CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10995
5.3 MEDIUM

A security vulnerability has been detected in Open Babel up to 3.1.1. This vulnerability affects the function zlib_stream::basic_unzip_streambuf::underflow in the library /src/zipstreamimpl.h. Such manipulation leads …

Sep 26, 2025
CVE-2025-10994
5.3 MEDIUM

A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of the file gamessformat.cpp. This manipulation causes use after …

Sep 26, 2025
CVE-2025-10993
4.7 MEDIUM

A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the …

Sep 26, 2025
CVE-2025-10992
5.3 MEDIUM

A vulnerability was determined in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. Affected is an unknown function of the file /user/info/lookupList. Executing manipulation can lead to improper …

Sep 26, 2025
CVE-2025-10752
4.3 MEDIUM

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Sep 26, 2025
CVE-2025-10178
6.4 MEDIUM

The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featured_image' shortcode in all versions up to, and including, …

Sep 26, 2025
CVE-2025-60251
5.0 MEDIUM

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.

Sep 26, 2025
CVE-2025-60250
4.7 MEDIUM

Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the 2841ae97419c2973296a0d4bdfe19a4f IV.

Sep 26, 2025
CVE-2025-10989
6.3 MEDIUM

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the …

Sep 26, 2025
CVE-2025-10988
6.3 MEDIUM

A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulation leads to improper authorization. …

Sep 26, 2025
CVE-2025-10987
6.3 MEDIUM

A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality of the file /crm/contact/transfer of the component …

Sep 26, 2025
CVE-2025-10981
4.3 MEDIUM

A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation results in improper authorization. The …

Sep 26, 2025
CVE-2025-10980
4.3 MEDIUM

A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manipulation leads to improper …

Sep 26, 2025
CVE-2025-56769
6.5 MEDIUM

An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary method invocation and potentially remote code …

Sep 25, 2025
CVE-2025-10979
4.3 MEDIUM

A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulation causes improper …

Sep 25, 2025
CVE-2025-10978
4.3 MEDIUM

A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/exportXls of the component …

Sep 25, 2025
CVE-2025-10975
6.3 MEDIUM

A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.robot.bridge.reasoning_server::run_reasoning_server of the file experiments/robot/bridge/reasoning_server.py of the component ZeroMQ. Performing …

Sep 25, 2025
CVE-2025-10974
6.3 MEDIUM

A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects the function pickle.loads of the file /calculate of the component Endpoint. Such …

Sep 25, 2025
CVE-2025-59402
5.4 MEDIUM

Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access …

Sep 25, 2025
CVE-2025-26482
4.9 MEDIUM

Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit this …

Sep 25, 2025
CVE-2025-10965
6.3 MEDIUM

A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/components/deploy/relay/server.py. Such …

Sep 25, 2025
CVE-2025-10964
6.3 MEDIUM

A weakness has been identified in Wavlink NU516U1. Affected by this vulnerability is the function sub_401B30 of the file /cgi-bin/firewall.cgi. This manipulation of the argument …

Sep 25, 2025
CVE-2025-29157
6.5 MEDIUM

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing …

Sep 25, 2025
CVE-2025-29156
6.1 MEDIUM

Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet

Sep 25, 2025
CVE-2025-10963
6.3 MEDIUM

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. Affected is the function sub_4016F0 of the file /cgi-bin/firewall.cgi. The manipulation of the argument del_flag …

Sep 25, 2025
CVE-2025-10962
6.3 MEDIUM

A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This impacts the function sub_403198 of the file /cgi-bin/wireless.cgi of the component SetName Page. The manipulation of …

Sep 25, 2025
CVE-2025-60249
6.4 MEDIUM

vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and user.py, by a user on a vulnerability-lookup instance who can add bundles, comments, or sightings. A cross-site …

Sep 25, 2025
CVE-2025-57623
5.3 MEDIUM

A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.

Sep 25, 2025
CVE-2025-29155
6.5 MEDIUM

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint

Sep 25, 2025
CVE-2025-10961
5.5 MEDIUM

A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-bin/wireless.cgi of the component Delete_Mac_list Page. Executing manipulation of …

Sep 25, 2025
CVE-2025-10960
6.3 MEDIUM

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. The impacted element is the function sub_402D1C of the file /cgi-bin/wireless.cgi of the component DeleteMac Page. Performing …

Sep 25, 2025
CVE-2025-10959
6.3 MEDIUM

A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. The affected element is the function sub_401778 of the file /cgi-bin/firewall.cgi. Such manipulation of the argument …

Sep 25, 2025
CVE-2025-10958
6.3 MEDIUM

A flaw has been found in Wavlink NU516U1 M16U1_V240425. Impacted is the function sub_403010 of the file /cgi-bin/wireless.cgi of the component AddMac Page. This manipulation …

Sep 25, 2025
CVE-2025-10879
5.3 MEDIUM

All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to retrieve the current user's username without …

Sep 25, 2025
CVE-2025-60018
4.8 MEDIUM

glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.

Sep 25, 2025
CVE-2025-55556
6.5 MEDIUM

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in the application.

Sep 25, 2025
CVE-2025-55554
5.3 MEDIUM

pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().

Sep 25, 2025
CVE-2025-43943
6.7 MEDIUM

Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Sep 25, 2025
CVE-2025-33116
4.4 MEDIUM

IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary …

Sep 25, 2025
CVE-2025-26333
5.9 MEDIUM

Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, …

Sep 25, 2025
CVE-2025-20362
6.5 MEDIUM KEV

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software …

Sep 25, 2025
CVE-2025-10952
5.3 MEDIUM

A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream_handler of the file ml_logger/server.py of …

Sep 25, 2025
CVE-2025-10911
5.5 MEDIUM

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

Sep 25, 2025
CVE-2025-59838
5.4 MEDIUM

Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user input when loading a saved custom text results …

Sep 25, 2025
CVE-2025-46153
5.3 MEDIUM

PyTorch before 3.7.0 has a bernoulli_p decompose function in decompositions.py even though it lacks full consistency with the eager CPU implementation, negatively affecting nn.Dropout1d, nn.Dropout2d, …

Sep 25, 2025
CVE-2025-46152
5.3 MEDIUM

In PyTorch before 2.7.0, bitwise_right_shift produces incorrect output for certain out-of-bounds values of the "other" argument.

Sep 25, 2025
CVE-2025-46150
5.3 MEDIUM

In PyTorch before 2.7.0, when torch.compile is used, FractionalMaxPool2d has inconsistent results.

Sep 25, 2025
CVE-2025-46149
5.3 MEDIUM

In PyTorch before 2.7.0, when inductor is used, nn.Fold has an assertion error.

Sep 25, 2025
CVE-2025-46148
5.3 MEDIUM

In PyTorch through 2.6.0, when eager is used, nn.PairwiseDistance(p=2) produces incorrect results.

Sep 25, 2025
CVE-2025-36601
4.0 MEDIUM

Dell PowerScale OneFS, versions 9.5.0.0 through 9.11.0.0, contains an exposure of sensitive information to an unauthorized actor vulnerability. An unauthenticated remote attacker could potentially exploit …

Sep 25, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.