CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-20724
5.5 MEDIUM

In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Oct 14, 2025
CVE-2025-20722
5.5 MEDIUM

In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a …

Oct 14, 2025
CVE-2025-55078
5.5 MEDIUM

In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory …

Oct 14, 2025
CVE-2025-41707
5.3 MEDIUM

The websocket handler is vulnerable to a denial of service condition. An unauthenticated remote attacker can send a crafted websocket message to trigger the issue …

Oct 14, 2025
CVE-2025-41706
5.3 MEDIUM

The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET request with an over-long content-length to …

Oct 14, 2025
CVE-2025-41705
6.8 MEDIUM

An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.

Oct 14, 2025
CVE-2025-41704
5.3 MEDIUM

An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the core functionality.

Oct 14, 2025
CVE-2025-10732
4.3 MEDIUM

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and …

Oct 14, 2025
CVE-2025-10357
6.1 MEDIUM

The Simple SEO WordPress plugin before 2.0.32 does not sanitise and escape some parameters when outputing them in the page, which could allow users with …

Oct 14, 2025
CVE-2025-42939
4.3 MEDIUM

SAP S/4HANA (Manage Processing Rules - For Bank Statements) allows an authenticated attacker with basic privileges to delete conditions from any shared rule of any …

Oct 14, 2025
CVE-2025-42908
5.4 MEDIUM

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session …

Oct 14, 2025
CVE-2025-42906
5.3 MEDIUM

SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the …

Oct 14, 2025
CVE-2025-42903
4.3 MEDIUM

A vulnerability in SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS allows user enumeration and potential disclosure of personal data through response discrepancies, causing low …

Oct 14, 2025
CVE-2025-42902
5.3 MEDIUM

Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or …

Oct 14, 2025
CVE-2025-42901
5.4 MEDIUM

SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the …

Oct 14, 2025
CVE-2025-62392
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62391
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62390
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62389
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62388
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62387
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62386
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62385
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62384
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62383
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62365
6.1 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper …

Oct 13, 2025
CVE-2025-62361
6.1 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open Redirect vulnerability was identified …

Oct 13, 2025
CVE-2025-62359
6.1 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, a Reflected Cross-Site Scripting (XSS) vulnerability …

Oct 13, 2025
CVE-2025-62358
5.4 MEDIUM

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, the log parameter in configuracao_geral.php is …

Oct 13, 2025
CVE-2025-62251
6.5 MEDIUM

Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 …

Oct 13, 2025
CVE-2025-11623
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Oct 13, 2025
CVE-2025-62364
6.2 MEDIUM

text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerability exists in the character picture …

Oct 13, 2025
CVE-2025-62252
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, …

Oct 13, 2025
CVE-2025-62246
5.4 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, …

Oct 13, 2025
CVE-2025-62176
4.3 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, the streaming server accepts serving events for …

Oct 13, 2025
CVE-2025-62175
4.3 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does …

Oct 13, 2025
CVE-2025-59836
5.3 MEDIUM

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in …

Oct 13, 2025
CVE-2025-62242
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and …

Oct 13, 2025
CVE-2025-62241
4.3 MEDIUM

Insecure Direct Object Reference (IDOR) vulnerability with shipment addresses in Liferay DXP 2023.Q4.1 through 2023.Q4.5 allows remote authenticated users to from one virtual instance to …

Oct 13, 2025
CVE-2025-62243
5.4 MEDIUM

Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 …

Oct 13, 2025
CVE-2025-62244
4.3 MEDIUM

Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 …

Oct 13, 2025
CVE-2025-43991
6.3 MEDIUM

SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. …

Oct 13, 2025
CVE-2025-39965
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but …

Oct 13, 2025
CVE-2025-10720
6.5 MEDIUM

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only …

Oct 13, 2025
CVE-2025-11674
6.8 MEDIUM

SOOP-CLM developed by PiExtract has a Server-Side Request Forgery vulnerability, allowing privileged remote attackers to read server files or probe internal network information.

Oct 13, 2025
CVE-2025-11672
5.3 MEDIUM

Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain user group names.

Oct 13, 2025
CVE-2025-11671
5.3 MEDIUM

Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain information such as …

Oct 13, 2025
CVE-2025-11668
4.7 MEDIUM

A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/update_user.php. This manipulation of …

Oct 13, 2025
CVE-2025-11667
6.3 MEDIUM

A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_candidate_modal.php.. The manipulation of …

Oct 13, 2025
CVE-2025-27259
5.4 MEDIUM

Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites …

Oct 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.