CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10665
6.3 MEDIUM

A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Affected is an unknown function of the file /Profilers/PProfile/COUNT3s3.php. The manipulation of the argument csem …

Sep 18, 2025
CVE-2024-25011
5.3 MEDIUM

Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remediate the information disclosure …

Sep 18, 2025
CVE-2025-10662
4.7 MEDIUM

A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_members.php?ac=editsave. Such manipulation of the …

Sep 18, 2025
CVE-2025-9992
6.4 MEDIUM

The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS field …

Sep 18, 2025
CVE-2025-0547
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Bizmu allows Cross-Site Scripting (XSS).This issue affects Bizmu: from …

Sep 18, 2025
CVE-2025-10493
5.3 MEDIUM

The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms …

Sep 18, 2025
CVE-2025-10634
6.3 MEDIUM

A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable …

Sep 18, 2025
CVE-2025-10629
6.3 MEDIUM

A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component Simple Service Discovery …

Sep 18, 2025
CVE-2025-10628
6.3 MEDIUM

A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the component Web Management Interface. Performing …

Sep 18, 2025
CVE-2025-10627
6.3 MEDIUM

A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /admin/delete_user.php. Such manipulation of the …

Sep 18, 2025
CVE-2025-10626
6.3 MEDIUM

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. Affected by this issue is some unknown functionality of the file /admin/update_s3.php. This …

Sep 18, 2025
CVE-2025-23337
6.7 MEDIUM

NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access …

Sep 17, 2025
CVE-2025-10625
6.3 MEDIUM

A vulnerability was detected in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /user/dashboard.php?page=update_profile. The manipulation …

Sep 17, 2025
CVE-2025-23336
4.4 MEDIUM

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of service by loading a misconfigured model. …

Sep 17, 2025
CVE-2025-10620
6.3 MEDIUM

A flaw has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file /editp2.php. Executing manipulation of the …

Sep 17, 2025
CVE-2025-59415
4.6 MEDIUM

Frappe Learning is a learning system that helps users structure their content. In versions 2.34.1 and below, there is a security vulnerability in Frappe Learning …

Sep 17, 2025
CVE-2025-10619
6.3 MEDIUM

A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of the file src/helpers/node-oauth-client-provider.ts of the component OAuth Server Discovery. …

Sep 17, 2025
CVE-2025-10618
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Online Clinic Management System 1.0. Affected by this issue is some unknown functionality of the file transact.php. …

Sep 17, 2025
CVE-2025-10617
6.3 MEDIUM

A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/positions.php. This manipulation …

Sep 17, 2025
CVE-2025-10616
6.3 MEDIUM

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted …

Sep 17, 2025
CVE-2025-59354
5.3 MEDIUM

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the DragonFly2 uses a variety of hash functions, including the …

Sep 17, 2025
CVE-2025-59351
5.3 MEDIUM

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the first return value of a function is dereferenced even …

Sep 17, 2025
CVE-2025-59350
5.3 MEDIUM

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the access control mechanism for the Proxy feature uses simple …

Sep 17, 2025
CVE-2025-59347
6.5 MEDIUM

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The Manager disables TLS certificate verification in HTTP clients. The …

Sep 17, 2025
CVE-2025-59346
5.3 MEDIUM

Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0 contain a server-side request forgery (SSRF) vulnerability that enables …

Sep 17, 2025
CVE-2025-37122
6.1 MEDIUM

A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) …

Sep 17, 2025
CVE-2025-10615
6.3 MEDIUM

A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipulation leads to unrestricted upload. The …

Sep 17, 2025
CVE-2025-10614
4.3 MEDIUM

A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of the file /print_reports_prev.php. …

Sep 17, 2025
CVE-2025-56648
6.5 MEDIUM

npm parcel 2.0.0-alpha and before has an Origin Validation Error vulnerability. Malicious websites can send XMLHTTPRequests to the application's development server and read the response …

Sep 17, 2025
CVE-2025-10613
6.3 MEDIUM

A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /leveledit1.php. Such manipulation of …

Sep 17, 2025
CVE-2025-10608
6.3 MEDIUM

A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Performing manipulation results in …

Sep 17, 2025
CVE-2025-59339
4.4 MEDIUM

The Bastion provides authentication, authorization, traceability and auditability for SSH accesses. Session-recording ttyrec files, may be handled by the provided osh-encrypt-rsync script that is a …

Sep 17, 2025
CVE-2025-58767
5.3 MEDIUM

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. …

Sep 17, 2025
CVE-2025-58431
6.2 MEDIUM

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint …

Sep 17, 2025
CVE-2025-10607
4.3 MEDIUM

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi. Such manipulation leads to …

Sep 17, 2025
CVE-2025-10606
4.3 MEDIUM

A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the …

Sep 17, 2025
CVE-2025-10605
4.3 MEDIUM

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. The manipulation of the …

Sep 17, 2025
CVE-2025-35436
5.3 MEDIUM

CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated remote attacker could cause a crash by providing a specially …

Sep 17, 2025
CVE-2025-35435
4.3 MEDIUM

CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could cause the service to crash. Fixed …

Sep 17, 2025
CVE-2025-35434
4.2 MEDIUM

CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. …

Sep 17, 2025
CVE-2025-35433
5.0 MEDIUM

CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after …

Sep 17, 2025
CVE-2025-35432
5.3 MEDIUM

CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who …

Sep 17, 2025
CVE-2025-35431
5.4 MEDIUM

CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. …

Sep 17, 2025
CVE-2025-35430
5.0 MEDIUM

CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to …

Sep 17, 2025
CVE-2025-10602
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s1.php. Performing manipulation …

Sep 17, 2025
CVE-2025-9862
6.5 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

Sep 17, 2025
CVE-2025-57055
6.5 MEDIUM

WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator can supply a malicious URL via the …

Sep 17, 2025
CVE-2025-54390
6.3 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureResetPasswordStatus attribute is enabled. An attacker can exploit …

Sep 17, 2025
CVE-2025-10595
6.3 MEDIUM

A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/delete_user.php. …

Sep 17, 2025
CVE-2023-53368
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix race issue between cpu buffer write and swap Warning happened in rb_end_commit() at …

Sep 17, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.