CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10255
3.5 LOW

A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the file /Products/Projects/Messages.aspx of the component Comment …

Sep 11, 2025
CVE-2025-10254
3.5 LOW

A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of the file /Products/Projects/Messages.aspx of the component …

Sep 11, 2025
CVE-2025-10253
3.5 LOW

A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifive.php of the component SVG File Handler. Such manipulation …

Sep 11, 2025
CVE-2025-10252
3.1 LOW

A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. …

Sep 11, 2025
CVE-2025-10246
3.5 LOW

A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument …

Sep 11, 2025
CVE-2025-6088
3.1 LOW

In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if the conversation ID is …

Sep 11, 2025
CVE-2025-10235
2.4 LOW

A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. …

Sep 11, 2025
CVE-2025-10234
2.4 LOW

A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point_edit.shtm of the component Data Point Edit Module. …

Sep 11, 2025
CVE-2025-10216
2.6 LOW

A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. …

Sep 10, 2025
CVE-2025-10222
3.3 LOW

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows …

Sep 10, 2025
CVE-2025-8277
3.1 LOW

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free …

Sep 9, 2025
CVE-2025-59014
2.7 LOW

An uncaught exception in the Bookmark Toolbar of TYPO3 CMS versions 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 lets administrator‑level backend users trigger a denial‑of‑service condition in the …

Sep 9, 2025
CVE-2025-40803
3.1 LOW

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical information from the device. This could allow an …

Sep 9, 2025
CVE-2025-40802
3.1 LOW

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to high volumes …

Sep 9, 2025
CVE-2025-9111
3.5 LOW

The AI ChatBot for WordPress WordPress plugin before 7.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such …

Sep 9, 2025
CVE-2025-8889
3.8 LOW

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files …

Sep 9, 2025
CVE-2025-42927
3.4 LOW

SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library …

Sep 9, 2025
CVE-2025-42914
3.1 LOW

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform …

Sep 9, 2025
CVE-2025-42913
3.1 LOW

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform …

Sep 9, 2025
CVE-2025-10117
3.5 LOW

A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add …

Sep 9, 2025
CVE-2024-48341
3.7 LOW

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop

Sep 8, 2025
CVE-2025-10099
2.4 LOW

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_usuario_cad.php of the …

Sep 8, 2025
CVE-2025-51586
3.7 LOW

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

Sep 8, 2025
CVE-2025-10088
3.5 LOW

A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument …

Sep 8, 2025
CVE-2025-58422
3.1 LOW

RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter …

Sep 8, 2025
CVE-2025-10080
3.1 LOW

A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/datart/security/util/AESUtil.java of the …

Sep 8, 2025
CVE-2025-10075
3.5 LOW

A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation …

Sep 8, 2025
CVE-2025-10074
3.5 LOW

A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the …

Sep 8, 2025
CVE-2025-0011
3.3 LOW

Improper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address information potentially resulting in …

Sep 6, 2025
CVE-2024-36331
3.2 LOW

Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity.

Sep 6, 2025
CVE-2023-31365
3.9 LOW

An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reserved dRAM area resulting in …

Sep 6, 2025
CVE-2023-31330
2.5 LOW

An out-of-bounds read in the ASP could allow a privileged attacker with access to a malicious bootloader to potentially read sensitive memory resulting in loss …

Sep 6, 2025
CVE-2023-31326
2.8 LOW

Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution environment (TEE) driver, potentially leading …

Sep 6, 2025
CVE-2023-31306
3.3 LOW

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management …

Sep 6, 2025
CVE-2023-20516
3.3 LOW

Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentially resulting in loss of confidentiality …

Sep 6, 2025
CVE-2021-46750
3.0 LOW

Failure to validate the address and size in TEE (Trusted Execution Environment) may allow a malicious x86 attacker to send malformed messages to the graphics …

Sep 6, 2025
CVE-2025-10029
3.5 LOW

A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation …

Sep 6, 2025
CVE-2025-10028
3.5 LOW

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the …

Sep 6, 2025
CVE-2025-57807
3.8 LOW

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing …

Sep 5, 2025
CVE-2025-10027
3.5 LOW

A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This …

Sep 5, 2025
CVE-2025-10026
3.5 LOW

A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The …

Sep 5, 2025
CVE-2025-10014
3.1 LOW

A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address …

Sep 5, 2025
CVE-2025-26461
3.3 LOW

In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the user attempts to close the app …

Sep 5, 2025
CVE-2025-58866
2.7 LOW

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami Yushuvaev Site Info site-info-dashboard-widget allows Retrieve Embedded Sensitive Data.This issue affects Site …

Sep 5, 2025
CVE-2025-58827
3.8 LOW

Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a …

Sep 5, 2025
CVE-2025-58816
3.5 LOW

Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Carousel Slider …

Sep 5, 2025
CVE-2024-21977
3.2 LOW

Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss …

Sep 5, 2025
CVE-2025-26419
3.3 LOW

In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-0076
3.3 LOW

In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check. This could lead to …

Sep 4, 2025
CVE-2025-26428
3.2 LOW

In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation …

Sep 4, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.