CVE Database

52406+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-33102
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Sep 1, 2025
CVE-2025-33099
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate …

Sep 1, 2025
CVE-2025-33084
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Sep 1, 2025
CVE-2025-33083
5.4 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web …

Sep 1, 2025
CVE-2025-33082
5.4 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web …

Sep 1, 2025
CVE-2025-0656
6.1 MEDIUM

IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web …

Sep 1, 2025
CVE-2024-12924
6.3 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing.This issue affects QR Menü: from s1.05.05 before v1.05.12.

Sep 1, 2025
CVE-2024-12914
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR Menü allows Cross-Site Scripting (XSS).This issue affects QR Menü: …

Sep 1, 2025
CVE-2025-36133
5.9 MEDIUM

IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files …

Sep 1, 2025
CVE-2025-9774
4.3 MEDIUM

A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patients/edit-patient.php. The manipulation of the argument …

Sep 1, 2025
CVE-2025-9773
4.3 MEDIUM

A flaw has been found in RemoteClinic up to 2.0. This vulnerability affects unknown code of the file /staff/edit.php. Executing manipulation of the argument Last …

Sep 1, 2025
CVE-2025-9769
4.1 MEDIUM

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr …

Sep 1, 2025
CVE-2025-9768
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sports Management System 1.0. This impacts an unknown function of the file /Admin/mode.php. The manipulation of the argument code …

Sep 1, 2025
CVE-2025-20707
6.7 MEDIUM

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Sep 1, 2025
CVE-2025-20703
6.5 MEDIUM

In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if …

Sep 1, 2025
CVE-2025-9760
6.3 MEDIUM

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Matricula API. …

Sep 1, 2025
CVE-2025-9758
6.3 MEDIUM

A vulnerability was identified in deepakmisal24 Chemical Inventory Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory_form.php. …

Sep 1, 2025
CVE-2025-9570
4.9 MEDIUM

The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download …

Sep 1, 2025
CVE-2025-9569
6.1 MEDIUM

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Sep 1, 2025
CVE-2025-9568
6.1 MEDIUM

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Sep 1, 2025
CVE-2025-9567
6.1 MEDIUM

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing …

Sep 1, 2025
CVE-2025-9756
6.3 MEDIUM

A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid …

Sep 1, 2025
CVE-2025-9755
4.3 MEDIUM

A vulnerability has been found in Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24. This affects an unknown function of the file /index.php. The manipulation of …

Sep 1, 2025
CVE-2025-9747
4.3 MEDIUM

A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request …

Aug 31, 2025
CVE-2025-9745
4.7 MEDIUM

A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. …

Aug 31, 2025
CVE-2025-9732
5.3 MEDIUM

A vulnerability was identified in DCMTK up to 3.6.9. This affects an unknown function in the library dcmimage/include/dcmtk/dcmimage/diybrpxt.h of the component dcm2img. Such manipulation leads …

Aug 31, 2025
CVE-2025-9728
4.3 MEDIUM

A security vulnerability has been detected in givanz Vvveb 1.0.7.2. This affects an unknown part of the file app/template/user/login.tpl. Such manipulation of the argument Email/Password …

Aug 31, 2025
CVE-2025-9727
6.3 MEDIUM

A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulation of the …

Aug 31, 2025
CVE-2025-5083
5.5 MEDIUM

The Amministrazione Trasparente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.0 due to …

Aug 31, 2025
CVE-2025-9695
5.3 MEDIUM

A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file …

Aug 30, 2025
CVE-2025-9690
6.3 MEDIUM

A flaw has been found in SourceCodester Advanced School Management System 1.0. This affects an unknown function of the file /index.php/stock/vendordetails. This manipulation of the …

Aug 30, 2025
CVE-2025-9689
6.3 MEDIUM

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/stock/item_select. The manipulation of …

Aug 30, 2025
CVE-2025-9688
5.0 MEDIUM

A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_viewer of the file src/device/cart/is_viewer.c. The manipulation leads …

Aug 30, 2025
CVE-2025-9687
6.3 MEDIUM

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoApi. Executing manipulation can lead to …

Aug 30, 2025
CVE-2025-9686
6.3 MEDIUM

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/AreaConhecimento/edit of the component …

Aug 30, 2025
CVE-2025-9685
6.3 MEDIUM

A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/AreaConhecimento/view of the component Listagem de áreas …

Aug 30, 2025
CVE-2025-9684
6.3 MEDIUM

A vulnerability was determined in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/FormulaMedia/edit of the component Formula de Cálculo …

Aug 30, 2025
CVE-2025-9500
6.4 MEDIUM

The TablePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode_debug’ parameter in all versions up to, and including, 3.2 due to …

Aug 30, 2025
CVE-2025-9499
6.4 MEDIUM

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library shortcode in all versions up to, and including, 2.4.9 …

Aug 30, 2025
CVE-2025-9618
4.3 MEDIUM

The Related Posts Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to …

Aug 30, 2025
CVE-2025-4956
4.3 MEDIUM

Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a …

Aug 30, 2025
CVE-2025-57822
6.5 MEDIUM

Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request …

Aug 29, 2025
CVE-2025-57752
6.2 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes …

Aug 29, 2025
CVE-2025-55173
4.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization is vulnerable …

Aug 29, 2025
CVE-2025-9677
5.3 MEDIUM

A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown function of the file …

Aug 29, 2025
CVE-2025-9676
5.3 MEDIUM

A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidManifest.xml of the component com.ncsoft.universeapp. The …

Aug 29, 2025
CVE-2025-9675
5.3 MEDIUM

A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.tuyangkeji.changevoice. …

Aug 29, 2025
CVE-2025-9674
5.3 MEDIUM

A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the …

Aug 29, 2025
CVE-2025-58067
4.2 MEDIUM

Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect a user to another origin if the …

Aug 29, 2025
CVE-2025-58066
5.3 MEDIUM

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1.2.0 and 1.6.1 inclusive servers which allow …

Aug 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.