CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43419
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, …

Nov 4, 2025
CVE-2025-43413
7.5 HIGH

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, …

Nov 4, 2025
CVE-2025-43407
7.8 HIGH

This issue was addressed with improved entitlements. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe …

Nov 4, 2025
CVE-2025-43405
7.5 HIGH

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app …

Nov 4, 2025
CVE-2025-43401
7.5 HIGH

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A remote attacker …

Nov 4, 2025
CVE-2025-43399
7.5 HIGH

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Tahoe …

Nov 4, 2025
CVE-2025-43387
7.8 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. A malicious app may be able …

Nov 4, 2025
CVE-2025-43386
7.8 HIGH

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, …

Nov 4, 2025
CVE-2025-43376
7.5 HIGH

A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7.7, iOS 26 and iPadOS …

Nov 4, 2025
CVE-2025-43373
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may …

Nov 4, 2025
CVE-2025-43364
7.8 HIGH

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.1. An app may …

Nov 4, 2025
CVE-2025-43361
7.8 HIGH

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, …

Nov 4, 2025
CVE-2025-43338
7.1 HIGH

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Sonoma …

Nov 4, 2025
CVE-2025-43323
8.1 HIGH

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, …

Nov 4, 2025
CVE-2024-13997
7.2 HIGH

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root …

Nov 3, 2025
CVE-2025-50735
7.5 HIGH

Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing …

Nov 3, 2025
CVE-2025-12531
7.1 HIGH

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could …

Nov 3, 2025
CVE-2025-63441
7.3 HIGH

Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.

Nov 3, 2025
CVE-2025-10280
7.1 HIGH

IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions …

Nov 3, 2025
CVE-2025-60785
8.8 HIGH

A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a crafted …

Nov 3, 2025
CVE-2025-60503
8.7 HIGH

A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper …

Nov 3, 2025
CVE-2025-11761
7.8 HIGH

A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. …

Nov 3, 2025
CVE-2025-48397
7.1 HIGH

The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch …

Nov 3, 2025
CVE-2025-48396
8.3 HIGH

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the …

Nov 3, 2025
CVE-2025-12622
8.8 HIGH

A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd of the file /goform/SysRunCmd. This manipulation of the argument …

Nov 3, 2025
CVE-2025-12619
8.8 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/openNetworkGateway. The manipulation of the argument wpapsk_crypto2_4g results in …

Nov 3, 2025
CVE-2025-12618
8.8 HIGH

A vulnerability has been found in Tenda AC8 16.03.34.06. This impacts an unknown function of the file /goform/DatabaseIniSet. The manipulation of the argument Time leads …

Nov 3, 2025
CVE-2025-12617
7.3 HIGH

A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument …

Nov 3, 2025
CVE-2025-12611
8.8 HIGH

A vulnerability was identified in Tenda AC21 16.03.08.16. This vulnerability affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument startIp leads …

Nov 3, 2025
CVE-2025-12608
7.3 HIGH

A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing …

Nov 3, 2025
CVE-2025-12607
7.3 HIGH

A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument …

Nov 3, 2025
CVE-2025-12606
7.3 HIGH

A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the …

Nov 3, 2025
CVE-2025-12605
7.3 HIGH

A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument …

Nov 2, 2025
CVE-2025-12604
7.3 HIGH

A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the …

Nov 2, 2025
CVE-2025-12596
8.8 HIGH

A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation of the argument Time …

Nov 2, 2025
CVE-2025-12595
8.8 HIGH

A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /goform/SetVirtualServerCfg. This manipulation of the argument list causes …

Nov 2, 2025
CVE-2025-12601
7.5 HIGH

Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Nov 1, 2025
CVE-2025-36367
8.8 HIGH

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious …

Nov 1, 2025
CVE-2025-6990
8.8 HIGH

The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.0 via the `TH_PhpCode` pagebuilder widget. This …

Nov 1, 2025
CVE-2025-6574
8.8 HIGH

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is …

Nov 1, 2025
CVE-2025-12171
8.8 HIGH

The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ingest_image() function in versions …

Nov 1, 2025
CVE-2025-11755
8.8 HIGH

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when importing recipes via …

Nov 1, 2025
CVE-2025-10487
7.3 HIGH

The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.12 …

Nov 1, 2025
CVE-2025-5949
8.8 HIGH

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is …

Nov 1, 2025
CVE-2025-11995
7.2 HIGH

The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due …

Nov 1, 2025
CVE-2025-11920
8.8 HIGH

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in …

Nov 1, 2025
CVE-2025-63561
7.5 HIGH

Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where …

Oct 31, 2025
CVE-2025-64349
8.8 HIGH

ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and …

Oct 31, 2025
CVE-2025-64348
7.1 HIGH

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with …

Oct 31, 2025
CVE-2025-63458
7.5 HIGH

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a …

Oct 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.