CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10950
6.3 MEDIUM

A vulnerability was determined in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected is the function log_handler of the file ml_logger/server.py of the component Ping Handler. This …

Sep 25, 2025
CVE-2025-59426
4.3 MEDIUM

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of …

Sep 25, 2025
CVE-2025-10540
6.5 MEDIUM

iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the …

Sep 25, 2025
CVE-2025-10947
5.3 MEDIUM

A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of the file /api/areacliente/pessoa/validarCpf …

Sep 25, 2025
CVE-2025-21056
6.6 MEDIUM

Improper input validation in Retail Mode prior to version 5.59.4 allows self attackers to execute privileged commands on their own devices.

Sep 25, 2025
CVE-2025-57324
6.5 MEDIUM

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers …

Sep 24, 2025
CVE-2025-57320
6.5 MEDIUM

json-schema-editor-visual is a package that provides jsonschema editor. A Prototype Pollution vulnerability in the setData and deleteData function of json-schema-editor-visual versions thru 1.1.1 allows attackers …

Sep 24, 2025
CVE-2025-59824
5.4 MEDIUM

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escape. Omni …

Sep 24, 2025
CVE-2025-59525
6.1 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded …

Sep 24, 2025
CVE-2025-57351
6.5 MEDIUM

A prototype pollution vulnerability exists in the ts-fns package versions prior to 13.0.7, where insufficient validation of user-provided keys in the assign function allows attackers …

Sep 24, 2025
CVE-2025-57348
6.5 MEDIUM

The node-cube package (prior to version 5.0.0) contains a vulnerability in its handling of prototype chain initialization, which could allow an attacker to inject properties …

Sep 24, 2025
CVE-2025-55178
5.3 MEDIUM

Llama Stack prior to version v0.2.20 accepted unverified parameters in the resolve_ast_by_type function which could potentially allow for remote code execution.

Sep 24, 2025
CVE-2025-59524
6.1 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in the …

Sep 24, 2025
CVE-2025-57354
6.5 MEDIUM

A vulnerability exists in the 'counterpart' library for Node.js and the browser due to insufficient sanitization of user-controlled input in translation key processing. The affected …

Sep 24, 2025
CVE-2025-57353
5.3 MEDIUM

The Runtime components of messageformat package for Node.js before 3.0.2 contain a prototype pollution vulnerability. Due to insufficient validation of nested message keys during the …

Sep 24, 2025
CVE-2025-57352
5.3 MEDIUM

A vulnerability exists in the 'min-document' package prior to version 2.19.0, stemming from improper handling of namespace operations in the removeAttributeNS method. By processing malicious …

Sep 24, 2025
CVE-2025-48867
4.8 MEDIUM

Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin …

Sep 24, 2025
CVE-2025-20338
6.0 MEDIUM

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root …

Sep 24, 2025
CVE-2025-20316
5.3 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an …

Sep 24, 2025
CVE-2025-20314
6.7 MEDIUM

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an …

Sep 24, 2025
CVE-2025-20313
6.7 MEDIUM

Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to …

Sep 24, 2025
CVE-2025-20293
5.3 MEDIUM

A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an …

Sep 24, 2025
CVE-2025-20240
6.1 MEDIUM

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack …

Sep 24, 2025
CVE-2025-20149
6.5 MEDIUM

A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device …

Sep 24, 2025
CVE-2025-20365
4.3 MEDIUM

A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 …

Sep 24, 2025
CVE-2025-20364
4.3 MEDIUM

A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless …

Sep 24, 2025
CVE-2025-20339
5.8 MEDIUM

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass …

Sep 24, 2025
CVE-2025-27036
6.1 MEDIUM

Information disclosure when Video engine escape input data is less than expected minimum size.

Sep 24, 2025
CVE-2025-27033
6.1 MEDIUM

Information disclosure while running video usecase having rogue firmware.

Sep 24, 2025
CVE-2025-27030
6.1 MEDIUM

information disclosure while invoking calibration data from user space to update firmware size.

Sep 24, 2025
CVE-2025-23275
4.2 MEDIUM

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain …

Sep 24, 2025
CVE-2025-23274
4.5 MEDIUM

NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted input image with dimensions …

Sep 24, 2025
CVE-2025-23272
5.7 MEDIUM

NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially crafted JPEG file. A successful exploit …

Sep 24, 2025
CVE-2025-9353
6.4 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to …

Sep 24, 2025
CVE-2025-60020
6.4 MEDIUM

nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.

Sep 24, 2025
CVE-2025-39890
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_ready_ext_event Currently, in ath12k_service_ready_ext_event(), svc_rdy_ext.mac_phy_caps is not freed in …

Sep 24, 2025
CVE-2024-58241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregister_dev This make use of disable_work_* on hci_unregister_dev since the …

Sep 24, 2025
CVE-2025-58457
4.3 MEDIUM

Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 …

Sep 24, 2025
CVE-2025-9031
4.3 MEDIUM

Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing.This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.

Sep 24, 2025
CVE-2025-41716
5.3 MEDIUM

The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical …

Sep 24, 2025
CVE-2025-48459
5.3 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, …

Sep 24, 2025
CVE-2025-43819
6.5 MEDIUM

A Insufficient Session Expiration vulnerability in the Liferay Portal 7.4.3.121 through 7.3.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, and …

Sep 24, 2025
CVE-2025-43779
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 …

Sep 24, 2025
CVE-2025-58473
5.9 MEDIUM

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated …

Sep 23, 2025
CVE-2025-57882
5.9 MEDIUM

An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated …

Sep 23, 2025
CVE-2025-55038
6.8 MEDIUM

An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device firmware version 3.60. Through the KOPR protocol utilized by the Remote PLC …

Sep 23, 2025
CVE-2025-58069
5.3 MEDIUM

The use of a hard-coded cryptographic key was discovered in firmware version 3.60 of the Click Plus PLC. The vulnerability relies on the fact that …

Sep 23, 2025
CVE-2025-54855
4.2 MEDIUM

Cleartext storage of sensitive information was discovered in Click Programming Software version v3.60. The vulnerability can be exploited by a local user with access to …

Sep 23, 2025
CVE-2024-21935
5.0 MEDIUM

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local …

Sep 23, 2025
CVE-2024-21927
5.0 MEDIUM

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing …

Sep 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.