CVE Database

52406+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-41048
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41047
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41046
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41045
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41044
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41043
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41042
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41041
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41040
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41039
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41038
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41037
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41036
5.4 MEDIUM

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user …

Sep 4, 2025
CVE-2025-41035
6.5 MEDIUM

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions …

Sep 4, 2025
CVE-2022-39888
4.3 MEDIUM

Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.

Sep 4, 2025
CVE-2025-9942
6.3 MEDIUM

A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulation leads to …

Sep 4, 2025
CVE-2025-9941
6.3 MEDIUM

A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the …

Sep 4, 2025
CVE-2025-9937
5.4 MEDIUM

A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulation results in improper authorization. …

Sep 4, 2025
CVE-2025-9936
4.3 MEDIUM

A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The …

Sep 4, 2025
CVE-2025-9934
6.3 MEDIUM

A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument pid results in …

Sep 4, 2025
CVE-2025-9931
4.3 MEDIUM

A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation …

Sep 4, 2025
CVE-2025-9616
5.3 MEDIUM

The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or …

Sep 4, 2025
CVE-2025-9516
4.9 MEDIUM

The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This …

Sep 4, 2025
CVE-2025-36909
5.3 MEDIUM

Information disclosure

Sep 4, 2025
CVE-2025-36908
6.7 MEDIUM

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36902
6.7 MEDIUM

In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 4, 2025
CVE-2025-36900
6.7 MEDIUM

In lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalation of privilege with System …

Sep 4, 2025
CVE-2025-36893
5.5 MEDIUM

In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution …

Sep 4, 2025
CVE-2024-56189
6.5 MEDIUM

In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Sep 4, 2025
CVE-2024-13073
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft TaskPano allows Cross-Site Scripting (XSS).This issue affects TaskPano: s1.06.04.

Sep 4, 2025
CVE-2024-13071
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft e-Mutabakat allows Cross-Site Scripting (XSS).This issue affects e-Mutabakat: from 2.02.05 …

Sep 4, 2025
CVE-2025-8268
6.5 MEDIUM

The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the rest_list and …

Sep 3, 2025
CVE-2025-56139
5.3 MEDIUM

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a …

Sep 3, 2025
CVE-2025-55162
6.3 MEDIUM

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In versions below 1.32.10 and 1.33.0 through 1.33.6, …

Sep 3, 2025
CVE-2025-9923
4.3 MEDIUM

A flaw has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /index.php. Executing manipulation of the …

Sep 3, 2025
CVE-2025-20336
5.3 MEDIUM

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Sep 3, 2025
CVE-2025-20335
5.3 MEDIUM

A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Sep 3, 2025
CVE-2025-20330
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker …

Sep 3, 2025
CVE-2025-20328
5.4 MEDIUM

A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site …

Sep 3, 2025
CVE-2025-20326
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could …

Sep 3, 2025
CVE-2025-20291
4.3 MEDIUM

A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco …

Sep 3, 2025
CVE-2025-20287
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to …

Sep 3, 2025
CVE-2025-20280
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Sep 3, 2025
CVE-2025-20270
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to …

Sep 3, 2025
CVE-2025-9922
4.3 MEDIUM

A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. …

Sep 3, 2025
CVE-2025-9867
5.4 MEDIUM

Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Sep 3, 2025
CVE-2025-9865
5.4 MEDIUM

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI …

Sep 3, 2025
CVE-2025-56761
5.4 MEDIUM

Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content …

Sep 3, 2025
CVE-2025-56760
4.3 MEDIUM

When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in …

Sep 3, 2025
CVE-2025-56689
4.6 MEDIUM

One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker …

Sep 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.