CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11943
7.3 HIGH

A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. …

Oct 19, 2025
CVE-2025-11942
7.3 HIGH

A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to …

Oct 19, 2025
CVE-2025-11940
7.0 HIGH

A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of the file assets/setup.nsi of the component …

Oct 19, 2025
CVE-2025-47410
8.8 HIGH

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked …

Oct 18, 2025
CVE-2025-9890
8.8 HIGH

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing …

Oct 18, 2025
CVE-2025-5555
7.8 HIGH

A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the …

Oct 18, 2025
CVE-2025-11691
7.5 HIGH

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() function in all versions …

Oct 18, 2025
CVE-2025-11517
7.5 HIGH

The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to …

Oct 18, 2025
CVE-2020-36853
7.2 HIGH

The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient …

Oct 18, 2025
CVE-2025-62650
8.3 HIGH

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.

Oct 17, 2025
CVE-2025-62422
8.8 HIGH

DataEase is an open source data visualization and analytics platform. In versions 2.10.13 and earlier, the /de2api/datasetData/tableField interface is vulnerable to SQL injection. An attacker …

Oct 17, 2025
CVE-2025-62420
8.8 HIGH

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database connection handler. …

Oct 17, 2025
CVE-2025-62419
7.5 HIGH

DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data …

Oct 17, 2025
CVE-2025-62356
7.5 HIGH

A path traversal vulnerability in all versions of the Qodo Qodo Gen IDE enables a threat actor to read arbitrary local files in and outside …

Oct 17, 2025
CVE-2025-59043
7.5 HIGH

OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than …

Oct 17, 2025
CVE-2025-55085
7.5 HIGH

In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was …

Oct 17, 2025
CVE-2025-55094
7.5 HIGH

In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when …

Oct 17, 2025
CVE-2025-55087
7.5 HIGH

In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted …

Oct 17, 2025
CVE-2025-11899
8.1 HIGH

Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, …

Oct 17, 2025
CVE-2025-11898
7.5 HIGH

Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

Oct 17, 2025
CVE-2025-62506
8.1 HIGH

MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege escalation vulnerability allows service accounts and STS (Security Token Service) …

Oct 16, 2025
CVE-2025-11864
7.3 HIGH

A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply of the file /src/cluster.ts of the component Outbound …

Oct 16, 2025
CVE-2025-62425
8.3 HIGH

MAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 …

Oct 16, 2025
CVE-2025-62417
7.8 HIGH

Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) …

Oct 16, 2025
CVE-2025-61553
8.2 HIGH

An out-of-bounds write in VirtIO network device emulation in BitVisor from commit 108df6 (2020-05-20) to commit 480907 (2025-07-06) allows local attackers to cause a denial …

Oct 16, 2025
CVE-2025-11493
8.8 HIGH

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a …

Oct 16, 2025
CVE-2025-62409
7.5 HIGH

Envoy is a cloud-native, open source edge and service proxy. Prior to 1.36.1, 1.35.5, 1.34.9, and 1.33.10, large requests and responses can potentially trigger TCP …

Oct 16, 2025
CVE-2025-34519
7.5 HIGH

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an insecure hashing algorithm vulnerability. The product stores passwords using the MD5 hash function without applying …

Oct 16, 2025
CVE-2025-34518
7.5 HIGH

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia …

Oct 16, 2025
CVE-2025-34517
7.5 HIGH

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia …

Oct 16, 2025
CVE-2025-34514
8.8 HIGH

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain authenticated OS command injection vulnerabilities in multiple web-accessible PHP scripts that call exec() and allow an …

Oct 16, 2025
CVE-2025-36128
7.5 HIGH

IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout …

Oct 16, 2025
CVE-2025-62496
8.8 HIGH

A vulnerability exists in the QuickJS engine's BigInt string parsing logic (js_bigint_from_string) when attempting to create a BigInt from a string with an excessively large …

Oct 16, 2025
CVE-2025-62495
8.8 HIGH

An integer overflow vulnerability exists in the QuickJS regular expression engine (libregexp) due to an inconsistent representation of the bytecode buffer size. * The regular …

Oct 16, 2025
CVE-2025-62494
8.8 HIGH

A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The code first checks if the …

Oct 16, 2025
CVE-2025-62491
8.8 HIGH

A Use-After-Free (UAF) vulnerability exists in the QuickJS engine's standard library when iterating over the global list of unhandled rejected promises (ts->rejected_promise_list). * The function …

Oct 16, 2025
CVE-2025-62490
8.8 HIGH

In quickjs, in js_print_object, when printing an array, the function first fetches the array length and then loops over it. The issue is, printing a …

Oct 16, 2025
CVE-2024-56143
8.2 HIGH

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not …

Oct 16, 2025
CVE-2025-61543
7.1 HIGH

A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent …

Oct 16, 2025
CVE-2025-61541
7.1 HIGH

Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the …

Oct 16, 2025
CVE-2025-61536
8.2 HIGH

FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` …

Oct 16, 2025
CVE-2025-41253
7.5 HIGH

The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An …

Oct 16, 2025
CVE-2025-22381
8.2 HIGH

Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.

Oct 16, 2025
CVE-2025-54658
7.8 HIGH

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS 11.5.1 and 11.4.2 …

Oct 16, 2025
CVE-2025-61581
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. People with access …

Oct 16, 2025
CVE-2025-58075
8.1 HIGH

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the …

Oct 16, 2025
CVE-2025-58073
8.1 HIGH

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the …

Oct 16, 2025
CVE-2025-41020
7.5 HIGH

Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' …

Oct 16, 2025
CVE-2025-62585
7.5 HIGH

Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.

Oct 16, 2025
CVE-2025-62584
7.5 HIGH

Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.

Oct 16, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.