CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2020-36854
6.4 MEDIUM

The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization …

Oct 18, 2025
CVE-2025-62651
6.5 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.

Oct 17, 2025
CVE-2025-62649
5.8 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for submission of equipment orders.

Oct 17, 2025
CVE-2025-62648
6.4 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.

Oct 17, 2025
CVE-2025-62647
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to …

Oct 17, 2025
CVE-2025-62646
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to review the stored audio of conversations between associates and Drive Thru customers.

Oct 17, 2025
CVE-2025-62644
5.0 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global Store Directory that shares personal information among authenticated users.

Oct 17, 2025
CVE-2025-62642
5.8 MEDIUM

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has an "Anyone Can Join This Party" signup API that does not verify user account creation, …

Oct 17, 2025
CVE-2025-62508
6.5 MEDIUM

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in …

Oct 17, 2025
CVE-2025-11914
4.3 MEDIUM

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function Download of the file /DeviceFileReport.do?Action=Download. Performing manipulation …

Oct 17, 2025
CVE-2025-62511
6.3 MEDIUM

yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-367) in …

Oct 17, 2025
CVE-2025-11925
6.1 MEDIUM

Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through …

Oct 17, 2025
CVE-2025-11913
4.3 MEDIUM

A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is the function Download of the file /Service.do?Action=Download. Such …

Oct 17, 2025
CVE-2025-11912
6.3 MEDIUM

A flaw has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected is the function Query of the file /DeviceState.do?Action=Query. This manipulation of the …

Oct 17, 2025
CVE-2025-11911
6.3 MEDIUM

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This impacts the function Query of the file /DeviceFault.do?Action=Query. The manipulation of the argument …

Oct 17, 2025
CVE-2025-11910
6.3 MEDIUM

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. This affects the function Query of the file /MemoryState.do?Action=Query. The manipulation of …

Oct 17, 2025
CVE-2025-56320
5.4 MEDIUM

Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary …

Oct 17, 2025
CVE-2025-34281
5.4 MEDIUM

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting …

Oct 17, 2025
CVE-2025-11909
6.3 MEDIUM

A weakness has been identified in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The impacted element is the function queryLast of the file /RepairRecord.do?Action=QueryLast. Executing manipulation …

Oct 17, 2025
CVE-2025-11908
6.3 MEDIUM

A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing …

Oct 17, 2025
CVE-2024-31573
4.0 MEDIUM

XMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transformation), because XSLT extension …

Oct 17, 2025
CVE-2025-62430
5.4 MEDIUM

ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site scripting (XSS) in multiple video and photo …

Oct 17, 2025
CVE-2025-62424
6.7 MEDIUM

ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of …

Oct 17, 2025
CVE-2025-62421
5.4 MEDIUM

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scripting vulnerability exists due to improper file upload validation …

Oct 17, 2025
CVE-2025-60514
6.5 MEDIUM

Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts.

Oct 17, 2025
CVE-2025-57164
6.5 MEDIUM

Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.

Oct 17, 2025
CVE-2025-62171
5.9 MEDIUM

ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer …

Oct 17, 2025
CVE-2025-58747
6.1 MEDIUM

Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects …

Oct 17, 2025
CVE-2025-11905
6.3 MEDIUM

A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the function getArticle of the file app\modules\cms\controller\gather.js. The manipulation results in code …

Oct 17, 2025
CVE-2025-48087
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from …

Oct 17, 2025
CVE-2025-11904
6.3 MEDIUM

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument …

Oct 17, 2025
CVE-2025-60360
5.5 MEDIUM

radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.

Oct 17, 2025
CVE-2025-60359
5.5 MEDIUM

radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.

Oct 17, 2025
CVE-2025-11903
6.3 MEDIUM

A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing a …

Oct 17, 2025
CVE-2025-11902
6.3 MEDIUM

A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/findField. Performing a manipulation …

Oct 17, 2025
CVE-2025-11895
4.3 MEDIUM

The Binary MLM Plan plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 5.0. This is due to …

Oct 17, 2025
CVE-2025-55099
6.1 MEDIUM

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing …

Oct 17, 2025
CVE-2025-55098
6.1 MEDIUM

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_device_type_get() when parsing …

Oct 17, 2025
CVE-2025-55097
6.1 MEDIUM

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_streaming_sampling_get() when parsing …

Oct 17, 2025
CVE-2025-55096
6.1 MEDIUM

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_hid_report_descriptor_get() when parsing …

Oct 17, 2025
CVE-2025-55093
5.3 MEDIUM

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when …

Oct 17, 2025
CVE-2025-55092
5.3 MEDIUM

In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in …

Oct 17, 2025
CVE-2025-62504
6.5 MEDIUM

Envoy is an open source edge and service proxy. Envoy versions earlier than 1.36.2, 1.35.6, 1.34.10, and 1.33.12 contain a use-after-free vulnerability in the Lua …

Oct 16, 2025
CVE-2024-42192
5.5 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.

Oct 16, 2025
CVE-2025-61554
5.5 MEDIUM

A divide-by-zero in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial of …

Oct 16, 2025
CVE-2025-60358
5.5 MEDIUM

radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

Oct 16, 2025
CVE-2025-62423
6.7 MEDIUM

ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admin Area’s …

Oct 16, 2025
CVE-2025-62418
6.9 MEDIUM

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to …

Oct 16, 2025
CVE-2025-62416
5.1 MEDIUM

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by …

Oct 16, 2025
CVE-2025-62415
6.9 MEDIUM

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to …

Oct 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.