CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10282
4.7 MEDIUM

BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.

Oct 9, 2025
CVE-2025-10281
4.7 MEDIUM

BBOT's git_clone module could be abused to disclose a GitHub API key to an attacker controlled server with a malicious formatted git URL.

Oct 9, 2025
CVE-2025-39664
6.5 MEDIUM

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file …

Oct 9, 2025
CVE-2025-32916
4.3 MEDIUM

Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to …

Oct 9, 2025
CVE-2025-36225
4.3 MEDIUM

IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.

Oct 9, 2025
CVE-2025-36171
4.9 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive …

Oct 9, 2025
CVE-2023-37401
5.3 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.

Oct 9, 2025
CVE-2025-39961
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase page table level The AMD IOMMU host page table …

Oct 9, 2025
CVE-2025-9371
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versions up to, and including, 28.1.6 due to …

Oct 9, 2025
CVE-2025-2934
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 …

Oct 9, 2025
CVE-2025-10249
6.5 MEDIUM

The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in …

Oct 9, 2025
CVE-2025-39959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp: Fix incorrect retrival of acp_chip_info Use dev_get_drvdata(dev->parent) instead of dev_get_platdata(dev) to correctly …

Oct 9, 2025
CVE-2025-39956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error When igc_led_setup() fails, igc_probe() fails and triggers …

Oct 9, 2025
CVE-2025-39954
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: sunxi-ng: mp: Fix dual-divider clock rate readback When dual-divider clock support was introduced, the …

Oct 9, 2025
CVE-2025-27049
5.5 MEDIUM

Transient DOS while processing IOCTL call for image encoding.

Oct 9, 2025
CVE-2025-27045
6.1 MEDIUM

Information disclosure while processing batch command execution in Video driver.

Oct 9, 2025
CVE-2025-27041
5.5 MEDIUM

Transient DOS while processing video packets received from video firmware.

Oct 9, 2025
CVE-2025-27040
6.5 MEDIUM

Information disclosure may occur while processing the hypervisor log.

Oct 9, 2025
CVE-2025-27039
6.6 MEDIUM

Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.

Oct 9, 2025
CVE-2025-11530
6.3 MEDIUM

A weakness has been identified in code-projects Online Complaint Site 1.0. Affected is an unknown function of the file /cms/admin/state.php. This manipulation of the argument …

Oct 9, 2025
CVE-2025-11523
6.3 MEDIUM

A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in …

Oct 9, 2025
CVE-2025-11166
5.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, …

Oct 9, 2025
CVE-2025-11516
6.3 MEDIUM

A weakness has been identified in code-projects Online Complaint Site 1.0. Impacted is an unknown function of the file /cms/users/complaint-details.php. Executing manipulation of the argument …

Oct 9, 2025
CVE-2025-11515
6.3 MEDIUM

A security flaw has been discovered in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/users/register-complaint.php. Performing manipulation of …

Oct 9, 2025
CVE-2025-11514
6.3 MEDIUM

A vulnerability was identified in code-projects Online Complaint Site 1.0. This vulnerability affects unknown code of the file /cms/users/index.php. Such manipulation of the argument Username …

Oct 9, 2025
CVE-2025-11512
4.3 MEDIUM

A vulnerability was found in code-projects Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/voters_add.php. The manipulation of the …

Oct 9, 2025
CVE-2025-11511
6.3 MEDIUM

A flaw has been found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/supplier_add.php. Executing manipulation of the argument supp_email …

Oct 8, 2025
CVE-2025-11509
6.3 MEDIUM

A vulnerability was detected in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/product_add.php. Performing manipulation of the argument prod_name results …

Oct 8, 2025
CVE-2025-11508
4.7 MEDIUM

A security vulnerability has been detected in code-projects Voting System 1.0. This affects an unknown function of the file /admin/voters_add.php. Such manipulation of the argument …

Oct 8, 2025
CVE-2025-11491
6.3 MEDIUM

A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in …

Oct 8, 2025
CVE-2025-11490
6.3 MEDIUM

A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component …

Oct 8, 2025
CVE-2025-61906
4.3 MEDIUM

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, in some situations, …

Oct 8, 2025
CVE-2025-61788
5.4 MEDIUM

Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 17.8 and 18.2, the paella would …

Oct 8, 2025
CVE-2025-42706
6.5 MEDIUM

A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, …

Oct 8, 2025
CVE-2025-42701
5.6 MEDIUM

A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, …

Oct 8, 2025
CVE-2025-11489
4.5 MEDIUM

A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem.ts. The manipulation leads …

Oct 8, 2025
CVE-2025-11487
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Farm Management System 1.0. Affected by this issue is some unknown functionality of the file /uploadProduct.php. Performing …

Oct 8, 2025
CVE-2025-11486
6.3 MEDIUM

A vulnerability was identified in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /buyNow.php. Such manipulation of …

Oct 8, 2025
CVE-2025-11481
6.3 MEDIUM

A flaw has been found in varunsardana004 Blood-Bank-And-Donation-Management-System up to dc9e0393d826fbc85fad9755b5bc12cba1919df2. The impacted element is an unknown function of the file /donate_blood.php. Executing manipulation of …

Oct 8, 2025
CVE-2025-60318
6.1 MEDIUM

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields.

Oct 8, 2025
CVE-2025-59303
6.4 MEDIUM

HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in …

Oct 8, 2025
CVE-2025-36636
4.3 MEDIUM

In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized …

Oct 8, 2025
CVE-2025-60834
6.5 MEDIUM

A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input.

Oct 8, 2025
CVE-2025-60313
6.1 MEDIUM

Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field. This allows a remote attacker …

Oct 8, 2025
CVE-2025-43771
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 …

Oct 8, 2025
CVE-2025-43724
4.4 MEDIUM

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerability. A high privileged attacker with local access could potentially exploit …

Oct 8, 2025
CVE-2025-61183
6.1 MEDIUM

Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the storeAvatar() method of UserBase.php

Oct 8, 2025
CVE-2025-60833
6.5 MEDIUM

An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data.

Oct 8, 2025
CVE-2025-60830
6.5 MEDIUM

redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.

Oct 8, 2025
CVE-2025-60828
6.5 MEDIUM

WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine interface.

Oct 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.