CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8594
3.8 LOW

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as …

Oct 14, 2025
CVE-2025-11731
3.1 LOW

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function …

Oct 14, 2025
CVE-2025-42909
3.0 LOW

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances …

Oct 14, 2025
CVE-2025-62178
3.5 LOW

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a Reflected Cross-Site Scripting (XSS) vulnerability …

Oct 13, 2025
CVE-2025-62174
3.5 LOW

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator resets a user account's …

Oct 13, 2025
CVE-2025-58084
3.5 LOW

Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has …

Oct 13, 2025
CVE-2025-39964
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg …

Oct 13, 2025
CVE-2025-31995
3.5 LOW

HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS, or command injection, leading …

Oct 13, 2025
CVE-2025-11650
1.8 LOW

A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file /etc/shadow of the component …

Oct 12, 2025
CVE-2025-11647
3.1 LOW

A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component GATT Service. This manipulation …

Oct 12, 2025
CVE-2025-11645
2.4 LOW

A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication …

Oct 12, 2025
CVE-2025-11644
2.0 LOW

A weakness has been identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is some unknown functionality of the component UART Interface. …

Oct 12, 2025
CVE-2025-11643
3.7 LOW

A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. Affected by this vulnerability is an unknown functionality of the file /squashfs-root/furbo_img …

Oct 12, 2025
CVE-2025-11641
3.9 LOW

A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This manipulation causes …

Oct 12, 2025
CVE-2025-11640
3.1 LOW

A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function of the component Bluetooth Low Energy. The manipulation results …

Oct 12, 2025
CVE-2025-11639
3.3 LOW

A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. The impacted element is an unknown function of the file collect_logs.sh of the …

Oct 12, 2025
CVE-2025-2139
3.5 LOW

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due …

Oct 12, 2025
CVE-2025-2138
3.5 LOW

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due …

Oct 12, 2025
CVE-2025-11634
2.4 LOW

A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. This affects an unknown part of the component UART Interface. The manipulation …

Oct 12, 2025
CVE-2025-11633
3.7 LOW

A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_to_s3 of the file collect_logs.sh of the …

Oct 12, 2025
CVE-2025-52615
3.5 LOW

HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by …

Oct 12, 2025
CVE-2025-52614
3.5 LOW

HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding …

Oct 12, 2025
CVE-2025-31998
3.5 LOW

HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. An attacker can exploit use this information to exploit known …

Oct 12, 2025
CVE-2025-31993
3.5 LOW

HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can exploit improper input validation by submitting maliciously crafted …

Oct 12, 2025
CVE-2025-11609
3.7 LOW

A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument …

Oct 11, 2025
CVE-2025-8606
2.4 LOW

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due …

Oct 11, 2025
CVE-2025-58292
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58291
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58290
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58286
3.3 LOW

Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58282
2.8 LOW

Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-52635
3.7 LOW

A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-52625
3.7 LOW

A vulnerability Cacheable SSL Page Found vulnerability has been identified in HCL AION. Cached data may expose credentials, system identifiers, or internal file paths to …

Oct 10, 2025
CVE-2025-52634
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

Oct 10, 2025
CVE-2025-52630
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-52655
3.1 LOW

Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code …

Oct 10, 2025
CVE-2025-21046
2.4 LOW

Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.

Oct 10, 2025
CVE-2025-4614
2.7 LOW

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web …

Oct 9, 2025
CVE-2025-11495
3.3 LOW

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation …

Oct 8, 2025
CVE-2025-11494
3.3 LOW

A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in …

Oct 8, 2025
CVE-2025-11485
2.4 LOW

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user of the file /admin.php of the component Manage Users …

Oct 8, 2025
CVE-2025-11443
3.7 LOW

A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forgotten Password …

Oct 8, 2025
CVE-2025-11441
3.7 LOW

A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the component HTTP Header Handler. The manipulation …

Oct 8, 2025
CVE-2025-11437
2.4 LOW

A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the component Form Editor. …

Oct 8, 2025
CVE-2025-11433
3.5 LOW

A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/controller.php?action=reset of the component Query …

Oct 8, 2025
CVE-2025-11425
2.4 LOW

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /edit_admin.php. The manipulation of the argument …

Oct 8, 2025
CVE-2025-11421
3.5 LOW

A flaw has been found in code-projects Voting System 1.0. The affected element is an unknown function of the file /admin/candidates_edit.php. This manipulation of the …

Oct 8, 2025
CVE-2025-61786
3.3 LOW

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.stat` and `Deno.FsFile.prototype.statSync` are not limited by the permission model …

Oct 8, 2025
CVE-2025-61785
3.3 LOW

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In versions prior to 2.5.3 and 2.2.15, `Deno.FsFile.prototype.utime` and `Deno.FsFile.prototype.utimeSync` are not limited by the permission model …

Oct 8, 2025
CVE-2025-11414
3.3 LOW

A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This …

Oct 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.