CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11374
6.5 MEDIUM

Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is …

Oct 28, 2025
CVE-2025-62367
4.8 MEDIUM

Taiga is an open source project management platform. In versions 6.8.3 and earlier, Taiga API is vulnerable to time-based blind SQL injection allowing sensitive data …

Oct 28, 2025
CVE-2025-27093
6.3 MEDIUM

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack …

Oct 28, 2025
CVE-2025-40843
5.9 MEDIUM

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a …

Oct 28, 2025
CVE-2025-61080
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Clear2Pay Bank Visibility Application - Payment Execution 1.10.0.104 via the ID parameter in the URL.

Oct 28, 2025
CVE-2025-61155
5.5 MEDIUM

The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A user-mode process can open a …

Oct 28, 2025
CVE-2025-36085
5.4 MEDIUM

IBM Concert 1.0.0 through 2.0.0 Software is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Oct 28, 2025
CVE-2025-36083
6.2 MEDIUM

IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before …

Oct 28, 2025
CVE-2025-36081
5.3 MEDIUM

IBM Concert Software 1.0.0 through 2.0.0 could allow a user to modify system logs due to improper neutralization of log input.

Oct 28, 2025
CVE-2025-34317
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34316
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34315
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34314
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34313
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34310
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34309
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34308
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34307
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34306
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34305
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain multiple stored cross-site scripting (XSS) vulnerabilities caused by a bug in the cleanhtml() function (/var/ipfire/header.pl) that …

Oct 28, 2025
CVE-2025-34304
6.5 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL query used when …

Oct 28, 2025
CVE-2025-34303
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34302
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-34301
5.4 MEDIUM

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code …

Oct 28, 2025
CVE-2025-12390
6.0 MEDIUM

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device …

Oct 28, 2025
CVE-2025-12103
5.0 MEDIUM

A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to …

Oct 28, 2025
CVE-2025-40040
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/ksm: fix flag-dropping behavior in ksm_madvise syzkaller discovered the following crash: (kernel BUG) [ 44.607039] …

Oct 28, 2025
CVE-2025-40039
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access The 'sess->rpc_handle_list' XArray manages RPC handles …

Oct 28, 2025
CVE-2025-55758
5.4 MEDIUM

Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.

Oct 28, 2025
CVE-2025-12347
6.3 MEDIUM

A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the …

Oct 28, 2025
CVE-2025-12346
6.3 MEDIUM

A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. …

Oct 28, 2025
CVE-2025-12344
6.3 MEDIUM

A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /service/NCloudGatewayServlet of the …

Oct 28, 2025
CVE-2025-33133
6.5 MEDIUM

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to …

Oct 28, 2025
CVE-2025-33132
6.5 MEDIUM

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to …

Oct 28, 2025
CVE-2025-33131
6.5 MEDIUM

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to …

Oct 28, 2025
CVE-2025-33126
6.5 MEDIUM

IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, …

Oct 28, 2025
CVE-2025-12335
4.3 MEDIUM

A vulnerability was determined in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_update.php. This manipulation of the …

Oct 28, 2025
CVE-2025-62259
5.4 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, …

Oct 27, 2025
CVE-2025-62258
6.5 MEDIUM

CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through …

Oct 27, 2025
CVE-2025-12334
4.3 MEDIUM

A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument prod_name/prod_desc/prod_cost results …

Oct 27, 2025
CVE-2025-12333
4.3 MEDIUM

A vulnerability has been found in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/supplier_add.php. The manipulation of the argument supp_name/supp_address …

Oct 27, 2025
CVE-2025-62793
6.8 MEDIUM

eLabFTW is an open source electronic lab notebook for research labs. The application served uploaded SVG files inline. Because SVG supports active content, an attacker …

Oct 27, 2025
CVE-2025-62781
5.0 MEDIUM

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged …

Oct 27, 2025
CVE-2025-62779
5.4 MEDIUM

Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML through …

Oct 27, 2025
CVE-2025-62778
5.3 MEDIUM

Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the …

Oct 27, 2025
CVE-2025-62261
6.5 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, …

Oct 27, 2025
CVE-2025-12331
4.7 MEDIUM

A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unrestricted upload. …

Oct 27, 2025
CVE-2025-12329
6.3 MEDIUM

A security flaw has been discovered in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. The affected element is an unknown function of the file /details.php. Performing …

Oct 27, 2025
CVE-2025-12328
6.3 MEDIUM

A vulnerability was identified in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. Impacted is an unknown function of the file /contestproblem.php. Such manipulation of the argument …

Oct 27, 2025
CVE-2025-62784
5.3 MEDIUM

InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the …

Oct 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.