CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43203
4.0 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An …

Sep 15, 2025
CVE-2025-43190
5.5 MEDIUM

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26, …

Sep 15, 2025
CVE-2025-31270
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access protected user …

Sep 15, 2025
CVE-2025-31269
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to …

Sep 15, 2025
CVE-2025-31268
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may …

Sep 15, 2025
CVE-2025-31254
5.4 MEDIUM

This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content …

Sep 15, 2025
CVE-2025-30468
6.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without …

Sep 15, 2025
CVE-2025-24197
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may …

Sep 15, 2025
CVE-2025-10485
4.3 MEDIUM

A vulnerability has been found in pojoin h3blog up to 5bf704425ebc11f4c24da51f32f36bb17ae20489. Affected by this issue is the function ppt_log of the file /login of the …

Sep 15, 2025
CVE-2025-10483
6.3 MEDIUM

A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/save_user.php. …

Sep 15, 2025
CVE-2025-57117
5.4 MEDIUM

A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting …

Sep 15, 2025
CVE-2025-43802
6.1 MEDIUM

Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7.4.3.51 through 7.4.3.109, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 …

Sep 15, 2025
CVE-2025-43797
5.4 MEDIUM

In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older …

Sep 15, 2025
CVE-2025-10481
6.3 MEDIUM

A security vulnerability has been detected in SourceCodester Online Student File Management System 1.0. This impacts an unknown function of the file /remove_file.php. The manipulation …

Sep 15, 2025
CVE-2025-10480
6.3 MEDIUM

A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.php. Executing manipulation can …

Sep 15, 2025
CVE-2025-43799
6.5 MEDIUM

Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through …

Sep 15, 2025
CVE-2025-43798
6.5 MEDIUM

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be …

Sep 15, 2025
CVE-2025-10477
6.3 MEDIUM

A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/PriProfile/eligibility.php. Such manipulation of the …

Sep 15, 2025
CVE-2025-59154
5.9 MEDIUM

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire’s SASL EXTERNAL mechanism for client TLS authentication contains a vulnerability in how …

Sep 15, 2025
CVE-2025-56448
6.8 MEDIUM

The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The …

Sep 15, 2025
CVE-2025-45091
5.4 MEDIUM

Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro are vulnerable to a stored Cross-Site Scripting (XSS) attack. An authenticated attacker can exploit this vulnerability by modifying their …

Sep 15, 2025
CVE-2025-10475
5.5 MEDIUM

A weakness has been identified in SpyShelter up to 15.4.0.1015. Affected is an unknown function in the library SpyShelter.sys of the component IOCTL Handler. This …

Sep 15, 2025
CVE-2025-43800
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 and 7.4 GA through update 92 …

Sep 15, 2025
CVE-2025-10473
6.3 MEDIUM

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/ruoyi/common/utils/sql/SqlUtil.java of the component Blacklist …

Sep 15, 2025
CVE-2025-10472
5.3 MEDIUM

A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the file app/controllers/v1/video.py of the component …

Sep 15, 2025
CVE-2025-52344
6.1 MEDIUM

Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers to inject arbitrary JavaScript code on the user's browser via …

Sep 15, 2025
CVE-2025-43791
6.1 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 …

Sep 15, 2025
CVE-2025-59328
6.5 MEDIUM

A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The issue stems from the insecure deserialization of untrusted …

Sep 15, 2025
CVE-2025-58177
5.4 MEDIUM

n8n is an open source workflow automation platform. From 1.24.0 to before 1.107.0, there is a stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized …

Sep 15, 2025
CVE-2025-57176
6.5 MEDIUM

On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads …

Sep 15, 2025
CVE-2025-57104
5.4 MEDIUM

Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx.

Sep 15, 2025
CVE-2025-49089
6.3 MEDIUM

wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.

Sep 15, 2025
CVE-2025-43792
5.3 MEDIUM

Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 …

Sep 15, 2025
CVE-2025-10471
6.3 MEDIUM

A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaController.cs. Performing manipulation of the argument url results in server-side …

Sep 15, 2025
CVE-2025-59397
5.0 MEDIUM

Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.

Sep 15, 2025
CVE-2025-56252
6.1 MEDIUM

Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted URL to the mobile parameter.

Sep 15, 2025
CVE-2025-52048
6.5 MEDIUM

In Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to SQL Injection, which allows an attacker to …

Sep 15, 2025
CVE-2025-36082
4.0 MEDIUM

IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system.

Sep 15, 2025
CVE-2023-53261
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: coresight: Fix memory leak in acpi_buffer->pointer There are memory leaks reported by kmemleak: ... unreferenced …

Sep 15, 2025
CVE-2023-53260
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ovl: fix null pointer dereference in ovl_permission() Following process: P1 P2 path_lookupat link_path_walk inode_permission ovl_permission …

Sep 15, 2025
CVE-2023-53258
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix possible underflow for displays with large vblank [Why] Underflow observed when using a …

Sep 15, 2025
CVE-2023-53256
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix FFA device names for logical partitions Each physical partition can provide multiple …

Sep 15, 2025
CVE-2023-53255
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: stratix10-svc: Fix a potential resource leak in svc_create_memory_pool() svc_create_memory_pool() is only called from stratix10_svc_drv_probe(). …

Sep 15, 2025
CVE-2023-53251
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: pcie: fix NULL pointer dereference in iwl_pcie_irq_rx_msix_handler() rxq can be NULL only when …

Sep 15, 2025
CVE-2023-53250
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: dmi-sysfs: Fix null-ptr-deref in dmi_sysfs_register_handle KASAN reported a null-ptr-deref error: KASAN: null-ptr-deref in range …

Sep 15, 2025
CVE-2023-53249
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: imx: clk-imx8mn: fix memory leak in imx8mn_clocks_probe Use devm_of_iomap() instead of of_iomap() to automatically …

Sep 15, 2025
CVE-2023-53248
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: install stub fence into potential unused fence pointers When using cpu to update page …

Sep 15, 2025
CVE-2023-53247
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: set_page_extent_mapped after read_folio in btrfs_cont_expand While trying to get the subpage blocksize tests running, …

Sep 15, 2025
CVE-2023-53246
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cifs: fix DFS traversal oops without CONFIG_CIFS_DFS_UPCALL When compiled with CONFIG_CIFS_DFS_UPCALL disabled, cifs_dfs_d_automount is NULL. …

Sep 15, 2025
CVE-2023-53245
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Fix handling of virtual Fibre Channel timeouts Hyper-V provides the ability to connect …

Sep 15, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.