CVE Database

52314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62414
6.9 MEDIUM

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting …

Oct 16, 2025
CVE-2025-61514
6.5 MEDIUM

An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.

Oct 16, 2025
CVE-2025-60855
5.1 MEDIUM

Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution …

Oct 16, 2025
CVE-2025-34255
5.3 MEDIUM

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether …

Oct 16, 2025
CVE-2025-34254
5.3 MEDIUM

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the …

Oct 16, 2025
CVE-2025-34253
5.4 MEDIUM

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the …

Oct 16, 2025
CVE-2025-11853
6.3 MEDIUM

A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Executing …

Oct 16, 2025
CVE-2025-11852
5.3 MEDIUM

A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the component ONVIF Service. Performing …

Oct 16, 2025
CVE-2025-62413
6.1 MEDIUM

MQTTX is an MQTT 5.0 desktop client and MQTT testing tool. A Cross-Site Scripting (XSS) vulnerability was introduced in MQTTX v1.12.0 due to improper handling …

Oct 16, 2025
CVE-2025-62411
5.5 MEDIUM

LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When …

Oct 16, 2025
CVE-2025-62407
6.1 MEDIUM

Frappe is a full-stack web application framework. Prior to 14.98.0 and 15.83.0, an open redirect was possible through the redirect argument on the login page, …

Oct 16, 2025
CVE-2025-61923
4.1 MEDIUM

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on …

Oct 16, 2025
CVE-2025-61909
4.4 MEDIUM

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) …

Oct 16, 2025
CVE-2025-61908
6.5 MEDIUM

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference …

Oct 16, 2025
CVE-2025-61907
6.5 MEDIUM

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access …

Oct 16, 2025
CVE-2025-61330
6.5 MEDIUM

A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment manufacturer H3C. The vulnerability stems from the use of …

Oct 16, 2025
CVE-2025-60641
6.5 MEDIUM

The file mexcel.php in the Vfront 0.99.52 codebase contains a vulnerable call to unserialize(base64_decode($_POST['mexcel'])), where $_POST['mexcel'] is user-controlled input. This input is decoded from base64 …

Oct 16, 2025
CVE-2025-60639
6.5 MEDIUM

Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).

Oct 16, 2025
CVE-2025-34512
6.1 MEDIUM

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary …

Oct 16, 2025
CVE-2025-61789
5.3 MEDIUM

Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use …

Oct 16, 2025
CVE-2025-58051
6.5 MEDIUM

Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able …

Oct 16, 2025
CVE-2025-56700
5.4 MEDIUM

Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged user …

Oct 16, 2025
CVE-2025-56699
5.4 MEDIUM

SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary …

Oct 16, 2025
CVE-2025-53092
6.5 MEDIUM

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi …

Oct 16, 2025
CVE-2025-25298
5.3 MEDIUM

Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password …

Oct 16, 2025
CVE-2025-9559
6.5 MEDIUM

Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be …

Oct 16, 2025
CVE-2025-62493
6.5 MEDIUM

A vulnerability exists in the QuickJS engine's BigInt string conversion logic (js_bigint_to_string1) due to an incorrect calculation of the required number of digits, which in …

Oct 16, 2025
CVE-2025-62492
6.5 MEDIUM

A vulnerability stemming from floating-point arithmetic precision errors exists in the QuickJS engine's implementation of TypedArray.prototype.indexOf() when a negative fromIndex argument is supplied. * The …

Oct 16, 2025
CVE-2025-55035
6.1 MEDIUM

Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication …

Oct 16, 2025
CVE-2025-11842
6.3 MEDIUM

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handler. The …

Oct 16, 2025
CVE-2025-61540
6.5 MEDIUM

SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.

Oct 16, 2025
CVE-2025-61539
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.

Oct 16, 2025
CVE-2025-41254
4.3 MEDIUM

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: …

Oct 16, 2025
CVE-2025-36002
5.5 MEDIUM

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5, and 6.2.1.0 stores user credentials in configuration files …

Oct 16, 2025
CVE-2025-53951
5.3 MEDIUM

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for Windows 11.5.1 and 11.4.2 …

Oct 16, 2025
CVE-2025-53950
5.5 MEDIUM

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 …

Oct 16, 2025
CVE-2025-46752
4.4 MEDIUM

A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the …

Oct 16, 2025
CVE-2025-9955
5.7 MEDIUM

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP admin services related to system logs …

Oct 16, 2025
CVE-2025-58426
4.3 MEDIUM

desknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applications.

Oct 16, 2025
CVE-2025-58079
4.3 MEDIUM

Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSuite applications.

Oct 16, 2025
CVE-2025-55072
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V2.0R1.0 to V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-54859
4.8 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-54760
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-52583
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-24833
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0–V9.0R2.0 allow execution of arbitrary JavaScript in a user’s web browser.

Oct 16, 2025
CVE-2025-58115
6.1 MEDIUM

ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be executed on the web browser of the user …

Oct 16, 2025
CVE-2025-54461
5.3 MEDIUM

ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited, an uninvited guest user may register itself as a …

Oct 16, 2025
CVE-2025-53858
5.4 MEDIUM

ChatLuck contains a cross-site scripting vulnerability in Chat Rooms. If exploited, an arbitrary script may be executed on the web browser of the user who …

Oct 16, 2025
CVE-2025-41410
5.4 MEDIUM

Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create …

Oct 16, 2025
CVE-2025-0277
6.5 MEDIUM

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing …

Oct 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.