct 27, 2025
CVE-2025-12280
2.4 LOW

A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Performing manipulation results in cross …

Oct 27, 2025
CVE-2025-12279
2.4 LOW

A vulnerability has been found in code-projects Client Details System 1.0. This vulnerability affects unknown code of the file /welcome.php. Such manipulation leads to cross …

Oct 27, 2025
CVE-2025-11248
3.2 LOW

ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could …

Oct 27, 2025
CVE-2025-12269
3.5 LOW

A vulnerability was found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The affected element is an unknown function of the file /dash/org/settings/previews of the component Account Setting …

Oct 27, 2025
CVE-2025-12264
3.5 LOW

A security flaw has been discovered in Wisencode up to 20251012. Affected by this vulnerability is an unknown functionality of the file /support-ticket/create of the …

Oct 27, 2025
CVE-2025-12251
3.5 LOW

A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI. The manipulation leads to cross …

Oct 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.