CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10746
6.5 MEDIUM

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to …

Oct 4, 2025
CVE-2025-61685
6.5 MEDIUM

Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vulnerable to a Directory Traversal attack that results in …

Oct 3, 2025
CVE-2025-61681
5.4 MEDIUM

KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its file upload functionality that can be exploited …

Oct 3, 2025
CVE-2025-43825
6.5 MEDIUM

A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through …

Oct 3, 2025
CVE-2025-10696
5.4 MEDIUM

OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor …

Oct 3, 2025
CVE-2025-10695
5.3 MEDIUM

Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for …

Oct 3, 2025
CVE-2025-59829
6.5 MEDIUM

Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied …

Oct 3, 2025
CVE-2025-53354
6.1 MEDIUM

NiceGUI is a Python-based UI framework. Versions 2.24.2 and below are at risk for Cross-Site Scripting (XSS) when developers render unescaped user input into the …

Oct 3, 2025
CVE-2025-54154
6.8 MEDIUM

An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise …

Oct 3, 2025
CVE-2025-53407
6.5 MEDIUM

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, …

Oct 3, 2025
CVE-2025-53406
6.5 MEDIUM

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, …

Oct 3, 2025
CVE-2025-52867
6.5 MEDIUM

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-52866
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52862
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52860
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52859
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52858
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52857
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52855
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52854
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52853
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52654
4.6 MEDIUM

HCL MyXalytics v6.6 is affected by an HTML Injection. This issue occurs when untrusted input is included in the output without proper handling, potentially allowing …

Oct 3, 2025
CVE-2025-52433
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52432
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52429
6.5 MEDIUM

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, …

Oct 3, 2025
CVE-2025-52428
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52427
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-52424
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-48730
6.5 MEDIUM

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, …

Oct 3, 2025
CVE-2025-48729
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-48728
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-48727
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-48726
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-47214
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-47213
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Oct 3, 2025
CVE-2025-47211
4.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Oct 3, 2025
CVE-2025-47210
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-46819
6.3 MEDIUM

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LUA …

Oct 3, 2025
CVE-2025-46818
6.0 MEDIUM

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua …

Oct 3, 2025
CVE-2025-44012
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-44011
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44010
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44009
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44008
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Oct 3, 2025
CVE-2025-44007
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-44006
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-33040
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-33039
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Oct 3, 2025
CVE-2025-33034
6.5 MEDIUM

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Oct 3, 2025
CVE-2021-42193
6.1 MEDIUM

nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload …

Oct 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.