CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11413
3.3 LOW

A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in …

Oct 7, 2025
CVE-2025-11412
3.3 LOW

A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads …

Oct 7, 2025
CVE-2025-62187
2.9 LOW

In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames …

Oct 7, 2025
CVE-2025-43910
2.3 LOW

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions …

Oct 7, 2025
CVE-2025-61670
3.3 LOW

Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` …

Oct 7, 2025
CVE-2025-43909
3.7 LOW

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions …

Oct 7, 2025
CVE-2022-50522
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount …

Oct 7, 2025
CVE-2025-59451
3.5 LOW

The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.

Oct 6, 2025
CVE-2025-59447
2.2 LOW

The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can leverage this interface to read a …

Oct 6, 2025
CVE-2025-61985
3.6 LOW

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

Oct 6, 2025
CVE-2025-61984
3.6 LOW

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand …

Oct 6, 2025
CVE-2025-11333
2.4 LOW

A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This impacts an unknown function of the file /customer_add_action.php of the component Add …

Oct 6, 2025
CVE-2025-11332
3.5 LOW

A vulnerability was determined in CmsEasy up to 7.7.7. This affects an unknown function in the library lib/inc/view.php of the component URL Handler. Executing a …

Oct 6, 2025
CVE-2025-58589
2.7 LOW

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as …

Oct 6, 2025
CVE-2025-58578
3.8 LOW

A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, …

Oct 6, 2025
CVE-2025-11322
3.7 LOW

A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component …

Oct 6, 2025
CVE-2025-11308
3.5 LOW

A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file /api-addons/v1/messages. Such manipulation of the argument Message …

Oct 5, 2025
CVE-2025-11289
2.4 LOW

A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the file src/main/java/com/zhiliao/common/template/TemplateFileServiceImpl.java of the component Template …

Oct 5, 2025
CVE-2025-11283
2.4 LOW

A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can …

Oct 5, 2025
CVE-2025-11282
2.4 LOW

A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Performing a manipulation results …

Oct 5, 2025
CVE-2025-11280
3.7 LOW

A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This …

Oct 5, 2025
CVE-2025-11276
3.5 LOW

A security flaw has been discovered in Rebuild up to 4.1.3. Affected by this issue is some unknown functionality of the component Comment/Guestbook. Performing manipulation …

Oct 5, 2025
CVE-2025-11274
3.3 LOW

A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of …

Oct 5, 2025
CVE-2025-61677
2.5 LOW

DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and below allow for deseriaization of untrusted data because of the …

Oct 3, 2025
CVE-2025-52658
3.5 LOW

HCL MyXalytics is affected by the use of vulnerable/outdated versions which can expose the application to known security risks that could be exploited.

Oct 3, 2025
CVE-2025-10306
3.8 LOW

The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via …

Oct 3, 2025
CVE-2025-54089
3.4 LOW

CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another …

Oct 2, 2025
CVE-2025-54087
2.6 LOW

CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request …

Oct 2, 2025
CVE-2025-54086
3.3 LOW

CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file …

Oct 2, 2025
CVE-2025-58769
3.3 LOW

auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications built with the …

Oct 1, 2025
CVE-2025-59682
3.1 LOW

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and …

Oct 1, 2025
CVE-2025-58054
3.5 LOW

Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of chat channel titles and …

Oct 1, 2025
CVE-2025-43718
2.9 LOW

Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF …

Oct 1, 2025
CVE-2023-50301
1.9 LOW

IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user.

Oct 1, 2025
CVE-2025-56675
3.5 LOW

The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information such as the Wi-Fi SSID and password.

Sep 30, 2025
CVE-2025-23291
2.4 LOW

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A successful exploit of this vulnerability …

Sep 30, 2025
CVE-2025-11195
3.3 LOW

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration …

Sep 30, 2025
CVE-2025-35032
3.4 LOW

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue …

Sep 29, 2025
CVE-2025-35031
3.3 LOW

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to …

Sep 29, 2025
CVE-2025-55795
3.5 LOW

The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user …

Sep 29, 2025
CVE-2025-11137
3.5 LOW

A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File Renaming Handler. The manipulation leads …

Sep 29, 2025
CVE-2025-11134
2.4 LOW

A security vulnerability has been detected in Cudy TR1200 1.16.3-20230804-164635. Impacted is an unknown function of the file /cgi-bin/luci/admin/network/wireless/config/ of the component Wireless Settings Page. …

Sep 29, 2025
CVE-2025-11124
3.5 LOW

A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument …

Sep 28, 2025
CVE-2025-11081
3.3 LOW

A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The …

Sep 27, 2025
CVE-2025-11069
2.4 LOW

A vulnerability was determined in westboy CicadasCMS 1.0. Affected by this issue is some unknown functionality of the file /system/org/save of the component Add Department …

Sep 27, 2025
CVE-2025-11068
2.4 LOW

A vulnerability was found in westboy CicadasCMS 1.0. Affected by this vulnerability is an unknown functionality of the file /system/cms/category/save. The manipulation of the argument …

Sep 27, 2025
CVE-2025-11067
2.4 LOW

A vulnerability has been found in Projectworlds Visitor Management System 1.0. Affected is an unknown function of the file /myform.php of the component Add Visitor …

Sep 27, 2025
CVE-2025-36144
3.3 LOW

IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.

Sep 27, 2025
CVE-2025-11027
2.4 LOW

A vulnerability was identified in givanz Vvveb up to 1.0.7.2. Affected by this issue is some unknown functionality of the component SVG File Handler. Such …

Sep 26, 2025
CVE-2025-36326
3.7 LOW

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of …

Sep 26, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.