CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-12943
7.5 HIGH

Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router) and RAXE300 (Nighthawk AXE7800 Tri-Band WiFi 6E Router) …

Nov 11, 2025
CVE-2025-12942
7.5 HIGH

Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to LAN with ability to perform MiTM attacks and control over …

Nov 11, 2025
CVE-2025-9408
8.1 HIGH

System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege escalation for …

Nov 11, 2025
CVE-2025-13027
8.1 HIGH

Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Nov 11, 2025
CVE-2025-13025
7.5 HIGH

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Nov 11, 2025
CVE-2025-13020
8.8 HIGH

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.

Nov 11, 2025
CVE-2025-13019
8.1 HIGH

Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.

Nov 11, 2025
CVE-2025-13018
8.1 HIGH

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.

Nov 11, 2025
CVE-2025-13017
8.1 HIGH

Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.

Nov 11, 2025
CVE-2025-13016
7.5 HIGH

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.

Nov 11, 2025
CVE-2025-13014
8.8 HIGH

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.

Nov 11, 2025
CVE-2025-13012
7.5 HIGH

Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.

Nov 11, 2025
CVE-2025-10918
7.1 HIGH

Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on …

Nov 11, 2025
CVE-2025-11959
8.1 HIGH

Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk Information Technologies Inc. Excavation Management Information …

Nov 11, 2025
CVE-2024-57695
7.7 HIGH

An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lock function. The …

Nov 11, 2025
CVE-2025-9223
8.8 HIGH

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action …

Nov 11, 2025
CVE-2025-10161
7.3 HIGH

Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on Untrusted Inputs in a Security Decision vulnerability in Turkguven Software Technologies Inc. …

Nov 11, 2025
CVE-2025-7633
7.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.

Nov 11, 2025
CVE-2025-7632
7.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.

Nov 11, 2025
CVE-2025-7430
7.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.

Nov 11, 2025
CVE-2025-12846
8.8 HIGH

The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is due to …

Nov 11, 2025
CVE-2025-7429
7.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.

Nov 11, 2025
CVE-2025-10714
8.4 HIGH

AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can …

Nov 11, 2025
CVE-2025-11855
7.5 HIGH

The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportRequest function, allowing any authenticated users, such as subscriber to create an admin …

Nov 11, 2025
CVE-2025-11307
8.8 HIGH

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users …

Nov 11, 2025
CVE-2025-12637
8.8 HIGH

The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation feature in the process_theme function in …

Nov 11, 2025
CVE-2025-11521
8.1 HIGH

The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs …

Nov 11, 2025
CVE-2025-11451
7.5 HIGH

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, …

Nov 11, 2025
CVE-2025-11168
8.8 HIGH

The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5. This is due to plugin not …

Nov 11, 2025
CVE-2025-42940
7.5 HIGH

SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed …

Nov 11, 2025
CVE-2025-64519
8.8 HIGH

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL injection vulnerability exists …

Nov 10, 2025
CVE-2025-63678
7.2 HIGH

An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute …

Nov 10, 2025
CVE-2025-11578
7.2 HIGH

A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by …

Nov 10, 2025
CVE-2025-64518
7.5 HIGH

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version …

Nov 10, 2025
CVE-2025-64512
8.6 HIGH

Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107, pdfminer.six will execute …

Nov 10, 2025
CVE-2025-64509
7.5 HIGH

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope can cause Bugsink to spend excessive CPU time …

Nov 10, 2025
CVE-2025-64508
7.5 HIGH

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli streams, such as many zeros) can be sent …

Nov 10, 2025
CVE-2025-64507
7.8 HIGH

Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment …

Nov 10, 2025
CVE-2025-64501
7.6 HIGH

ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and below, the `prosemirror_to_html` gem is vulnerable to Cross-Site Scripting …

Nov 10, 2025
CVE-2025-64484
8.5 HIGH

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load …

Nov 10, 2025
CVE-2025-64183
7.5 HIGH

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.2.0 through …

Nov 10, 2025
CVE-2025-64182
7.8 HIGH

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.2.0 through …

Nov 10, 2025
CVE-2025-64181
7.5 HIGH

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through …

Nov 10, 2025
CVE-2025-64167
7.1 HIGH

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading to …

Nov 10, 2025
CVE-2025-49145
8.7 HIGH

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create …

Nov 10, 2025
CVE-2025-48065
8.8 HIGH

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with …

Nov 10, 2025
CVE-2025-48055
8.5 HIGH

Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user …

Nov 10, 2025
CVE-2025-63149
7.5 HIGH

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list_Info function. This vulnerability allows attackers to cause a …

Nov 10, 2025
CVE-2025-47932
8.8 HIGH

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is …

Nov 10, 2025
CVE-2025-12727
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Nov 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.