CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-61161
8.4 HIGH

DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers …

Oct 29, 2025
CVE-2025-64284
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File …

Oct 29, 2025
CVE-2025-64216
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeSphere SmartMag smart-mag allows PHP Local File Inclusion.This issue …

Oct 29, 2025
CVE-2025-64195
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Eduma eduma allows PHP Local File Inclusion.This issue …

Oct 29, 2025
CVE-2025-60075
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS.This issue affects hpb seo plugin for WordPress: from …

Oct 29, 2025
CVE-2025-11702
8.5 HIGH

GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed …

Oct 29, 2025
CVE-2025-62776
7.8 HIGH

The installer of WTW EAGLE (for Windows) 3.0.8.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. …

Oct 29, 2025
CVE-2025-62801
7.8 HIGH

FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field …

Oct 28, 2025
CVE-2025-62727
7.5 HIGH

Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range …

Oct 28, 2025
CVE-2025-59837
7.2 HIGH

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed …

Oct 28, 2025
CVE-2025-12425
7.8 HIGH

Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Oct 28, 2025
CVE-2025-12423
7.5 HIGH

Protocol manipulation might lead to denial of service.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Oct 28, 2025
CVE-2025-60805
7.5 HIGH

An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.

Oct 28, 2025
CVE-2025-60800
7.5 HIGH

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

Oct 28, 2025
CVE-2025-60354
7.5 HIGH

Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.

Oct 28, 2025
CVE-2025-54605
7.5 HIGH

Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).

Oct 28, 2025
CVE-2025-54604
7.5 HIGH

Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).

Oct 28, 2025
CVE-2025-60858
7.5 HIGH

Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and transmits DDNS credentials in plaintext within its configuration and update scripts, allowing attackers to intercept or extract sensitive …

Oct 28, 2025
CVE-2025-60349
7.5 HIGH

An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver. Any …

Oct 28, 2025
CVE-2025-56399
8.8 HIGH

alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` …

Oct 28, 2025
CVE-2025-61107
7.5 HIGH

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause …

Oct 28, 2025
CVE-2025-61106
7.5 HIGH

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause …

Oct 28, 2025
CVE-2025-61104
7.5 HIGH

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause …

Oct 28, 2025
CVE-2025-61103
7.5 HIGH

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause …

Oct 28, 2025
CVE-2025-34312
8.8 HIGH

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' …

Oct 28, 2025
CVE-2025-34311
8.8 HIGH

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user …

Oct 28, 2025
CVE-2025-53855
7.8 HIGH

An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadein file can lead to …

Oct 28, 2025
CVE-2025-53814
7.8 HIGH

A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead to heap-based …

Oct 28, 2025
CVE-2025-40082
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() BUG: KASAN: slab-out-of-bounds in hfsplus_uni2asc+0xa71/0xb90 fs/hfsplus/unicode.c:186 Read of size …

Oct 28, 2025
CVE-2025-12378
7.3 HIGH

A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addproduct.php. Performing manipulation …

Oct 28, 2025
CVE-2025-11735
7.5 HIGH

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the `phrase` parameter in all versions up …

Oct 28, 2025
CVE-2025-62777
8.8 HIGH

Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to …

Oct 28, 2025
CVE-2025-12342
7.3 HIGH

A flaw has been found in Serdar Bayram Ghost Hot Spot up to 20251014. The affected element is an unknown function of the file /Auth.php …

Oct 28, 2025
CVE-2025-12341
7.8 HIGH

A vulnerability was detected in ermig1979 AntiDupl up to 2.3.12. Impacted is an unknown function of the file AntiDupl.NET.WinForms.exe of the component Delete Duplicate Image …

Oct 28, 2025
CVE-2025-12339
7.3 HIGH

A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The …

Oct 28, 2025
CVE-2025-12338
7.3 HIGH

A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation …

Oct 28, 2025
CVE-2025-12337
7.3 HIGH

A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing a …

Oct 28, 2025
CVE-2025-12336
7.3 HIGH

A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_index.php. Such …

Oct 28, 2025
CVE-2025-43024
7.5 HIGH

A GUI dialog of an application allows to view what files are in the file system without proper authorization.

Oct 28, 2025
CVE-2025-62260
7.5 HIGH

Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions …

Oct 27, 2025
CVE-2025-12326
7.3 HIGH

A vulnerability was found in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This vulnerability affects unknown code of the file /process.php of the component POST Request …

Oct 27, 2025
CVE-2025-12325
7.3 HIGH

A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/forgot-password.php. The manipulation of the …

Oct 27, 2025
CVE-2025-12322
8.8 HIGH

A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromNatStaticSetting of the file /goform/NatStaticSetting. Executing a manipulation of …

Oct 27, 2025
CVE-2025-12316
7.3 HIGH

A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argument OfficeName …

Oct 27, 2025
CVE-2025-61105
7.5 HIGH

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause …

Oct 27, 2025
CVE-2025-61102
7.5 HIGH

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause …

Oct 27, 2025
CVE-2025-61101
7.5 HIGH

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause …

Oct 27, 2025
CVE-2025-59151
8.2 HIGH

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable …

Oct 27, 2025
CVE-2025-61100
7.5 HIGH

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause …

Oct 27, 2025
CVE-2025-61099
7.5 HIGH

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause …

Oct 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.