CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-55904
4.0 MEDIUM

Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference when a multipart/related HTTP POST request with an empty HTTP body is …

Sep 17, 2025
CVE-2025-50709
4.3 MEDIUM

An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter

Sep 17, 2025
CVE-2025-10594
6.3 MEDIUM

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_student.php. …

Sep 17, 2025
CVE-2025-10593
6.3 MEDIUM

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the …

Sep 17, 2025
CVE-2025-8463
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing.This issue affects SecHard: before 3.6.2-20250805.

Sep 17, 2025
CVE-2025-54467
5.3 MEDIUM

When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security …

Sep 17, 2025
CVE-2025-53884
5.3 MEDIUM

NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of …

Sep 17, 2025
CVE-2025-10592
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the …

Sep 17, 2025
CVE-2025-0879
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside Software Shopside App allows Cross-Site Scripting (XSS). This issue requires …

Sep 17, 2025
CVE-2025-8999
5.3 MEDIUM

The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' function in all versions …

Sep 17, 2025
CVE-2025-0546
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Restriction of Rendered UI Layers or Frames vulnerability in Mevzuattr Software MevzuatTR …

Sep 17, 2025
CVE-2025-10590
4.3 MEDIUM

A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuario_det.php. The manipulation …

Sep 17, 2025
CVE-2025-0420
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Paraşüt allows Cross-Site Scripting (XSS).This issue affects Paraşüt: from …

Sep 17, 2025
CVE-2025-59456
5.5 MEDIUM

In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload

Sep 17, 2025
CVE-2025-59455
4.2 MEDIUM

In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition

Sep 17, 2025
CVE-2025-0419
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. Zirve Nova allows Cross-Site Scripting (XSS).This issue …

Sep 17, 2025
CVE-2025-9565
6.4 MEDIUM

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 …

Sep 17, 2025
CVE-2025-9215
6.5 MEDIUM

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions …

Sep 17, 2025
CVE-2025-9203
6.4 MEDIUM

The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitle_ssize', 'track_title', and 'track_artist_name' parameters in version 1.0.5. …

Sep 17, 2025
CVE-2025-10042
5.9 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to …

Sep 17, 2025
CVE-2025-9818
6.7 MEDIUM

A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided by OMRON SOCIAL SOLUTIONS Co., Ltd., where the executable file …

Sep 17, 2025
CVE-2025-59307
6.7 MEDIUM

RAID Manager provided by Century Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory …

Sep 17, 2025
CVE-2025-55075
4.9 MEDIUM

Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker.

Sep 17, 2025
CVE-2025-10188
5.4 MEDIUM

The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This …

Sep 17, 2025
CVE-2025-10125
6.4 MEDIUM

The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shortcode in all versions up to, and including, 1.4 …

Sep 17, 2025
CVE-2025-9891
4.3 MEDIUM

The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This …

Sep 17, 2025
CVE-2025-9851
6.4 MEDIUM

The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar' shortcode in all versions up to, and including, 4.1.0 due …

Sep 17, 2025
CVE-2025-9629
4.3 MEDIUM

The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing …

Sep 17, 2025
CVE-2025-8394
6.4 MEDIUM

The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_productive_breadcrumb shortcode in all versions up to, and including, 1.1.23 …

Sep 17, 2025
CVE-2025-10166
6.4 MEDIUM

The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twitter' shortcode in all versions up to, and including, …

Sep 17, 2025
CVE-2025-10050
6.6 MEDIUM

The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the …

Sep 17, 2025
CVE-2025-43804
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject …

Sep 16, 2025
CVE-2025-37131
4.9 MEDIUM

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, …

Sep 16, 2025
CVE-2025-37130
6.5 MEDIUM

A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow …

Sep 16, 2025
CVE-2025-37129
6.7 MEDIUM

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could …

Sep 16, 2025
CVE-2025-37128
6.8 MEDIUM

A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful …

Sep 16, 2025
CVE-2025-9708
6.8 MEDIUM

A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying …

Sep 16, 2025
CVE-2025-43805
5.3 MEDIUM

Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not …

Sep 16, 2025
CVE-2025-10566
4.3 MEDIUM

A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=users. The …

Sep 16, 2025
CVE-2025-49728
4.0 MEDIUM

Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally.

Sep 16, 2025
CVE-2025-47967
4.7 MEDIUM

Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

Sep 16, 2025
CVE-2025-54237
5.5 MEDIUM

Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this …

Sep 16, 2025
CVE-2025-58174
4.6 MEDIUM

LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stored cross-site scripting in the Profile …

Sep 16, 2025
CVE-2023-53334
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: chipidea: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have …

Sep 16, 2025
CVE-2023-53332
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: genirq/ipi: Fix NULL pointer deref in irq_data_get_affinity_mask() If ipi_send_{mask|single}() is called with an invalid interrupt …

Sep 16, 2025
CVE-2023-53330
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: caif: fix memory leak in cfctrl_linkup_request() When linktype is unknown or kzalloc failed in cfctrl_linkup_request(), …

Sep 16, 2025
CVE-2023-53329
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: workqueue: fix data race with the pwq->stats[] increment KCSAN has discovered a data race in …

Sep 16, 2025
CVE-2023-53328
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Enhance sanity check while generating attr_list ni_create_attr_list uses WARN_ON to catch error cases while …

Sep 16, 2025
CVE-2023-53327
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iommufd/selftest: Catch overflow of uptr and length syzkaller hits a WARN_ON when trying to have …

Sep 16, 2025
CVE-2023-53326
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc: Don't try to copy PPR for task with NULL pt_regs powerpc sets up PF_KTHREAD …

Sep 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.