CVE Database

57948+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-13261
5.3 MEDIUM

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version …

Nov 17, 2025
CVE-2025-13260
6.3 MEDIUM

A vulnerability has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /manufacturer/edit_product.php. Such manipulation of the argument …

Nov 17, 2025
CVE-2025-13259
6.3 MEDIUM

A flaw has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /manufacturer/edit_unit.php. This manipulation of the argument …

Nov 17, 2025
CVE-2025-13256
6.3 MEDIUM

A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrow.php. Executing a manipulation of …

Nov 17, 2025
CVE-2025-13255
6.3 MEDIUM

A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing a …

Nov 17, 2025
CVE-2025-13254
6.3 MEDIUM

A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /add_member.php. Such manipulation of the argument …

Nov 17, 2025
CVE-2025-13253
6.3 MEDIUM

A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /add_librarian.php. This manipulation of the argument …

Nov 17, 2025
CVE-2025-13251
6.3 MEDIUM

A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can lead to sql injection. The attack …

Nov 16, 2025
CVE-2025-13250
6.3 MEDIUM

A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job Handler. Performing manipulation results in improper …

Nov 16, 2025
CVE-2025-13249
6.3 MEDIUM

A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTemplate=false of the component OfficeServer …

Nov 16, 2025
CVE-2025-13246
6.3 MEDIUM

A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthenticationFilter of the file src/main/java/com/suisung/shopsuite/common/security/JwtAuthenticationFilter.java. The manipulation leads to path …

Nov 16, 2025
CVE-2025-13244
4.3 MEDIUM

A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown function of the file /register.php. This manipulation causes cross …

Nov 16, 2025
CVE-2025-13243
6.3 MEDIUM

A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /editprofile.php. The manipulation results in sql injection. …

Nov 16, 2025
CVE-2025-13239
4.3 MEDIUM

A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of …

Nov 16, 2025
CVE-2025-13238
6.3 MEDIUM

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the …

Nov 16, 2025
CVE-2025-13236
6.3 MEDIUM

A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID …

Nov 16, 2025
CVE-2025-13234
6.3 MEDIUM

A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the …

Nov 16, 2025
CVE-2025-13221
5.3 MEDIUM

A weakness has been identified in Intelbras UnniTI 24.07.11. The affected element is an unknown function of the file /xml/sistema/usuarios.xml. Executing manipulation of the argument …

Nov 15, 2025
CVE-2025-13210
4.7 MEDIUM

A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the …

Nov 15, 2025
CVE-2025-13209
6.3 MEDIUM

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument …

Nov 15, 2025
CVE-2025-13208
6.3 MEDIUM

A security flaw has been discovered in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. The impacted element is an unknown function of the file controller/api/hotelList.php. The …

Nov 15, 2025
CVE-2025-13200
5.3 MEDIUM

A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of information through …

Nov 15, 2025
CVE-2025-13199
5.3 MEDIUM

A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username …

Nov 15, 2025
CVE-2025-13198
4.7 MEDIUM

A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the …

Nov 15, 2025
CVE-2025-7000
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific …

Nov 15, 2025
CVE-2025-6171
5.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have …

Nov 15, 2025
CVE-2025-2615
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have …

Nov 15, 2025
CVE-2025-11865
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain …

Nov 15, 2025
CVE-2025-12849
5.3 MEDIUM

The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin …

Nov 15, 2025
CVE-2025-8994
6.5 MEDIUM

The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL …

Nov 15, 2025
CVE-2025-12847
4.3 MEDIUM

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media …

Nov 15, 2025
CVE-2025-12494
4.3 MEDIUM

The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in …

Nov 15, 2025
CVE-2025-12182
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize_image_callback()` function in all versions up …

Nov 15, 2025
CVE-2025-8386
6.9 MEDIUM

The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting …

Nov 15, 2025
CVE-2025-64307
6.5 MEDIUM

The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, …

Nov 15, 2025
CVE-2023-7328
5.3 MEDIUM

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to …

Nov 14, 2025
CVE-2025-13187
5.3 MEDIUM

A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess …

Nov 14, 2025
CVE-2025-64084
5.4 MEDIUM

An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in application/controllers/Awards.php does not properly sanitize the user-supplied Gridsquare POST parameter. …

Nov 14, 2025
CVE-2025-63745
5.5 MEDIUM

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_ne.c. A crafted binary input can trigger a …

Nov 14, 2025
CVE-2025-63744
4.3 MEDIUM

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a …

Nov 14, 2025
CVE-2025-13185
4.7 MEDIUM

A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. The manipulation of the …

Nov 14, 2025
CVE-2025-63701
6.8 MEDIUM

A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.20789) when DocumentPropertiesW() is called with a valid dmDriverExtra value but an undersized …

Nov 14, 2025
CVE-2025-13179
4.3 MEDIUM

A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects some unknown processing. Such manipulation …

Nov 14, 2025
CVE-2025-63291
5.4 MEDIUM

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by the caller. The …

Nov 14, 2025
CVE-2025-13177
4.3 MEDIUM

A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can …

Nov 14, 2025
CVE-2025-13174
6.3 MEDIUM

A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function do_job of the file /rachelos/we-mp-rss/blob/main/jobs/mps.py of …

Nov 14, 2025
CVE-2025-63830
6.1 MEDIUM

CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.

Nov 14, 2025
CVE-2025-63725
6.1 MEDIUM

Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php.

Nov 14, 2025
CVE-2025-63724
6.0 MEDIUM

SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php.

Nov 14, 2025
CVE-2025-54562
4.3 MEDIUM

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Technical Information to be Disclosed through stack …

Nov 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.