CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-11601
7.3 HIGH

A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing manipulation …

Oct 11, 2025
CVE-2025-11599
7.3 HIGH

A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown function of the file /forgot-password.php. This manipulation of …

Oct 11, 2025
CVE-2025-8593
8.8 HIGH

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to …

Oct 11, 2025
CVE-2025-11596
7.3 HIGH

A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of the file /pages/delete_order_details.php. Executing manipulation of the argument …

Oct 11, 2025
CVE-2025-58299
8.4 HIGH

Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58298
7.3 HIGH

Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.

Oct 11, 2025
CVE-2025-58287
7.8 HIGH

Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality.

Oct 11, 2025
CVE-2025-31718
7.5 HIGH

In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of privilege with no additional execution …

Oct 11, 2025
CVE-2025-31717
7.5 HIGH

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

Oct 11, 2025
CVE-2025-8093
8.8 HIGH

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.

Oct 10, 2025
CVE-2025-62162
7.5 HIGH

cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.11.4, parsing certain malformed CEL expressions can …

Oct 10, 2025
CVE-2025-11586
8.8 HIGH

A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based …

Oct 10, 2025
CVE-2025-11585
7.3 HIGH

A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the file /useredit.php. The manipulation of the …

Oct 10, 2025
CVE-2025-11584
7.3 HIGH

A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation …

Oct 10, 2025
CVE-2025-61930
8.1 HIGH

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the password change …

Oct 10, 2025
CVE-2025-61921
7.5 HIGH

Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the …

Oct 10, 2025
CVE-2025-61920
7.5 HIGH

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature …

Oct 10, 2025
CVE-2025-61919
7.5 HIGH

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: …

Oct 10, 2025
CVE-2025-55903
8.3 HIGH

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate …

Oct 10, 2025
CVE-2025-11583
7.3 HIGH

A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjob.php. Executing manipulation of the …

Oct 10, 2025
CVE-2025-11582
7.3 HIGH

A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing of the file /registration.php. Performing manipulation of the …

Oct 10, 2025
CVE-2025-60880
8.3 HIGH

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing …

Oct 10, 2025
CVE-2025-23309
8.2 HIGH

NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of service, escalation of privileges, code execution, and …

Oct 10, 2025
CVE-2025-23282
7.0 HIGH

NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit …

Oct 10, 2025
CVE-2025-23280
7.0 HIGH

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code …

Oct 10, 2025
CVE-2025-60305
8.8 HIGH

SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge …

Oct 10, 2025
CVE-2025-59530
7.5 HIGH

quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause …

Oct 10, 2025
CVE-2025-60869
7.3 HIGH

Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An …

Oct 10, 2025
CVE-2025-60378
8.1 HIGH

Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in …

Oct 10, 2025
CVE-2025-61864
7.8 HIGH

A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's …

Oct 10, 2025
CVE-2025-61863
7.8 HIGH

An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61862
7.8 HIGH

An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61861
7.8 HIGH

An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61860
7.8 HIGH

An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61859
7.8 HIGH

An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61858
7.8 HIGH

An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61857
7.8 HIGH

An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal …

Oct 10, 2025
CVE-2025-61856
7.8 HIGH

A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's …

Oct 10, 2025
CVE-2025-11189
7.3 HIGH

The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter, allowing for Javascript execution.

Oct 10, 2025
CVE-2025-11188
7.3 HIGH

The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued and to compromise the corresponding …

Oct 10, 2025
CVE-2025-52650
8.2 HIGH

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

Oct 10, 2025
CVE-2025-30001
7.3 HIGH

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which …

Oct 10, 2025
CVE-2025-25018
8.7 HIGH

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

Oct 10, 2025
CVE-2025-25017
8.2 HIGH

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

Oct 10, 2025
CVE-2025-21064
8.8 HIGH

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

Oct 10, 2025
CVE-2025-21062
7.8 HIGH

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction …

Oct 10, 2025
CVE-2025-21061
7.1 HIGH

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering …

Oct 10, 2025
CVE-2025-21058
7.3 HIGH

Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attackers to potentially execute arbitrary code …

Oct 10, 2025
CVE-2025-21050
7.1 HIGH

Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

Oct 10, 2025
CVE-2025-61773
8.1 HIGH

pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both …

Oct 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.