CVE Database

52406+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-9673
5.3 MEDIUM

A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the …

Aug 29, 2025
CVE-2025-9672
5.3 MEDIUM

A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file AndroidManifest.xml of the component de.hafas.android.rejseplanen. …

Aug 29, 2025
CVE-2025-9671
5.3 MEDIUM

A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file AndroidManifest.xml of the …

Aug 29, 2025
CVE-2025-9670
5.3 MEDIUM

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in …

Aug 29, 2025
CVE-2025-9667
6.3 MEDIUM

A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delete_account.php of the component Admin Panel. Performing …

Aug 29, 2025
CVE-2025-9666
6.3 MEDIUM

A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some unknown functionality of the file /delete_student.php of …

Aug 29, 2025
CVE-2025-9665
6.3 MEDIUM

A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_student.php of the …

Aug 29, 2025
CVE-2025-33038
6.5 MEDIUM

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Aug 29, 2025
CVE-2025-33037
6.5 MEDIUM

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Aug 29, 2025
CVE-2025-33036
6.5 MEDIUM

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Aug 29, 2025
CVE-2025-33033
6.5 MEDIUM

A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability …

Aug 29, 2025
CVE-2025-33032
4.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Aug 29, 2025
CVE-2025-30275
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Aug 29, 2025
CVE-2025-30274
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service …

Aug 29, 2025
CVE-2025-30272
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service …

Aug 29, 2025
CVE-2025-30271
6.5 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then …

Aug 29, 2025
CVE-2025-30270
6.5 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then …

Aug 29, 2025
CVE-2025-30268
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can …

Aug 29, 2025
CVE-2025-30267
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can …

Aug 29, 2025
CVE-2025-30265
6.5 MEDIUM

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then …

Aug 29, 2025
CVE-2025-30263
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Aug 29, 2025
CVE-2025-30262
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Aug 29, 2025
CVE-2025-30261
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Aug 29, 2025
CVE-2025-30260
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they …

Aug 29, 2025
CVE-2025-29900
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Aug 29, 2025
CVE-2025-29899
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Aug 29, 2025
CVE-2025-29898
6.5 MEDIUM

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the …

Aug 29, 2025
CVE-2025-29890
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, …

Aug 29, 2025
CVE-2025-29889
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29888
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29886
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29882
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can …

Aug 29, 2025
CVE-2025-9664
6.3 MEDIUM

A security flaw has been discovered in code-projects Simple Grading System 1.0. Affected is an unknown function of the file /add_student_grade.php of the component Admin …

Aug 29, 2025
CVE-2025-9663
6.3 MEDIUM

A vulnerability was identified in code-projects Simple Grading System 1.0. This impacts an unknown function of the file /edit_account.php of the component Admin Panel. The …

Aug 29, 2025
CVE-2025-55580
5.4 MEDIUM

SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in …

Aug 29, 2025
CVE-2025-55579
5.4 MEDIUM

SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.

Aug 29, 2025
CVE-2025-29879
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29878
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29875
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-29874
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit …

Aug 29, 2025
CVE-2025-22483
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Aug 29, 2025
CVE-2024-12923
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the …

Aug 29, 2025
CVE-2025-9656
4.3 MEDIUM

A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the …

Aug 29, 2025
CVE-2025-55750
6.5 MEDIUM

Gitpod is a developer platform for cloud development environments. In versions before main-gha.33628 for both Gitpod Classic and Gitpod Classic Enterprise, OAuth integration with Bitbucket …

Aug 29, 2025
CVE-2025-55202
5.3 MEDIUM

Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections …

Aug 29, 2025
CVE-2025-55177
5.4 MEDIUM KEV

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could …

Aug 29, 2025
CVE-2025-54877
5.3 MEDIUM

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise …

Aug 29, 2025
CVE-2025-9654
6.3 MEDIUM

A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simple.mjs. Performing …

Aug 29, 2025
CVE-2025-55304
5.5 MEDIUM

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A denial-of-service was …

Aug 29, 2025
CVE-2025-54080
5.5 MEDIUM

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read …

Aug 29, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.