CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60549
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAutoDetecWAN_wizard4.

Oct 24, 2025
CVE-2025-60547
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard7.

Oct 24, 2025
CVE-2025-60938
7.5 HIGH

Emoncms 11.7.3 has a remote code execution vulnerability in the firmware upload feature that allows authenticated users to execute arbitrary commands on the target system. …

Oct 24, 2025
CVE-2025-60572
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvNetwork.

Oct 24, 2025
CVE-2025-60571
7.5 HIGH

D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetQoS.

Oct 24, 2025
CVE-2025-60570
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLogDnsquery.

Oct 24, 2025
CVE-2025-60569
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.

Oct 24, 2025
CVE-2025-60568
7.5 HIGH

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.

Oct 24, 2025
CVE-2025-43994
8.6 HIGH

Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could …

Oct 24, 2025
CVE-2025-11145
7.5 HIGH

Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware …

Oct 24, 2025
CVE-2025-46183
8.2 HIGH

The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may result in …

Oct 24, 2025
CVE-2025-10861
7.5 HIGH

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up …

Oct 24, 2025
CVE-2025-10680
8.8 HIGH

OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use

Oct 24, 2025
CVE-2025-12028
8.8 HIGH

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing nonce …

Oct 24, 2025
CVE-2025-11889
7.2 HIGH

The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Oct 24, 2025
CVE-2025-11504
7.5 HIGH

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This …

Oct 24, 2025
CVE-2025-62868
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local File Inclusion.This issue …

Oct 24, 2025
CVE-2025-62254
7.5 HIGH

The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update …

Oct 23, 2025
CVE-2025-58429
7.5 HIGH

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-62688
7.1 HIGH

An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker with low-privileged credentials …

Oct 23, 2025
CVE-2025-62498
8.8 HIGH

A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity …

Oct 23, 2025
CVE-2025-61977
7.0 HIGH

A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an …

Oct 23, 2025
CVE-2025-59500
7.7 HIGH

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Oct 23, 2025
CVE-2025-59273
7.3 HIGH

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

Oct 23, 2025
CVE-2025-58078
7.5 HIGH

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService …

Oct 23, 2025
CVE-2025-12100
7.8 HIGH

Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6.

Oct 23, 2025
CVE-2025-55067
7.1 HIGH

The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When the system clock reaches January …

Oct 23, 2025
CVE-2025-54964
8.4 HIGH

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary …

Oct 23, 2025
CVE-2025-12044
7.5 HIGH

Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a …

Oct 23, 2025
CVE-2025-6980
7.5 HIGH

Captive Portal can expose sensitive information

Oct 23, 2025
CVE-2025-6979
8.8 HIGH

Captive Portal can allow authentication bypass

Oct 23, 2025
CVE-2025-6978
7.2 HIGH

Diagnostics command injection vulnerability

Oct 23, 2025
CVE-2025-54808
7.8 HIGH

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on …

Oct 23, 2025
CVE-2025-23352
7.8 HIGH

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitialized pointer access. A successful exploit of this …

Oct 23, 2025
CVE-2025-23347
7.8 HIGH

NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulnerability might lead to code …

Oct 23, 2025
CVE-2025-11621
8.1 HIGH

Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across …

Oct 23, 2025
CVE-2025-62169
8.1 HIGH

OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and …

Oct 23, 2025
CVE-2025-59048
8.1 HIGH

OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IAM role Impersonation …

Oct 23, 2025
CVE-2025-50950
7.5 HIGH

Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.

Oct 23, 2025
CVE-2025-61136
7.1 HIGH

A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover …

Oct 23, 2025
CVE-2025-61132
7.1 HIGH

A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attackers to conduct password reset poisoning and account takeover …

Oct 23, 2025
CVE-2025-62399
7.5 HIGH

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

Oct 23, 2025
CVE-2025-12105
7.5 HIGH

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. …

Oct 23, 2025
CVE-2025-10914
7.6 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Reflected …

Oct 23, 2025
CVE-2025-11575
7.8 HIGH

Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through …

Oct 23, 2025
CVE-2025-62708
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads …

Oct 22, 2025
CVE-2025-62707
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads …

Oct 22, 2025
CVE-2025-62617
7.2 HIGH

Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionality of …

Oct 22, 2025
CVE-2025-62610
8.1 HIGH

Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does …

Oct 22, 2025
CVE-2025-62513
7.5 HIGH

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used …

Oct 22, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.