CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64324
7.7 HIGH

KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user …

Nov 18, 2025
CVE-2025-62406
8.1 HIGH

Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset …

Nov 18, 2025
CVE-2025-63215
7.2 HIGH

The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate …

Nov 18, 2025
CVE-2025-63227
7.2 HIGH

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials …

Nov 18, 2025
CVE-2025-37161
7.5 HIGH

A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation could …

Nov 18, 2025
CVE-2025-63955
7.5 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into …

Nov 18, 2025
CVE-2025-61662
7.8 HIGH

A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory …

Nov 18, 2025
CVE-2025-60455
8.4 HIGH

Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.

Nov 18, 2025
CVE-2025-37163
7.2 HIGH

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this …

Nov 18, 2025
CVE-2025-37155
7.8 HIGH

A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this …

Nov 18, 2025
CVE-2025-64076
7.5 HIGH

Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read …

Nov 18, 2025
CVE-2025-63829
7.5 HIGH

eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction() function.

Nov 18, 2025
CVE-2025-58692
8.8 HIGH

An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through …

Nov 18, 2025
CVE-2025-58413
7.5 HIGH

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 …

Nov 18, 2025
CVE-2025-58034
7.2 HIGH KEV

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 …

Nov 18, 2025
CVE-2025-56527
7.5 HIGH

Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.

Nov 18, 2025
CVE-2025-55796
7.5 HIGH

The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confirmation resends, and email …

Nov 18, 2025
CVE-2025-53843
7.5 HIGH

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 …

Nov 18, 2025
CVE-2025-47761
7.8 HIGH

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local …

Nov 18, 2025
CVE-2025-46373
7.8 HIGH

A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.8 may allow an authenticated local IPSec user to …

Nov 18, 2025
CVE-2025-34324
7.8 HIGH

GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The manifest contains package URLs and SHA-256 hashes but is …

Nov 18, 2025
CVE-2025-33184
7.8 HIGH

NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successful exploit of …

Nov 18, 2025
CVE-2025-33183
7.8 HIGH

NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successful exploit of …

Nov 18, 2025
CVE-2025-63800
7.5 HIGH

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing …

Nov 18, 2025
CVE-2025-63602
7.3 HIGH

A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an …

Nov 18, 2025
CVE-2025-63408
7.8 HIGH

Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a …

Nov 18, 2025
CVE-2025-12383
7.4 HIGH

In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, …

Nov 18, 2025
CVE-2025-59113
7.5 HIGH

Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored on the server, which allows …

Nov 18, 2025
CVE-2025-6670
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin …

Nov 18, 2025
CVE-2025-13344
7.3 HIGH

A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=login. This …

Nov 18, 2025
CVE-2025-41737
7.5 HIGH

Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.

Nov 18, 2025
CVE-2025-41736
8.8 HIGH

A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in …

Nov 18, 2025
CVE-2025-41735
8.8 HIGH

A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.

Nov 18, 2025
CVE-2025-4212
7.2 HIGH

The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, …

Nov 18, 2025
CVE-2025-13069
8.8 HIGH

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This …

Nov 18, 2025
CVE-2025-12955
7.5 HIGH

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due …

Nov 18, 2025
CVE-2025-13088
8.8 HIGH

The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0. This is …

Nov 18, 2025
CVE-2025-12775
8.8 HIGH

The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 1.1.0 via the `ajax_upload_handle` function. …

Nov 18, 2025
CVE-2025-12528
8.1 HIGH

The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic …

Nov 18, 2025
CVE-2025-12411
7.1 HIGH

The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' parameter in versions up to, and including, 1.1.10. …

Nov 18, 2025
CVE-2025-11620
7.2 HIGH

The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mrpu_add_multiple_roles_ui' and …

Nov 18, 2025
CVE-2025-8727
7.2 HIGH

There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a …

Nov 18, 2025
CVE-2025-8076
7.2 HIGH

There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a …

Nov 18, 2025
CVE-2025-10089
7.7 HIGH

Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, …

Nov 18, 2025
CVE-2025-48593
8.0 HIGH

In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with …

Nov 18, 2025
CVE-2025-12974
8.1 HIGH

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in …

Nov 18, 2025
CVE-2025-8693
8.8 HIGH

A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an authenticated attacker to execute operating …

Nov 18, 2025
CVE-2025-13323
7.3 HIGH

A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Performing manipulation of …

Nov 18, 2025
CVE-2025-13230
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Nov 18, 2025
CVE-2025-13229
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Nov 18, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.