CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-56311
6.5 MEDIUM

In Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF vulnerability on the reboot endpoint (/boaform/admin/formReboot). An attacker can …

Sep 23, 2025
CVE-2025-57636
6.5 MEDIUM

OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP parameter "time".

Sep 23, 2025
CVE-2025-58674
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the issue …

Sep 23, 2025
CVE-2025-56146
5.3 MEDIUM

Indian Bank IndSMART Android App 3.8.1 is vulnerable to Missing SSL Certificate Validation in NuWebViewActivity.

Sep 23, 2025
CVE-2025-54081
6.7 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If …

Sep 23, 2025
CVE-2025-45326
6.5 MEDIUM

An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.

Sep 23, 2025
CVE-2025-59821
6.5 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNN’s URL/path handling and template rendering …

Sep 23, 2025
CVE-2025-59548
6.1 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, specially crafted URLs to the FileBrowser …

Sep 23, 2025
CVE-2025-59547
5.3 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has …

Sep 23, 2025
CVE-2025-59539
6.3 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography …

Sep 23, 2025
CVE-2025-58246
4.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue …

Sep 23, 2025
CVE-2025-57639
6.5 MEDIUM

OS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.user parameter in the formSetSambaConf function of …

Sep 23, 2025
CVE-2025-29084
6.5 MEDIUM

SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Upgrade.php file.

Sep 23, 2025
CVE-2025-29083
6.5 MEDIUM

SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugin_Manager.php file.

Sep 23, 2025
CVE-2025-0209
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding. A malicious actor can …

Sep 23, 2025
CVE-2025-56304
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.

Sep 23, 2025
CVE-2025-0663
6.8 MEDIUM

A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all …

Sep 23, 2025
CVE-2024-6429
4.3 MEDIUM

A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameters …

Sep 23, 2025
CVE-2025-5717
6.8 MEDIUM

An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user …

Sep 23, 2025
CVE-2025-57407
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or …

Sep 23, 2025
CVE-2025-4760
4.8 MEDIUM

An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the …

Sep 23, 2025
CVE-2024-4598
6.5 MEDIUM

An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended …

Sep 23, 2025
CVE-2025-9342
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privilege Abuse.This issue affects AHE Mobile: from 1.9.7 before 1.9.9.

Sep 23, 2025
CVE-2025-7106
5.3 MEDIUM

danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/server/middleware/roles/access.js` uses `permissions.some()` to validate permissions, which …

Sep 23, 2025
CVE-2025-10848
6.3 MEDIUM

A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown processing of the file /check_student.php. Such manipulation of the …

Sep 23, 2025
CVE-2025-10846
6.3 MEDIUM

A vulnerability was determined in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/ComponenteCurricular/edit. This manipulation of the argument ID …

Sep 23, 2025
CVE-2025-10845
6.3 MEDIUM

A vulnerability was found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/ComponenteCurricular/view. The manipulation of the argument ID …

Sep 23, 2025
CVE-2025-10844
6.3 MEDIUM

A vulnerability has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/Cadastro/aluno. The manipulation …

Sep 23, 2025
CVE-2025-10548
6.5 MEDIUM

The CleverControl employee monitoring software (v11.5.1041.6) fails to validate TLS server certificates during the installation process. The installer downloads and executes external components using curl.exe …

Sep 23, 2025
CVE-2025-39887
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix null-ptr-deref in bitmap_parselist() A crash was observed with the following output: BUG: kernel …

Sep 23, 2025
CVE-2025-39886
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Tell memcg to use allow_spinning=false path in bpf_timer_init() Currently, calling bpf_map_kmalloc_node() from __bpf_async_init() can …

Sep 23, 2025
CVE-2025-39885
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix recursive semaphore deadlock in fiemap call syzbot detected a OCFS2 hang due to …

Sep 23, 2025
CVE-2025-39884
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix subvolume deletion lockup caused by inodes xarray race There is a race condition …

Sep 23, 2025
CVE-2025-39879
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: always call ceph_shift_unused_folios_left() The function ceph_process_folio_batch() sets folio_batch entries to NULL, which is an …

Sep 23, 2025
CVE-2025-39878
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: fix crash after fscrypt_encrypt_pagecache_blocks() error The function move_dirty_folio_in_page_array() was created by commit ce80b76dd327 ("ceph: …

Sep 23, 2025
CVE-2025-39876
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() The function of_phy_find_device may return NULL, so we …

Sep 23, 2025
CVE-2025-39875
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igb: Fix NULL pointer dereference in ethtool loopback test The igb driver currently causes a …

Sep 23, 2025
CVE-2025-39874
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: macsec: sync features on RTM_NEWLINK Syzkaller managed to lock the lower device via ETHTOOL_SFEATURES: netdev_lock …

Sep 23, 2025
CVE-2025-39872
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hsr: hold rcu and dev lock for hsr_get_port_ndev hsr_get_port_ndev calls hsr_for_each_port, which need to hold …

Sep 23, 2025
CVE-2025-10840
6.3 MEDIUM

A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown function of the file /admin/print-payment.php. This manipulation of the …

Sep 23, 2025
CVE-2025-10839
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. The impacted element is an unknown function of the file /admin/inv-print.php. The …

Sep 23, 2025
CVE-2025-8902
6.4 MEDIUM

The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sidebar' shortcode in all versions up to, and …

Sep 23, 2025
CVE-2025-10835
6.3 MEDIUM

A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function of the file /admin/view_payorder.php. Performing manipulation of …

Sep 23, 2025
CVE-2025-58915
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Request a Quote request-a-quote allows Stored XSS.This issue affects Request a Quote: …

Sep 23, 2025
CVE-2025-42907
4.3 MEDIUM

SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser …

Sep 23, 2025
CVE-2025-10828
6.3 MEDIUM

A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. This affects an unknown part of the file /admin/edit.php. Such manipulation of …

Sep 23, 2025
CVE-2025-10827
4.3 MEDIUM

A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. …

Sep 23, 2025
CVE-2025-10826
6.3 MEDIUM

A security flaw has been discovered in Campcodes Online Beauty Parlor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Sep 23, 2025
CVE-2025-10825
6.3 MEDIUM

A vulnerability was identified in Campcodes Online Beauty Parlor Management System 1.0. Affected is an unknown function of the file /admin/view-appointment.php. The manipulation of the …

Sep 23, 2025
CVE-2025-10824
5.3 MEDIUM

A vulnerability was determined in axboe fio up to 3.41. This impacts the function __parse_jobs_ini of the file init.c. Executing manipulation can lead to use …

Sep 23, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.