CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-0607
4.3 MEDIUM

Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing.This issue affects Logo Cloud: before 2.57.

Oct 6, 2025
CVE-2025-0606
6.0 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing, Resource Leak Exposure.This issue affects Logo Cloud: before 0.67.

Oct 6, 2025
CVE-2025-9914
4.3 MEDIUM

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to …

Oct 6, 2025
CVE-2025-9913
4.5 MEDIUM

JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

Oct 6, 2025
CVE-2025-58591
6.5 MEDIUM

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive …

Oct 6, 2025
CVE-2025-58590
6.5 MEDIUM

It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.

Oct 6, 2025
CVE-2025-58587
6.5 MEDIUM

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to …

Oct 6, 2025
CVE-2025-58586
5.3 MEDIUM

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. …

Oct 6, 2025
CVE-2025-58585
5.3 MEDIUM

Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.

Oct 6, 2025
CVE-2025-58584
5.3 MEDIUM

In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such …

Oct 6, 2025
CVE-2025-58583
5.3 MEDIUM

The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

Oct 6, 2025
CVE-2025-58582
5.3 MEDIUM

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated …

Oct 6, 2025
CVE-2025-58581
4.3 MEDIUM

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as …

Oct 6, 2025
CVE-2025-58580
6.5 MEDIUM

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated …

Oct 6, 2025
CVE-2025-58579
5.3 MEDIUM

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user …

Oct 6, 2025
CVE-2025-9710
6.3 MEDIUM

The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality …

Oct 6, 2025
CVE-2025-9703
4.3 MEDIUM

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the …

Oct 6, 2025
CVE-2025-11321
4.3 MEDIUM

A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performing manipulation of the …

Oct 6, 2025
CVE-2025-11320
6.3 MEDIUM

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the …

Oct 6, 2025
CVE-2025-11319
6.3 MEDIUM

A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16e87b965024097. This issue affects some unknown processing of the file /delete.php. This manipulation of the …

Oct 6, 2025
CVE-2025-11306
4.3 MEDIUM

A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The …

Oct 5, 2025
CVE-2025-11304
6.3 MEDIUM

A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown functionality of the component API. Executing …

Oct 5, 2025
CVE-2025-11303
6.3 MEDIUM

A vulnerability was detected in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/mp. Performing a manipulation of the argument command results …

Oct 5, 2025
CVE-2025-11298
6.3 MEDIUM

A vulnerability was determined in Belkin F9K1015 1.00.10. Impacted is an unknown function of the file /goform/formSetWanStatic. Executing a manipulation of the argument m_wan_ipaddr can …

Oct 5, 2025
CVE-2025-11292
6.3 MEDIUM

A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetSitesurvey. Executing a manipulation of the argument wan_ipaddr …

Oct 5, 2025
CVE-2025-11291
4.3 MEDIUM

A security flaw has been discovered in ixmaps website2017 up to 0c71cffa0162186bc057a76766bc97e9f5a3a2d0. This impacts an unknown function of the file /map.php of the component HTTP …

Oct 5, 2025
CVE-2025-11290
5.6 MEDIUM

A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the …

Oct 5, 2025
CVE-2025-8917
5.8 MEDIUM

A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extract` function. This flaw …

Oct 5, 2025
CVE-2025-11288
6.3 MEDIUM

A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET …

Oct 5, 2025
CVE-2025-11286
4.7 MEDIUM

A vulnerability was determined in samanhappy MCPHub up to 0.9.10. This affects an unknown part of the file src/controllers/serverController.ts of the component MCPRouter Service. This …

Oct 5, 2025
CVE-2025-11285
6.3 MEDIUM

A vulnerability was found in samanhappy MCPHub up to 0.9.10. Affected by this issue is some unknown functionality of the file src/controllers/serverController.ts. The manipulation of …

Oct 5, 2025
CVE-2025-11281
5.0 MEDIUM

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course …

Oct 5, 2025
CVE-2025-11279
5.5 MEDIUM

A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing of the component Add Work Item Page. The …

Oct 5, 2025
CVE-2025-11278
4.3 MEDIUM

A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of the component AllMon2. The manipulation leads to …

Oct 5, 2025
CVE-2025-11277
5.3 MEDIUM

A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can …

Oct 5, 2025
CVE-2025-11275
5.3 MEDIUM

A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation …

Oct 5, 2025
CVE-2025-11273
6.3 MEDIUM

A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oauth/provider.ts. The manipulation of the argument URL …

Oct 4, 2025
CVE-2025-11272
5.4 MEDIUM

A vulnerability has been found in SeriaWei ZKEACMS up to 4.3. This affects the function Delete of the file src/ZKEACMS.Redirection/Controllers/UrlRedirectionController.cs of the component POST Request …

Oct 4, 2025
CVE-2023-53615
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix deletion race condition System crash when using debug kernel due to link …

Oct 4, 2025
CVE-2023-53614
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/ksm: fix race with VMA iteration and mm_struct teardown exit_mmap() will tear down the VMAs …

Oct 4, 2025
CVE-2023-53612
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Simplify platform device handling Coretemp's platform driver is unconventional. All the real work …

Oct 4, 2025
CVE-2023-53611
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmi_si: fix a memleak in try_smi_init() Kmemleak reported the following leak info in try_smi_init(): unreferenced …

Oct 4, 2025
CVE-2023-53610
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: irqchip: Fix refcount leak in platform_irqchip_probe of_irq_find_parent() returns a node pointer with refcount incremented, We …

Oct 4, 2025
CVE-2023-53609
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: core: Do not increase scsi_device's iorequest_cnt if dispatch failed" The "atomic_inc(&cmd->device->iorequest_cnt)" in …

Oct 4, 2025
CVE-2023-53607
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: Fix BUG_ON in probe function The snd_dma_buffer.bytes field now contains the aligned size, …

Oct 4, 2025
CVE-2023-53606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: clean up potential nfsd_file refcount leaks in COPY codepath There are two different flavors …

Oct 4, 2025
CVE-2023-53605
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm: amd: display: Fix memory leakage This commit fixes memory leakage in dc_construct_ctx() function.

Oct 4, 2025
CVE-2023-53603
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid fcport pointer dereference Klocwork reported warning of NULL pointer may be dereferenced. …

Oct 4, 2025
CVE-2023-53602
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix memory leak in WMI firmware stats Memory allocated for firmware pdev, vdev …

Oct 4, 2025
CVE-2023-53601
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bonding: do not assume skb mac_header is set Drivers must not assume in their ndo_start_xmit() …

Oct 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.