CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-34220
5.3 MEDIUM

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contains a /api-gateway/identity/search-groups endpoint that does …

Sep 29, 2025
CVE-2025-34211
4.9 MEDIUM

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA and SaaS deployments) contain a private SSL …

Sep 29, 2025
CVE-2025-56764
5.3 MEDIUM

Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), …

Sep 29, 2025
CVE-2025-35034
4.3 MEDIUM

Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL …

Sep 29, 2025
CVE-2025-35033
4.1 MEDIUM

Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue …

Sep 29, 2025
CVE-2025-57879
6.1 MEDIUM

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL …

Sep 29, 2025
CVE-2025-57878
6.1 MEDIUM

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL …

Sep 29, 2025
CVE-2025-57877
4.8 MEDIUM

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative …

Sep 29, 2025
CVE-2025-57876
4.8 MEDIUM

There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, authenticated attacker to inject malicious …

Sep 29, 2025
CVE-2025-57875
4.8 MEDIUM

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative …

Sep 29, 2025
CVE-2025-57874
4.8 MEDIUM

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative …

Sep 29, 2025
CVE-2025-57873
4.8 MEDIUM

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative …

Sep 29, 2025
CVE-2025-57872
6.1 MEDIUM

There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote, unauthenticated attacker to craft a URL …

Sep 29, 2025
CVE-2025-57871
4.8 MEDIUM

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS 11.4 and below that may allow a remote authenticated attacker with administrative …

Sep 29, 2025
CVE-2025-36099
4.9 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A privileged user could exploit …

Sep 29, 2025
CVE-2025-57197
6.0 MEDIUM

In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with …

Sep 29, 2025
CVE-2025-56807
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file …

Sep 29, 2025
CVE-2025-43400
6.3 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, …

Sep 29, 2025
CVE-2025-61659
6.8 MEDIUM

bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.

Sep 29, 2025
CVE-2025-41245
4.9 MEDIUM

VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of …

Sep 29, 2025
CVE-2025-36352
6.4 MEDIUM

IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in …

Sep 29, 2025
CVE-2025-36351
4.3 MEDIUM

IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.

Sep 29, 2025
CVE-2025-57428
6.5 MEDIUM

Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port …

Sep 29, 2025
CVE-2025-11147
5.4 MEDIUM

Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be executed in “/html/<filename>.html”.

Sep 29, 2025
CVE-2025-11146
5.4 MEDIUM

Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is …

Sep 29, 2025
CVE-2025-10346
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10345
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10344
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10343
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10342
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2025-10341
6.1 MEDIUM

HTML injection vulnerability in Perfex CRM v3.2.1 consisting of a stored HTML injection due to lack of proper validation of user input by sending a …

Sep 29, 2025
CVE-2024-5200
4.8 MEDIUM

The Postie WordPress plugin before 1.9.71 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Sep 29, 2025
CVE-2025-11141
4.7 MEDIUM

A security flaw has been discovered in Ruijie NBR2100G-E up to 20250919. Affected by this issue is the function listAction of the file /itbox_pi/branch_passw.php?a=list. Performing …

Sep 29, 2025
CVE-2025-10504
6.1 MEDIUM

Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

Sep 29, 2025
CVE-2025-11139
6.3 MEDIUM

A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function uploadStudioFile of the component com.artery.form.services.FormStudioUpdater. This manipulation of the argument …

Sep 29, 2025
CVE-2025-11138
6.3 MEDIUM

A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command …

Sep 29, 2025
CVE-2025-11136
4.7 MEDIUM

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component …

Sep 29, 2025
CVE-2025-9904
5.3 MEDIUM

Unallocated memory access vulnerability in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer …

Sep 29, 2025
CVE-2025-9903
5.9 MEDIUM

Out-of-bounds write vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver …

Sep 29, 2025
CVE-2025-7698
5.9 MEDIUM

Out-of-bounds read vulnerabilities in print processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer Driver / Generic Plus LIPS4 Printer Driver …

Sep 29, 2025
CVE-2025-11125
4.3 MEDIUM

A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. Affected by this vulnerability is an unknown functionality of the file /connection_error.php of …

Sep 29, 2025
CVE-2025-11121
6.3 MEDIUM

A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the …

Sep 28, 2025
CVE-2025-11119
4.3 MEDIUM

A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST …

Sep 28, 2025
CVE-2025-11114
6.3 MEDIUM

A flaw has been found in CodeAstro Online Leave Application 1.0. Affected by this vulnerability is an unknown functionality of the file /leaveAplicationForm.php. Executing manipulation …

Sep 28, 2025
CVE-2025-11113
6.3 MEDIUM

A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulation of the argument city …

Sep 28, 2025
CVE-2025-11112
4.3 MEDIUM

A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown function of the file /myprofile.php. Such manipulation of …

Sep 28, 2025
CVE-2025-11104
6.3 MEDIUM

A vulnerability was detected in CodeAstro Electricity Billing System 1.0. Affected by this issue is some unknown functionality of the file /admin/bill.php. The manipulation of …

Sep 28, 2025
CVE-2025-11103
4.7 MEDIUM

A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. …

Sep 28, 2025
CVE-2025-11100
6.3 MEDIUM

A vulnerability was identified in D-Link DIR-823X 250416. This affects the function uci_set of the file /goform/set_wifi_blacklists. Such manipulation leads to command injection. It is …

Sep 28, 2025
CVE-2025-11099
6.3 MEDIUM

A vulnerability was determined in D-Link DIR-823X 250416. The impacted element is the function uci_del of the file /goform/delete_prohibiting. This manipulation of the argument delvalue …

Sep 28, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.