CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11580
5.3 MEDIUM

A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The …

Oct 10, 2025
CVE-2025-61780
5.8 MEDIUM

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running …

Oct 10, 2025
CVE-2025-60308
4.1 MEDIUM

code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room function of the online hotel reservation system. …

Oct 10, 2025
CVE-2025-8887
6.1 MEDIUM

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Forceful …

Oct 10, 2025
CVE-2025-8886
6.7 MEDIUM

Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect Authorization vulnerability in Usta Information Systems Inc. Aybs …

Oct 10, 2025
CVE-2025-61319
6.1 MEDIUM

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the …

Oct 10, 2025
CVE-2025-61152
6.5 MEDIUM

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious actor can craft a forged …

Oct 10, 2025
CVE-2025-60868
6.5 MEDIUM

The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded …

Oct 10, 2025
CVE-2025-62239
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 …

Oct 10, 2025
CVE-2025-62238
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 …

Oct 10, 2025
CVE-2025-62237
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, …

Oct 10, 2025
CVE-2025-7781
6.4 MEDIUM

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘cs_job_title’ parameter in all versions up …

Oct 10, 2025
CVE-2025-7374
5.4 MEDIUM

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. This …

Oct 10, 2025
CVE-2025-11579
5.3 MEDIUM

github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR …

Oct 10, 2025
CVE-2025-52624
5.4 MEDIUM

A vulnerability Bypass of the script allowlist configuration in HCL AION. An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk …

Oct 10, 2025
CVE-2025-11190
5.4 MEDIUM

The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.

Oct 10, 2025
CVE-2025-52632
6.5 MEDIUM

A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

Oct 10, 2025
CVE-2025-37727
5.7 MEDIUM

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API …

Oct 10, 2025
CVE-2025-40640
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS due to lack of proper validation of …

Oct 10, 2025
CVE-2025-62292
4.3 MEDIUM

In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, …

Oct 10, 2025
CVE-2025-21070
4.0 MEDIUM

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-21069
4.0 MEDIUM

Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21068
4.0 MEDIUM

Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21067
4.0 MEDIUM

Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21066
4.0 MEDIUM

Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21065
6.6 MEDIUM

Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

Oct 10, 2025
CVE-2025-21063
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording …

Oct 10, 2025
CVE-2025-21060
5.5 MEDIUM

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required …

Oct 10, 2025
CVE-2025-21059
6.2 MEDIUM

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

Oct 10, 2025
CVE-2025-21057
4.0 MEDIUM

Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

Oct 10, 2025
CVE-2025-21055
4.3 MEDIUM

Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21054
4.0 MEDIUM

Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

Oct 10, 2025
CVE-2025-21053
4.0 MEDIUM

Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

Oct 10, 2025
CVE-2025-21052
4.0 MEDIUM

Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory …

Oct 10, 2025
CVE-2025-21051
4.0 MEDIUM

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-21049
5.5 MEDIUM

Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this …

Oct 10, 2025
CVE-2025-21048
6.7 MEDIUM

Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.

Oct 10, 2025
CVE-2025-21047
5.2 MEDIUM

Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

Oct 10, 2025
CVE-2025-21045
4.0 MEDIUM

Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.

Oct 10, 2025
CVE-2025-21044
5.7 MEDIUM

Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

Oct 10, 2025
CVE-2025-10124
4.5 MEDIUM

The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode available to anyone with contributor and above privileges. …

Oct 10, 2025
CVE-2025-61871
6.7 MEDIUM

NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root …

Oct 10, 2025
CVE-2025-11570
4.6 MEDIUM

Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data. **Note:** This is exploitable only if …

Oct 10, 2025
CVE-2025-62240
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update …

Oct 9, 2025
CVE-2025-43296
5.5 MEDIUM

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

Oct 9, 2025
CVE-2025-35062
5.3 MEDIUM

Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.

Oct 9, 2025
CVE-2025-35061
5.9 MEDIUM

Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can …

Oct 9, 2025
CVE-2025-35060
5.5 MEDIUM

Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or …

Oct 9, 2025
CVE-2025-35059
4.3 MEDIUM

Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.

Oct 9, 2025
CVE-2025-35058
5.9 MEDIUM

Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can …

Oct 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.