CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-58755
8.8 HIGH

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compressed files. …

Sep 9, 2025
CVE-2025-10113
7.3 HIGH

A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of …

Sep 9, 2025
CVE-2025-10112
7.3 HIGH

A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation …

Sep 9, 2025
CVE-2025-58454
8.2 HIGH

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior inthe endpoint /WeGIA/html/memorando/listar_despachos.php, in the …

Sep 8, 2025
CVE-2025-58453
8.2 HIGH

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior in the endpoint /WeGIA/html/memorando/exibe_anexo.php, in …

Sep 8, 2025
CVE-2025-10111
7.3 HIGH

A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The …

Sep 8, 2025
CVE-2025-10109
7.3 HIGH

A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the …

Sep 8, 2025
CVE-2025-57817
7.2 HIGH

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not …

Sep 8, 2025
CVE-2025-57816
7.5 HIGH

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, …

Sep 8, 2025
CVE-2025-10108
7.3 HIGH

A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument …

Sep 8, 2025
CVE-2025-52288
7.5 HIGH

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) component, in Open5GS thru 2.7.5 allowing attackers to cause a …

Sep 8, 2025
CVE-2025-52389
8.8 HIGH

An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other users via …

Sep 8, 2025
CVE-2025-10104
7.3 HIGH

A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /review_search.php. The manipulation of …

Sep 8, 2025
CVE-2025-9112
8.8 HIGH

The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure_temp_file_uploader' function in all versions up …

Sep 8, 2025
CVE-2025-55849
8.4 HIGH

WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee

Sep 8, 2025
CVE-2025-10103
7.3 HIGH

A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /home.php. Executing manipulation of the …

Sep 8, 2025
CVE-2025-10102
7.3 HIGH

A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function of the file /index.php. Performing manipulation of …

Sep 8, 2025
CVE-2025-56265
8.8 HIGH

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a …

Sep 8, 2025
CVE-2025-10100
7.3 HIGH

A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of the file /admin_class.php?action=login. Performing manipulation of the argument …

Sep 8, 2025
CVE-2025-59033
7.4 HIGH

The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the …

Sep 8, 2025
CVE-2025-56630
7.3 HIGH

FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.

Sep 8, 2025
CVE-2025-55998
8.1 HIGH

A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web …

Sep 8, 2025
CVE-2025-40930
7.5 HIGH

JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other …

Sep 8, 2025
CVE-2025-40928
7.5 HIGH

JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact

Sep 8, 2025
CVE-2022-50238
7.4 HIGH

The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended driver block rules. Some entries present on the online list …

Sep 8, 2025
CVE-2025-36855
8.8 HIGH

A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product …

Sep 8, 2025
CVE-2025-36854
8.1 HIGH

A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a …

Sep 8, 2025
CVE-2025-36853
7.5 HIGH

A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer …

Sep 8, 2025
CVE-2025-10092
7.3 HIGH

A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The …

Sep 8, 2025
CVE-2025-10091
7.3 HIGH

A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. …

Sep 8, 2025
CVE-2025-10090
7.3 HIGH

A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.departments/GetTreeDate.aspx. Executing manipulation of …

Sep 8, 2025
CVE-2025-41708
7.4 HIGH

Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit …

Sep 8, 2025
CVE-2025-41682
8.8 HIGH

An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.

Sep 8, 2025
CVE-2025-41664
7.5 HIGH

A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the runtime of …

Sep 8, 2025
CVE-2025-8085
8.6 HIGH

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

Sep 8, 2025
CVE-2025-10082
7.3 HIGH

A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument …

Sep 8, 2025
CVE-2025-10079
7.3 HIGH

A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of …

Sep 8, 2025
CVE-2025-10078
7.3 HIGH

A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID …

Sep 8, 2025
CVE-2025-10077
7.3 HIGH

A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the …

Sep 8, 2025
CVE-2025-10076
7.3 HIGH

A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argument …

Sep 8, 2025
CVE-2025-39730
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() The function needs to check the minimal filehandle …

Sep 7, 2025
CVE-2025-39727
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: swap: fix potential buffer overflow in setup_clusters() In setup_swap_map(), we only ensure badpages are …

Sep 7, 2025
CVE-2025-10068
7.3 HIGH

A flaw has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/admin_forum/add_views.php. Executing manipulation of the argument …

Sep 7, 2025
CVE-2025-10062
7.3 HIGH

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument …

Sep 6, 2025
CVE-2025-58445
7.5 HIGH

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through …

Sep 6, 2025
CVE-2025-58446
7.5 HIGH

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes large grammars (>100k characters) at very …

Sep 6, 2025
CVE-2025-0032
7.2 HIGH

Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss …

Sep 6, 2025
CVE-2024-36354
7.5 HIGH

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant …

Sep 6, 2025
CVE-2024-36352
8.4 HIGH

Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial …

Sep 6, 2025
CVE-2024-36342
8.8 HIGH

Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execution.

Sep 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.