CVE Database

52322+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10227
4.6 MEDIUM

Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2.0.8 on Windows and Linux allows a local …

Sep 10, 2025
CVE-2025-10224
5.4 MEDIUM

Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be …

Sep 10, 2025
CVE-2025-10223
5.4 MEDIUM

Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated …

Sep 10, 2025
CVE-2025-10221
5.5 MEDIUM

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on …

Sep 10, 2025
CVE-2025-9979
4.3 MEDIUM

The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv …

Sep 10, 2025
CVE-2025-9888
4.3 MEDIUM

The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is …

Sep 10, 2025
CVE-2025-9857
6.4 MEDIUM

The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all versions up …

Sep 10, 2025
CVE-2025-9622
4.3 MEDIUM

The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.6. …

Sep 10, 2025
CVE-2025-9463
6.5 MEDIUM

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter …

Sep 10, 2025
CVE-2025-9367
5.5 MEDIUM

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient …

Sep 10, 2025
CVE-2025-8778
4.3 MEDIUM

The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions …

Sep 10, 2025
CVE-2025-7843
6.4 MEDIUM

The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the …

Sep 10, 2025
CVE-2025-7826
6.5 MEDIUM

The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient …

Sep 10, 2025
CVE-2025-6189
6.5 MEDIUM

The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter in all versions up to, and including, …

Sep 10, 2025
CVE-2025-10142
4.9 MEDIUM

The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and …

Sep 10, 2025
CVE-2025-10126
6.4 MEDIUM

The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' shortcode in all versions up to, and including, 1.0.8 …

Sep 10, 2025
CVE-2025-8388
6.4 MEDIUM

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_url’ parameter in all versions …

Sep 10, 2025
CVE-2025-10197
6.3 MEDIUM

A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability is an unknown functionality of the file …

Sep 10, 2025
CVE-2025-10195
5.3 MEDIUM

A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such …

Sep 10, 2025
CVE-2025-59044
4.4 MEDIUM

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display …

Sep 9, 2025
CVE-2025-59036
5.5 MEDIUM

Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the authentication logic will cause …

Sep 9, 2025
CVE-2025-58135
5.3 MEDIUM

Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access.

Sep 9, 2025
CVE-2025-58134
4.3 MEDIUM

Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.

Sep 9, 2025
CVE-2025-58131
6.6 MEDIUM

Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective …

Sep 9, 2025
CVE-2025-49461
4.3 MEDIUM

Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

Sep 9, 2025
CVE-2025-49460
4.3 MEDIUM

Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.

Sep 9, 2025
CVE-2025-49458
6.5 MEDIUM

Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access.

Sep 9, 2025
CVE-2025-54241
5.5 MEDIUM

After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation …

Sep 9, 2025
CVE-2025-54240
5.5 MEDIUM

After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation …

Sep 9, 2025
CVE-2025-54239
5.5 MEDIUM

After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure, potentially disclosing sensitive information. Exploitation …

Sep 9, 2025
CVE-2025-44595
6.1 MEDIUM

Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.

Sep 9, 2025
CVE-2025-44593
6.1 MEDIUM

Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored …

Sep 9, 2025
CVE-2025-34178
5.4 MEDIUM

In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored …

Sep 9, 2025
CVE-2025-34177
5.4 MEDIUM

In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored …

Sep 9, 2025
CVE-2025-34176
4.3 MEDIUM

In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related strings/characters. This value is directly used in a file …

Sep 9, 2025
CVE-2025-58759
5.1 MEDIUM

TinyEnv is an environment variable loader for PHP applications. In versions 1.0.9 and 1.0.10, TinyEnv did not properly strip inline comments inside .env values. This …

Sep 9, 2025
CVE-2025-58758
5.1 MEDIUM

TinyEnv is an environment variable loader for PHP applications. In versions 1.0.1, 1.0.2, 1.0.9, and 1.0.10, TinyEnv did not require the `.env` file to exist …

Sep 9, 2025
CVE-2025-58442
5.3 MEDIUM

Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in …

Sep 9, 2025
CVE-2025-58430
6.1 MEDIUM

listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to the session …

Sep 9, 2025
CVE-2025-55054
6.1 MEDIUM

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Sep 9, 2025
CVE-2025-55053
6.5 MEDIUM

CWE-328: Use of Weak Hash

Sep 9, 2025
CVE-2025-54255
4.0 MEDIUM

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature …

Sep 9, 2025
CVE-2025-43786
5.3 MEDIUM

Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 …

Sep 9, 2025
CVE-2025-36125
6.4 MEDIUM

IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript …

Sep 9, 2025
CVE-2025-36011
4.3 MEDIUM

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to …

Sep 9, 2025
CVE-2025-34175
6.1 MEDIUM

In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting …

Sep 9, 2025
CVE-2025-34174
5.4 MEDIUM

In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being …

Sep 9, 2025
CVE-2025-34173
4.3 MEDIUM

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file …

Sep 9, 2025
CVE-2025-34172
6.1 MEDIUM

In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting …

Sep 9, 2025
CVE-2025-55052
4.3 MEDIUM

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Sep 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.