CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12231
2.4 LOW

A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense …

Oct 27, 2025
CVE-2025-12230
2.4 LOW

A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. …

Oct 27, 2025
CVE-2025-12229
2.4 LOW

A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles …

Oct 27, 2025
CVE-2025-12228
2.4 LOW

A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown function of the file /public/admin/users/create of the component Users …

Oct 27, 2025
CVE-2025-12227
3.5 LOW

A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.php. Executing a manipulation …

Oct 27, 2025
CVE-2025-12224
3.5 LOW

A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerability affects unknown code of the file admin/contact.php. This manipulation of the argument …

Oct 27, 2025
CVE-2025-12207
3.3 LOW

A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation …

Oct 27, 2025
CVE-2025-12206
3.3 LOW

A flaw has been found in Kamailio 5.5. The impacted element is the function rve_is_constant of the file src/core/rvalue.c. This manipulation causes null pointer dereference. …

Oct 27, 2025
CVE-2025-6601
2.7 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have …

Oct 27, 2025
CVE-2025-11989
3.7 LOW

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have …

Oct 27, 2025
CVE-2025-11888
2.7 LOW

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an …

Oct 25, 2025
CVE-2025-11244
3.7 LOW

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is …

Oct 25, 2025
CVE-2025-62711
3.1 LOW

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug …

Oct 24, 2025
CVE-2025-10723
2.7 LOW

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to …

Oct 24, 2025
CVE-2025-41721
2.7 LOW

A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralization of special elements when adding a password …

Oct 22, 2025
CVE-2025-62774
3.1 LOW

On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.

Oct 22, 2025
CVE-2025-62773
2.4 LOW

Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.

Oct 22, 2025
CVE-2025-62772
3.1 LOW

On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.

Oct 22, 2025
CVE-2025-62480
2.7 LOW

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable …

Oct 21, 2025
CVE-2025-62479
2.7 LOW

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable …

Oct 21, 2025
CVE-2025-61755
3.7 LOW

Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.16 …

Oct 21, 2025
CVE-2025-61749
2.7 LOW

Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having …

Oct 21, 2025
CVE-2025-61748
3.7 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Oct 21, 2025
CVE-2025-53051
2.7 LOW

Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker …

Oct 21, 2025
CVE-2022-4981
3.3 LOW

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The …

Oct 21, 2025
CVE-2025-5496
3.3 LOW

ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.

Oct 21, 2025
CVE-2025-57837
2.9 LOW

Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Oct 20, 2025
CVE-2025-11946
3.5 LOW

A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp of the …

Oct 19, 2025
CVE-2025-11945
3.5 LOW

A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the component Avatar Upload Image Endpoint. Such manipulation leads …

Oct 19, 2025
CVE-2025-62643
3.4 LOW

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.

Oct 17, 2025
CVE-2025-62505
3.0 LOW

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. …

Oct 17, 2025
CVE-2025-60361
3.3 LOW

radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

Oct 17, 2025
CVE-2025-62412
3.8 LOW

LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can …

Oct 16, 2025
CVE-2025-61924
3.8 LOW

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking …

Oct 16, 2025
CVE-2025-11851
3.5 LOW

A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set_alias.cgi. Such manipulation of the argument …

Oct 16, 2025
CVE-2025-11840
3.3 LOW

A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead …

Oct 16, 2025
CVE-2025-11839
3.3 LOW

A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked …

Oct 16, 2025
CVE-2025-54499
3.1 LOW

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to …

Oct 16, 2025
CVE-2025-10545
3.1 LOW

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add …

Oct 16, 2025
CVE-2025-62379
3.1 LOW

Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace endpoint automatically assigns the redirect_to query …

Oct 15, 2025
CVE-2025-2529
2.9 LOW

Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in …

Oct 15, 2025
CVE-2025-6026
3.1 LOW

An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to …

Oct 15, 2025
CVE-2025-56746
2.2 LOW

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user …

Oct 15, 2025
CVE-2025-59294
2.1 LOW

Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.

Oct 14, 2025
CVE-2025-59284
3.3 LOW

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

Oct 14, 2025
CVE-2025-59280
3.1 LOW

Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.

Oct 14, 2025
CVE-2025-58903
2.7 LOW

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null …

Oct 14, 2025
CVE-2025-47890
2.6 LOW

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 …

Oct 14, 2025
CVE-2025-31514
2.7 LOW

An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS 7.6.0 through 7.6.3, 7.4 all versions, 7.2 all versions, 7.0 all versions, 6.4 …

Oct 14, 2025
CVE-2025-40773
3.5 LOW

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks …

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.