CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-63454
7.5 HIGH

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentControl_list_Info function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-62618
8.0 HIGH

ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the …

Oct 31, 2025
CVE-2025-63459
7.5 HIGH

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_421CF0 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63465
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_422880 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63464
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_42396C function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63463
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the wifiOff parameter in the sub_4232EC function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63462
7.5 HIGH

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the wifiOff parameter in the sub_421A04 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63461
7.5 HIGH

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63460
7.5 HIGH

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63469
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_421BAC function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63468
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63467
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-63466
7.5 HIGH

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the sub_426EF8 function. This vulnerability allows attackers to cause a …

Oct 31, 2025
CVE-2025-12509
8.4 HIGH

On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator …

Oct 31, 2025
CVE-2025-12508
8.4 HIGH

When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to the interception of authentication data and compromise …

Oct 31, 2025
CVE-2025-12507
8.8 HIGH

The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs …

Oct 31, 2025
CVE-2025-64168
7.1 HIGH

Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team …

Oct 31, 2025
CVE-2025-60749
7.8 HIGH

DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.

Oct 31, 2025
CVE-2025-57107
7.1 HIGH

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor …

Oct 31, 2025
CVE-2025-57106
7.5 HIGH

Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF …

Oct 31, 2025
CVE-2025-12501
7.5 HIGH

Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-service attacks (DoS). GameMaker users who use the …

Oct 31, 2025
CVE-2025-33003
7.8 HIGH

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabilities within the scope of a container due to execution …

Oct 31, 2025
CVE-2025-64366
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy …

Oct 31, 2025
CVE-2025-64364
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Masterstudy masterstudy allows PHP Local File Inclusion.This issue …

Oct 31, 2025
CVE-2025-64363
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeventhQueen Kleo kleo allows PHP Local File Inclusion.This issue …

Oct 31, 2025
CVE-2025-64360
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File …

Oct 31, 2025
CVE-2025-64359
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting consulting allows PHP Local File Inclusion.This issue …

Oct 31, 2025
CVE-2025-64353
8.8 HIGH

Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3.

Oct 31, 2025
CVE-2025-58149
7.5 HIGH

When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a …

Oct 31, 2025
CVE-2025-58148
7.5 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of …

Oct 31, 2025
CVE-2025-58147
7.5 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hypercalls can specify a mask of …

Oct 31, 2025
CVE-2025-12115
7.5 HIGH

The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versions up to, and including, 2.1.9. This …

Oct 31, 2025
CVE-2025-62232
7.5 HIGH

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level …

Oct 31, 2025
CVE-2025-30189
7.4 HIGH

When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. …

Oct 31, 2025
CVE-2025-30188
7.5 HIGH

Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate …

Oct 31, 2025
CVE-2025-10897
8.6 HIGH

The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible …

Oct 31, 2025
CVE-2025-7846
8.8 HIGH

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in …

Oct 31, 2025
CVE-2025-54763
7.2 HIGH

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web …

Oct 31, 2025
CVE-2025-8849
7.5 HIGH

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key` and `value` …

Oct 31, 2025
CVE-2025-6176
7.5 HIGH

Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection …

Oct 31, 2025
CVE-2025-52664
8.8 HIGH

SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users

Oct 31, 2025
CVE-2025-52663
7.3 HIGH

A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to …

Oct 31, 2025
CVE-2025-48984
8.8 HIGH

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

Oct 31, 2025
CVE-2025-48982
7.8 HIGH

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.

Oct 31, 2025
CVE-2025-34298
8.8 HIGH

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to …

Oct 30, 2025
CVE-2025-34287
7.8 HIGH

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because …

Oct 30, 2025
CVE-2025-34286
7.2 HIGH

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters …

Oct 30, 2025
CVE-2025-34284
8.8 HIGH

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to …

Oct 30, 2025
CVE-2025-34280
7.2 HIGH

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate …

Oct 30, 2025
CVE-2025-34134
7.2 HIGH

Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled …

Oct 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.